On July 31, an accountant at a mid-sized U.S. private equity firm picked up the phone. The caller introduced herself as the firm’s outside counsel, ran through details about an upcoming acquisition, and walked the accountant through a routine wire transfer. The voice was right. The professional shorthand was right. The wire went out. By the time anyone realized “outside counsel” was a synthetic voice generated from fifteen seconds of YouTube audio, roughly $25 million was already in motion.
Reuters reported the campaign on August 7. Levi Strauss was named the same day, hit by an “unauthorized third party” that extracted corporate information. Google and a handful of internet-intelligence firms have linked the activity to a loose cluster of English-speaking extortion crews — groups that used to send mass phishes and now pick up the phone.
If you run a small or midsize business, this is the threat that should keep you up at night. Not ransomware itself — the *delivery mechanism* for ransomware, which is increasingly a friendly voice on the other end of a call.
Phishing has been the number-one way attackers break into small businesses for years. Verizon’s 2025 Data Breach Investigations Report put a fine point on it: 88% of breaches at small and midsize businesses involved ransomware, and ransomware almost never arrives first. It rides in on a stolen credential or a successful phish.
What changed in the last eight months is the quality of the bait. A February 2026 poll by Sagiss and Pollfish found 72% of U.S. desk workers say phishing emails have become more convincing in the past year. The grammar is cleaner, the context tightens to whatever you’re actually working on, and the sender sounds like someone in your building. That’s AI doing what AI does — pattern-matching your org chart, your vendors, your typical phrasing.
Voice cloning pushes it past email. A 2024 IBM survey of 1,000 marketing leaders found roughly 1 in 4 had already experimented with voice-cloning tools. The same tools are commodity-priced on criminal forums. ElevenLabs and a dozen competitors offer them with a credit card and a sixty-second audio sample. Some require less. The fake “counsel” on that $25 million call was built from a public earnings call recording.
The shift matters because phone calls carry trust. We are wired to lower our guard when we hear a human voice asking us to do something routine. A phishing email that asks for an out-of-band wire transfer gets a second look. The same request, in a familiar voice, often does not.
SMBs get hit four times harder than large organizations in raw breach counts, according to Verizon — and that gap is widening. The defenses that worked in 2022 don’t cover what attackers are doing now. Three shifts matter:
Treat every first-time wire instruction as suspect. The classic control here is “call back on a known number.” That’s still right, but it has to mean *a number you already had*, not one the caller gave you. If someone asks you to send money somewhere you haven’t sent money before, insist on a video call or an in-person confirmation, even if the voice sounds exactly right.
Lock down the tools voice cloners use. That public earnings call, the CEO’s podcast appearance, the all-hands Zoom recording — every minute of senior-staff audio posted online is fuel. Most of the damage in 2026 attacks has come from publicly available audio, not from leaked private material. Decide as a leadership team which voices are allowed to be in the public record, and treat the rest as sensitive even if they’re not secret.
Run phishing drills that include the phone. Most awareness training still treats phishing as an email problem. It isn’t anymore. The Sagiss poll found workers are roughly twice as likely to fall for an AI-generated voice call as for a polished phish. Your training program should test the same muscle — pause, verify out-of-band, escalate — across email, text, and voice.
You don’t need a SOC to do any of this. You need a written policy that anyone with the authority to move money knows cold, and a culture that says “weird gut feeling” is a legitimate reason to slow down.

Here is a workable routine for a 50-person company with a finance team of three:
None of this requires new software. It requires writing it down, repeating it, and rewarding employees who escalate instead of punishing them for slowing a $40,000 payment by ten minutes.
The attackers aren’t smarter. They have cheaper tools. A phishing kit that took a skilled operator a week to build in 2021 now takes an afternoon, and the voice-cloning equivalent fits in a chat prompt. That’s the entire shift: the floor has dropped out from under the small-business defender, and the controls written before 2024 assume an attacker who has to spend time and money to sound convincing.
They don’t anymore. Your controls need to assume they were convincing from the start, and your people need permission to slow the train when something feels off.
That $25 million wire started with a phone call. The next one starts with a calendar invite.

Last year, 63% of small businesses watched their cyber insurance premiums jump 200% or more. This year, the carriers are not just charging more. They are sending applications with a checklist that looks a lot like a security audit. For a lot of small business owners, that checklist is the first time anyone has told them, in writing, what the minimum actually is.
That is the real story right now. Attackers have always known small businesses are softer targets. What is new is that insurance companies have started pricing it that way too, and they are not willing to write checks to companies that cannot prove they are doing the basics.
A few data points that explain why this is happening:
These are not theoretical numbers. The $100,000 figure is not a worst-case scenario — it is closer to a median. Average ransomware payments from US small businesses last year ran about $115,000. Add forensic investigation, customer notification, legal fees, and the cost of downtime, and the real bill is usually two or three times the ransom itself.
The companies that survive these events are not the ones with the best security in their peer group. They are the ones that had enough working controls that an underwriter was willing to back them.
Cyber insurance used to be closer to a credit-card application. “Do you have a firewall? Yes. Approved.” That era is over. In 2026, carriers verify the answers. They ask for screenshots, logs, and configuration exports. The Coalition and Fisch Solutions renewal checklists for 2026 spell it out:
If a small business cannot produce those five items, the carrier either declines the policy, charges a deductible that makes the coverage almost pointless, or excludes ransomware from the policy entirely.

The frustrating part is that almost none of these controls are expensive or exotic. Phishing-resistant MFA is free with Microsoft 365 or Google Workspace for most companies. EDR tools from companies like CrowdStrike, SentinelOne, or even Microsoft Defender for Business run in the low double digits per endpoint per month. Backups to an immutable cloud target with quarterly restore tests are a weekend project, not a quarter-long engagement.
So why is the gap so wide? A few reasons, all familiar:
If you are a small business owner, here is the practical list. Not the long version, just the one that will get you through an insurance application and meaningfully reduce your real risk.
None of these are fun projects. All of them are cheaper than a bad week.

For most of the last decade, small businesses have been told that cybersecurity is “important” in the same vague way flossing is important. The insurance market has finally done what the awareness campaigns could not: it has attached a dollar amount to the gap, and it has started refusing to insure the gap.
That is a painful adjustment, but it is also the first honest market signal small business owners have ever gotten about what the minimum looks like. The companies that take the checklist seriously, even the ones doing it grudgingly while filling out a renewal form, will end up safer than the ones that wait for an incident to teach the lesson.
The 40% who cannot survive a six-figure attack are not going to learn it from a magazine article. They are going to learn it from the next invoice, the next claim denial, or the next morning when a workstation shows a ransom note instead of a desktop. The good news is that the checklist to avoid all three of those mornings fits on one page, costs less than a part-time hire, and does not require a security team to operate.
It just requires the decision to start.
Sources
Last week’s article looked at management consoles as the new front door. This week, the same idea is showing up in a different place: the network itself.
In July, more than 30 Minnesota water systems were targeted in a coordinated cyberattack. One plant went offline. Around the same time, The Hacker News reported that attackers were using a compromised third-party advertising script to swap cryptocurrency wallet addresses on customer sites. Different victims, different techniques, same weakness: organizations trusted the network path around a system more than the system’s own security.
For a small business, that should change the question from “Is the server patched?” to “What can move through our network, and who can make that happen?”
Most companies still draw their environments as a few boxes: users, servers, cloud apps, and maybe a firewall in front. Actual traffic is messier. A laptop moves between home Wi-Fi and the office. A vendor gets remote access to a building-control system. A SaaS integration receives an API token. A managed service provider can log into half the environment from one console.
Each connection creates a trust decision. Those decisions pile up quietly because they usually work. The HVAC vendor can reach the controller. The accounting software can pull payroll data. The developer can access the build server. Nobody notices until an attacker inherits one of those permissions.
The Minnesota water-system incident is a useful warning even for companies nowhere near critical infrastructure. An attacker does not need to own every machine to cause an outage. Access to one operational system, one remote-management account, or one poorly separated network segment can be enough.
Network security is therefore less about building a taller wall and more about limiting the blast radius when somebody gets through.
Small businesses depend heavily on outside providers. That is sensible. Few 100-person companies should run their own email, payroll, endpoint management, backup infrastructure, and building systems.
The problem is that vendor access tends to outlive the original project. A contractor receives a VPN account for a migration. The account remains active for years. A remote-management agent gets installed on every workstation. Nobody checks which technician can use it. A service account has broad permissions because narrowing them would take an afternoon that never appears on the calendar.
Recent incidents involving N-able N-central servers show why this matters. N-central is used by managed service providers to administer customer environments. The Hacker News reported that attackers were able to take over servers after an initial fix proved incomplete. A flaw in a central management layer can turn one compromise into a customer-by-customer problem.
The practical lesson is uncomfortable: your vendor’s security model is part of your network model. If a provider can reach your endpoints, domain controllers, backup systems, or firewall, that provider is effectively inside your security boundary.
Ask vendors four direct questions:
If the answers are vague, treat the access as a risk you own.

A flat network is convenient right up until ransomware arrives. Once an attacker lands on one workstation, every reachable system becomes part of the next move: file shares, identity services, backups, printers, cameras, and operational equipment.
Segmentation does not require a six-figure redesign. Start with a few boundaries that reflect business impact:
The rule is simple: a device should be able to reach what it needs, not whatever happens to share the same switch.
Test those rules from the outside and from inside. A firewall diagram is a plan, not proof. A quarterly review of actual routes and firewall logs will catch the forgotten exception that a policy document will not.
Network security also includes the services users barely notice. DNS decides where a browser goes. Advertising and analytics scripts decide what code loads in a page. Wi-Fi decides which network a device joins.
Attackers keep exploiting those layers because they sit between a user and the application they think they are using. Recent reports of poisoned web scripts and hijacked hotel Wi-Fi pushing fake software updates show the same pattern in public and private networks: control the path, then let the victim do the clicking.
For SMBs, a few controls make a real difference. Use a managed DNS resolver with malware and newly registered-domain blocking. Prevent endpoints from silently changing DNS settings. Require browsers and operating systems to update through trusted channels, and train staff to treat browser pop-ups that demand an update as hostile until proven otherwise.
For public-facing websites, maintain an inventory of third-party scripts. Remove anything nobody can explain. Pin versions where practical, monitor changes to the site’s JavaScript, and avoid loading payment or authentication pages with unnecessary external code.

The network is no longer background plumbing. It carries identity, automation, vendor access, and the commands that keep the business running. The organizations that handle the next breach best will not be the ones with the longest security product list. They will be the ones that made compromise boring: one account, one device, one segment, and no easy route to everything else.
Sources
Reply with ‘post it’ and the images will be added and the article will go live.
Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, the tools those teams are *not* flying blind on (legitimate admin consoles, automation platforms, and self-hosted developer tools) are getting hit with pre-authentication exploits at a pace that should reset every CISO’s priorities.
On July 23, Check Point disclosed CVE-2026-16232, a CVSS 9.3 authentication bypass in SmartConsole, the admin panel used to manage Check Point firewalls and Security Gateways. It is being exploited in the wild right now. There is no patch you can install; there is a fix you have to pull from Check Point’s portal and apply manually. If your firewall’s management interface is reachable from the public internet, and a surprising number still are, the bypass is the only thing standing between an attacker and full administrative control of your perimeter.
This is not a one-off. It is the pattern of the month.
In the last ten days, I count at least six high-severity, pre-authentication or low-privilege vulnerabilities in internet-reachable admin interfaces:
eval() and executing code on the forum server. No account, no admin, no user interaction.Six different vendors. Six different industries. The same shape every time: a web-accessible admin surface, a flaw that does not require valid credentials, and exploitation that lands within days of disclosure.
Ten years ago, the management console was a thing only the sysadmin touched, from a workstation on the corporate LAN, over a jump host. That world is gone.
A few forces pushed the admin panel onto the public internet, and most of them were reasonable at the time:
The CrowdStrike 2026 Global Threat Report pegs roughly 79% of intrusions as malware-free — meaning the attacker uses valid credentials or exploits a legitimate interface rather than dropping a payload. That statistic understates the current moment. The legitimate interface now often ships with a pre-auth hole.

Two numbers from the last two weeks should reshape your patch-priority list:
Microsoft’s July 2026 Patch Tuesday shipped fixes for 570 vulnerabilities — the largest monthly release on record, per Krebs on Security. Of those, 11 were critical RCEs in components most enterprises do not think about: Hyper-V, Remote Desktop Gateway, Windows Routing and Remote Access Service. The defenders’ queue is longer than the attackers’.
Verizon’s 2026 Data Breach Investigations Report (still the cleanest cross-industry baseline) found that exploitation of vulnerabilities tripled as an initial-access pattern between the 2024 and 2026 editions, surpassing stolen credentials for the first time in the report’s history. The methodology shift matches what the news cycle is showing: it is easier for attackers to find a fresh CVE than to phish a credential.
You do not have to patch 570 CVEs. You have to patch the ones in things that are reachable from the internet. The hard part is the second clause.
nmap -p- against your external range, or pull a Shodan report for your CIDRs. Anything with a web UI that is not behind a VPN or zero-trust gateway is your to-do list. Be ruthless. If a contractor needs it, give them a Tailscale/Cloudflare Tunnel path, not a public port.The pattern of the last month is not “attackers got smarter.” It is that the surface area grew faster than the controls did, and the gap is showing up in the news once a week now. The fix is not a new product. It is the boring work of shrinking what the public internet can reach, and treating actively-exploited CVEs as the emergency they are. Your firewall’s admin console should not be one Shodan query away from a stranger. In 2026, it usually is.

Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, Comparitech and Dark Reading put a number on the target that’s getting hit hardest because of that gap: healthcare.
In February, a ransomware attack on the University of Mississippi Medical Center (UMMC) disrupted operations for more than two weeks. The hospital is the only Level 1 trauma center in the state. Surgeries were rescheduled. Cancer patients had to be diverted. The CEO called it “the most significant operational challenge in our history.” It was not a one-off. Comparitech, tracking incidents across the healthcare sector through the first half of 2026, found that attacks against healthcare businesses — not the hospitals themselves, but the vendors, billing providers, and clearinghouses behind them — more than doubled year over year. The 110% surge is the headline. The mechanism is the part that should keep a CIO up at night.
Rebecca Moody, head of data research at Comparitech, said the obvious thing out loud: “Through one central hub, you’re targeting multiple healthcare organizations that often have huge databases or were providing third-party services to hundreds of hospitals.”
The German medical-billing company Unimed learned this in March. Unimed processes billing for roughly 95% of Germany’s university hospitals and more than half of its larger clinics. One intrusion. Tens of thousands of patient records out. The same shape played out in February at TriZetto Provider Solutions, where a breach exposed the data of 3.4 million patients across the company’s healthcare-provider customers. QualDerm Partners disclosed in February that a December 2025 attack had compromised 3.1 million patient records.
Notice the pattern. None of those headlines name a hospital. They name the company the hospitals depend on. The attackers aren’t picking locks anymore. They’re picking the lockmaker.
The small-clinic version of this is real. The 40-physician orthopedic group that outsources its billing to a clearinghouse, the regional imaging center that uses a third-party transcription service, the dental practice that hands its claims processing to a SaaS vendor — every one of those is a single breach away from having to notify tens of thousands of patients they never treated. The vendor may not even tell you before the press release goes out.
The other half of the equation is the hospital itself. The FBI’s Internet Crime Complaint Center said in April 2026 that healthcare was the most-attacked critical-infrastructure sector in all of 2025. That is not a new finding. It is the same finding the FBI has published every year for the past decade. What changed in 2026 is the gap between attacker capability and defender capacity stopped closing.
Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center (Health-ISAC), described the structural trap in plain language: legacy medical-device complexity, always-on clinical operations, and heavy third-party dependence, all under the budget pressure of a 60% gross margin business that the government reimburses below cost. Hospital CISOs are taking the threats seriously. They are also losing the hiring war to payers, pharma, and the vendors they already depend on.
The Shadow AI thread from last week lands directly here. When an overworked nurse pastes a medication list into ChatGPT at 2 a.m. to make sense of a discharge summary, and when a billing clerk uploads a denial letter to Claude to draft an appeal, the data has left the building. There is no DLP rule in the world that catches that on a personal phone on the hospital Wi-Fi. Most hospitals have not even tried.

On July 16, 2026, Owen Flowers (18) and Thalha Jubair (20) were each sentenced to five and a half years in a UK court for the 2024 ransomware attack on Transport for London. The Transport for London case was the headline. The healthcare part of the plea is the part that matters for this article.
Flowers was arrested at home on September 6, 2024 — three days after the TfL intrusion ended. The NCA says officers caught him mid-attack on two U.S. healthcare organizations: SSM Health Care Corporation and Sutter Health. Search warrants turned up devices holding proof of all three intrusions. In chats that prosecutors entered into evidence, Flowers acknowledged that locking those systems down “might kill some 90-year-old on life support.” The arrest is what stopped him.
The DOJ’s September 2025 indictment against Jubair, still untested in court, ties the broader Scattered Spider crew to roughly 120 intrusions, at least 47 U.S. victims, and more than $115 million in ransom payments between May 2022 and September 2025. Healthcare was not a side project. It was a quarter of the work. Scattered Spider’s tradecraft — SIM swap, voice phishing, MFA bypass via the carrier — works against hospitals because hospitals answer the phone and accept SMS codes, the same way every other enterprise does.
For a small hospital, a regional clinic network, or a healthcare-adjacent vendor, the work is unglamorous and the order matters.
The 110% surge is not a peak. It is the new floor. Healthcare is the most attacked critical-infrastructure sector in the United States for the fifteenth year running, the ransomware crews have learned that vendors are a multiplier, and the people behind Scattered Spider are in court because they tried it on SSM Health and got caught. Next time they may not get caught. The hospitals that handle the next eighteen months well are not the ones with the best vendor security questionnaire. They are the ones who accepted early that the lockmaker is the target, not the lock.

Last week’s Bitdefender numbers said 47.4% of IT teams have only partial or no visibility into the AI tools their employees are using. That is the polite version of the problem.
A sales rep pastes a contract into ChatGPT to “summarize the legalese.” An engineer feeds a production stack trace into a chatbot to debug faster. A marketing manager uploads an entire customer persona deck to an image generator for a slide. None of these people think they are doing anything risky. The data is already gone, and your DLP never saw it leave.
That is Shadow AI. The operating environment of 2026, and the single biggest hole in most SMB security programs right now.
Bitdefender’s 2026 Cybersecurity Assessment put a number on it: 51.8% of IT and security pros said they have full visibility into how AI is used in their company. 47.4% said they have only partial or no visibility. That sounds like a coin flip, but the sub-bullets are worse.
58% of managers said they have complete AI visibility. Among frontline practitioners, the number drops to 45.9%. The strategic layer of the business is making decisions based on a picture that does not exist. The people doing the actual work know they are flying blind. The two groups are not talking about it, or the managers are not listening.
For an SMB with 50 to 500 employees and no dedicated AI governance lead, this gap collapses fast. The first time you find out an employee fed customer PII into a free chatbot is when your general counsel gets the call from your insurance carrier. By then, “shadow” is the wrong word.
It is tempting to treat Shadow AI as a single problem. It is at least four, and they have different fixes.
Public LLM paste-and-go. Employees copy text, code, customer data, or contracts into ChatGPT, Claude, Gemini, DeepSeek, or one of the dozen Chinese-origin models employees install on personal phones to bypass corporate restrictions. Prompts are stored on vendor servers. Some are used for training by default. Opt-out exists but the toggle is buried in settings most users have never opened. Samsung learned this in 2023 when engineers pasted source code into ChatGPT and the company banned generative AI company-wide within a month. Three years later, the same mistake is happening in companies that were not paying attention.
Unauthorized copilots and agents. Microsoft 365 Copilot, Google Workspace Gemini, Slack AI, Notion AI, and Zoom AI Companion have shipped into the SaaS tools you already pay for. Most are enabled by default at the tenant level. Most can be configured to respect your existing data boundaries. Most have not been. When Copilot launches in your M365 tenant and starts surfacing summaries of HR investigations, M&A drafts, or terminated employee folders to anyone who asks in Teams, that is not a Copilot bug. That is your tenant configuration.
Browser extensions and meeting summarizers. Read.ai, Otter, Fireflies, Tactiq, Fathom, and a dozen look-alikes join your Zoom and Teams calls automatically and write transcripts to their own cloud. They often capture audio, video, screen shares, and chat. Some pipe everything to a third-party LLM for the “smart summary” feature. Sales calls, customer calls, board calls — all in scope. Most IT teams have no inventory of these extensions.
Local AI tooling and shadow agents. Engineers running Ollama, LM Studio, or llamafile on a laptop to “keep our data local” sounds good in theory. In practice, those models often pull pre-trained weights from unverified Hugging Face mirrors, ship with no SBOM, and run with no sandbox. SMBs that adopted local AI for “security reasons” are often running unsigned binaries from strangers — the opposite of the security reason they thought they had.

I am going to name specific examples because hand-waving about “AI risks” does not move anyone to action.
EchoLeak (Microsoft 365 Copilot, 2025). Researchers at Aim Labs disclosed a prompt injection vulnerability in Copilot that allowed an attacker to exfiltrate data from a user’s mailbox and OneDrive through a single crafted email. No user interaction beyond receiving the email was required. Microsoft patched it. The class of bug did not go away — every LLM-integrated product has the same shape of problem, and the research community finds new variants every month.
DeepSeek exposure (January 2025). The Chinese AI lab DeepSeek exposed more than a million rows of internal logs, API keys, and user prompts via an unauthenticated ClickHouse database. Any company that had employees using DeepSeek for work had sensitive prompts sitting on an exposed server. No public count of affected corporate users exists, which is itself the story.
Slack AI data leakage pattern. Multiple 2025 disclosures showed Slack AI susceptible to prompt injection through shared files and channels, where hidden text in a document could hijack the AI’s response and exfiltrate data the user had access to. Slack patched. The lesson did not stick — every AI-augmented SaaS tool is in the same boat and the disclosure cadence is a metronome.
The temptation is to write an AI policy and call it done. That does not work. People will use AI tools regardless. The job is to make the safe path the easy path and to know what is happening when it is not. Five moves for a small IT team this quarter.
Turn off generative AI features in your SaaS tenants by default. M365 Copilot, Gemini in Workspace, Slack AI, Notion AI — set them to opt-in per user group, not enabled tenant-wide. The defaults shipped in late 2025 and early 2026 are permissive. Override them.
Publish an approved AI tools list. Three to five tools you have vetted, with the data classification each one is approved to handle. “Approved for public and internal data. Not approved for customer PII, financial records, or PHI.” That single paragraph gives your help desk something to point to when an employee asks “can I use this?”
Make sure tenant-bound AI features are configured correctly. Copilot honors M365 permissions when set up right. The config lives in the Copilot admin center, the audit logs in Purview, and the gaps are the difference between “summarize a public Teams channel” and “summarize every HR investigation in the last five years.”
Block the unsanctioned tools at the network layer. DNS filtering, egress proxy, and CASB products can each take a bite. None of them catch everything. The goal is not perfection; the goal is to make approved tools fast and unapproved ones annoying enough that employees come to IT instead of going around.
Add one line to your incident response plan. “Employee pastes sensitive data into an unauthorized AI tool.” Run the tabletop. You will discover who needs to be on the call, what your regulatory disclosure clock looks like, and which contracts have notification clauses. That tabletop is worth more than another policy doc.
The companies handling Shadow AI well in 2026 are not the ones with the best AI policy. They are the ones that accepted two things early: employees will use AI whether you sanction it or not, and you cannot govern what you cannot see. Everything else — the tool list, the tenant config, the network controls, the runbook — follows from those two facts.
The Bitdefender stat said 47.4% have partial or no visibility. The fix is the unglamorous work of getting your SaaS tenant in order, talking to your teams, and writing down what “approved” means. The work fits in a quarter. The cost of skipping it does not.

The first week of July handed IT teams a worst-case scenario. The interesting part is that the survey data said this was coming.
On Wednesday, CISA added a high-severity SharePoint flaw to its Known Exploited Vulnerabilities catalog. By Thursday, threat actors were actively probing a critical (CVSS 9.8) bug in the official Gitea Docker image, 13 days after disclosure, letting any unauthenticated visitor impersonate any user, including admin. The same day, Progress warned of live exploitation of a pre-auth remote code execution bug in Kemp LoadMaster, a load balancer used heavily in mid-market networks. Adobe patched seven CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic. The Linux kernel dropped a fix for a use-after-free privilege escalation dubbed “Bad Epoll” that an ordinary logged-in user can ride straight to root, including from inside Chrome’s sandbox.
If you read security news, that paragraph sounds normal. That is the problem.
That string of disclosures is not a coincidence and not a fluke. The week of June 29 to July 6, 2026 was ordinary. Run the same exercise next month and you will get a similar wall of CVEs, similar exploitation, similar “patch now” advisories. The cadence is the story.
Bitdefender published its 2026 Cybersecurity Assessment on July 1, surveying 1,200 IT and security professionals across six countries. The headline finding is the one the industry has been quietly avoiding: awareness of cyber risk is at an all-time high, and operational resilience is at an all-time low. The two curves have decoupled, and they are still moving apart.
The numbers tell the same story in different rooms. 51.8% of respondents told Bitdefender they have full visibility into how AI is being used inside their company. 47.4% admitted they have only partial or no visibility into “Shadow AI,” the personal ChatGPT tabs, the unauthorized Copilot installs, the unvetted browser extensions that summarize meetings. When you split that answer by role, the gap is sharper. Nearly 58% of managers believe they have complete AI visibility. Among frontline practitioners, that number drops to 45.9%. The strategic decisions are being made on a picture half the building does not recognize.
The large enterprise has more attack surface, but it also has people whose entire job is to read the CISA KEV catalog on Monday morning and have a remediation plan by lunch. The 80-person logistics company does not. The 200-person law firm does not. The 40-person SaaS startup does not. They have one or two people doing IT, often with no dedicated security hire, and they are reading the same Gitea writeup that a Fortune 500 CISO is reading, except without a team to back them up.
The Bitdefender report is blunt about this part too. “Security teams understand the importance of reducing the attack surface,” it reads, “yet they often lack the skills, resources, or strategy to do so.” That sentence does not get quoted in marketing decks. Awareness without capacity is a tax you pay every quarter and collect no return on.

On the same day the Bitdefender report came out, Microsoft’s Mark Russinovich published a blog post that nobody at a small business had time to read. He announced that Microsoft is pulling its post-quantum cryptography roadmap forward to 2029, two years earlier than the previous schedule. His reasoning: cryptographically relevant quantum computers could arrive sooner than previously expected. For a CISO at a global bank, this is a multi-year migration program. For an IT generalist at a 150-person manufacturer, it is one more line item on a list that is already too long.
The fix is not exotic, though. Microsoft’s own plan rests on three moves small IT teams can start with: adopt TLS 1.3 everywhere you terminate HTTPS, audit where cryptography is hard-coded into your applications and break those couplings, and design for “crypto agility,” meaning your systems can swap algorithms without being rebuilt from scratch. None of this is a 2029 problem. The migration window is what makes it one.
The honest version of a hardening plan for a small team is small. It is not “buy a SIEM.” It is five things, do them this month.
Subscribe to the CISA KEV catalog as an email or RSS feed. Anything that lands on that list gets a 14-day patch or mitigation deadline from the U.S. government. Treat it as a binding SLA. If you cannot patch in 14 days, document why and what compensating control you have in place.
Build a real list of internet-exposed assets. Not a theoretical list. The actual set of hosts, services, and ports exposed to the public internet as of this week. Run an unauthenticated scan from outside your network. The gap between what you think is exposed and what is exposed is where the Gitea bugs live.
Replace “is MFA enabled” with “is MFA enforced on the highest-privilege accounts, with phishing-resistant factors.” Hardware keys (FIDO2) and platform-bound passkeys are not exotic anymore. They are cheap. They are the single highest-ROI control most small businesses are still not using.
Pick one “if this breaks at 2 a.m.” scenario and write the runbook. A Gitea admin compromise, a SharePoint exploit, a VPN appliance RCE, pick the one most likely to hit you, write three pages of what you do, and rehearse it with the team. A 200-person company with a good runbook beats a 2,000-person company with a stale one.
Schedule a 90-minute review of your top five SaaS vendors by data exposure. SOC 2 report, SBOM availability, breach notification clause. The questions alone will reveal the ones that should not be in your stack.
The gap between awareness and resilience is not going to close on its own. The CVE flood is not going to slow down. AI is not going to reduce the attack surface. The post-quantum transition is going to land on the same overstretched IT generalist who is already triaging a Gitea CVE and patching a SharePoint server. The companies that handle the next two years well are the ones that stop pretending awareness is the same as readiness. The job of hardening is unglamorous, mostly invisible, and the actual work of 2026. The week of July 6 made that impossible to miss.

The part no one wants to say out loud: you can’t audit them all.
Last week, a security research firm named Novee published a finding that should make every CIO in the country uncomfortable. A class of vulnerabilities they’re calling Cordyceps — embedded in GitHub Actions workflows — exposed more than 300 public repositories (including those of Microsoft, Google, and Apache) to full supply-chain takeover. An attacker with the right foothold could push poisoned code into the open source packages that millions of applications depend on. The exposure was wide. The blast radius is the entire internet.
If you’re running a 50-person SaaS company or a regional healthcare network, you probably read that story and thought the same thing I did: I don’t control any of this.
That’s the point. Welcome to the supply chain problem.
Five years ago, “supply chain attack” mostly meant a compromised vendor slipping malware into a software update. The SolarWinds incident of late 2020 fit that model almost perfectly. One point of compromise. Investigate, contain, move on.
The 2026 version is messier, broader, and harder to point at. Three stories from the last ten days alone:
Three different vendors. Three different attack surfaces. One common reality for anyone running a small IT team: the things you depend on to ship software, take payments, or run your website are being attacked in ways you cannot see.
The press coverage tends to focus on the household names. Microsoft, Google, Apache, AWS — these are mature companies with serious security teams. If they miss a bug in their CI/CD pipeline or their extension store, it’s news for a week and then they patch.
The same software is sitting in your stack. A 30-person e-commerce business might run its entire operation on a handful of npm packages, a payment processor, an inventory SaaS, and a small fleet of AWS services. Any one of those is a possible entry point. The smaller company can’t audit the source of every dependency, can’t review the security of every SaaS vendor, and almost certainly doesn’t have a Software Bill of Materials to begin with.
A few uncomfortable numbers, courtesy of Verizon’s 2025 Data Breach Investigations Report: 30% of breaches now involve a third-party component, and that share has been climbing every year since 2021. For small businesses specifically, the figure is higher — somewhere around 40%, depending on which report you read.
You don’t have to be the actual target. You just have to be downstream of one.

The honest answer: you cannot eliminate the risk. Anyone who tells you they can is selling you something. But you can reduce the blast radius and catch problems faster. Here’s what I’d actually do this week if I were running IT for a 50-to-500-person company.
1. Inventory your dependencies. Then inventory them again.
You probably have an official list of approved SaaS vendors and on-prem software. That list is incomplete. The real inventory lives in your developers’ package.json files, your DevOps team’s GitHub Actions, your marketing team’s browser extensions, and your sales team’s Chrome plug-ins. Get a Software Bill of Materials (SBOM) tool — CycloneDX or SPDX-format generators are free and plug into most CI systems. You can’t protect what you can’t name.
2. Lock down browser extensions.
The StegoAd case is a reminder that the attack surface you can see is not the only one. Browser extensions run with the same privileges as the user who installed them. Set a corporate policy. Audit which extensions are installed across the team. Don’t allow employees to install extensions on company-managed browsers without a review. This sounds pedantic. It is not.
3. Watch the maintainers, not just the packages.
A growing share of supply chain attacks in 2026 target the humans behind the software. Compromised maintainer accounts. Social engineering of project owners. Hijacked email addresses used for password resets. Miasma works exactly this way. If your business depends on a small open source library maintained by one person in another time zone, that is a single point of failure. Know who they are. Have a contingency plan for what happens if their account gets hijacked.
4. Treat vendor security like vendor pricing.
If you evaluate SaaS vendors on price, uptime, and feature set, add security to that list and make it count. Ask vendors for SOC 2 reports. Ask how they handle dependency updates. Ask whether they have their own SBOM. The answers vary wildly, and the questions alone will weed out vendors who shouldn’t be in your stack.
5. Have an “off switch.”
When the next big npm or Python package gets compromised — and there will be a next one — how fast can you pin your dependencies to known-good versions, roll back your last build, or block traffic to the affected vendor? That is your incident response plan for supply chain failures. Most companies don’t have one. Spend an afternoon writing it.
The uncomfortable trend is that the perimeter is dissolving. The work of securing your business used to mean securing your network, your laptops, and your office. It now means securing every package, every service, every extension, and every developer tool that touches your stack. The number of those things grows every quarter. The number of people you have to secure them with doesn’t.
For a 200-person company, the practical move isn’t to out-tech the attackers. It’s to be a less attractive target than the next 200-person company. That means knowing your dependencies, limiting the third-party surface, and having a plan for the day one of them fails. None of this is glamorous. All of it is the actual job in 2026.

A deepfake video call cost Arup $25M. The same playbook is hitting SMBs every week — and most security programs haven’t caught up.
In early 2024, an accountant at the engineering firm Arup sat down for what looked like a routine video conference. The CFO was on the call. So were several other colleagues. Everyone looked right. Everyone sounded right. The only problem: none of them were real. A finance worker wired roughly $25 million to attackers who had fabricated the entire meeting with deepfake video and cloned voices.
That case made global headlines. The quieter story is the one playing out at thousands of small and mid-sized businesses every week: an “executive” emails an AP clerk asking for a wire transfer, a “vendor” calls about updating payment details, a “Microsoft technician” leaves a voicemail that sounds exactly like your IT director. Generative AI has turned social engineering from a craft into a production line, and most security programs have not caught up.
For most of the last decade, phishing emails were easy to spot. Bad grammar, mismatched sender domains, generic greetings. The defenders’ advantage was that attacks were expensive to personalize at scale. An attacker could blast a million generic “Nigerian prince” emails, or send a hundred highly targeted ones. They chose the first.
That trade-off is gone. Large language models let attackers produce clean, fluent, locally appropriate phishing copy in any language. Voice cloning tools need as little as ten seconds of audio to mimic a specific person. Deepfake video has moved from research demos to real-time face-swaps on a commodity laptop. The cost of a targeted attack has dropped by orders of magnitude, and the volume has followed.
A 2024 study by IBM’s X-Force found that AI-generated phishing emails had a click-through rate about 70% higher than the human-written kind. A separate analysis from the UK’s National Cyber Security Centre warned that the average employee can no longer tell the difference. We are past the point where user-reported “this email felt weird” is a reliable defense.
Three patterns are showing up over and over in incident reports.
1. The impersonated vendor. Attackers research a company’s real suppliers, then email the AP team from a look-alike domain saying banking details have changed. The invoice is real, the dollar amount matches a known contract, and the signature line includes a plausible employee whose LinkedIn profile they scraped last week. AI writes the email in flawless English, including the small talk about the recipient’s recent promotion.
2. The cloned executive. Voice cloning needs a target’s voice from a podcast, earnings call, or public video. Most executives in a public company have hours of this content online. The attacker calls an employee, often outside business hours, with a calm “I’m in a meeting, can you do me a quick favor” request. The request is usually a gift card purchase, a wire transfer, or the disclosure of an MFA code.
3. The deepfake meeting. The Arup case is the template. A fabricated Teams or Zoom meeting with multiple fake participants, all of whom look and sound like real colleagues. The goal is usually authorizing a financial transaction or harvesting credentials. The sophistication has been climbing through 2025 and 2026.

Big banks and tech firms have spent twenty years building layered defenses. They still get hit, but the cost per attempt is high enough to push attackers elsewhere. A 50-person marketing agency or a regional medical practice has none of that. The CEO’s voice is on the company website. The accounting team’s job titles are on LinkedIn. The whole org chart is one Google search away.
The defender’s math is also worse. A large enterprise can absorb a six-figure loss. A small business that loses $200,000 to a fraudulent wire transfer is often looking at layoffs, or closing. Ransomware actors know this, which is why attacks on companies under 200 employees have roughly doubled in the last two years.
There is no silver bullet, but a few practical moves close most of the gap.
Use a verbal callback on any out-of-band financial request. If the CFO emails asking for a wire transfer, call her back on a number you already have. Not a number in the email. A cloned voice sounds real on a first listen, but the attacker cannot answer your callback because they do not control your executive’s actual phone. This one habit stops the majority of BEC fraud in incident data, and it costs nothing.
Treat any change-of-payment-details request as hostile by default. Require that changes be confirmed through a known channel, with a second person signing off. The friction is real. It is also the reason your finance team has not already been robbed.
Train on the new reality, not the old one. Most security awareness programs were built around 2015 phishing: bad grammar, obvious scams, hover-to-preview. Update the curriculum. Show staff real AI-generated phishing samples. Run a tabletop exercise that uses voice cloning. The goal is not to make people paranoid; it is to make them skeptical in a structured way.
Lock down public executive content where you can. You do not have to delete the CEO’s podcast appearances. But you can stop posting new high-quality video of their face and voice on public pages, and you can coach executives to use work accounts for sensitive calls. Audio and video of a person walking through an airport is enough to build a convincing clone.
Adopt phishing-resistant MFA. Hardware security keys (FIDO2/WebAuthn) and platform-bound passkeys cannot be phished by a fake login page, no matter how convincing. They are the single highest-ROI control most small businesses are still not using.

AI has not invented a new category of attack. Social engineering has always worked because humans are the easiest part of any system to fool. What AI did was make the cost curve bend sharply in the attacker’s favor. The defenses that worked when attacks were expensive and rare are eroding, and the ones that work now (out-of-band verification, hardware MFA, structured skepticism) require actual process change, not just another product.
The companies that are handling this well are the ones that stopped expecting email to be a trustworthy channel for money, credentials, or sensitive instructions. That is a cultural shift more than a technical one, and it is the work of the next few years.
If you do one thing this week, pick the highest-risk workflow in your business (the one where a single email or phone call can move money or grant access) and add a verbal callback step. It will feel slow. It is also the reason you will not be in the next incident report.
The December 2024 NPRM ends the “addressable vs. required” loophole. Here’s what healthcare IT teams need to do in the next 90 days.
In February 2024, a single ransomware group compromised Change Healthcare and walked away with the medical records of 192.7 million Americans. That’s more than half the country. The attack vector was almost embarrassingly simple: a Citrix portal without multi-factor authentication.
The company paid a $22 million ransom. UnitedHealth Group, Change’s parent, has since reported breach-related costs north of $3 billion. And yet — until very recently — the federal baseline for protecting patient data hadn’t meaningfully changed since 2013.
That’s about to change. And a lot of healthcare organizations are nowhere near ready.
HHS published a Notice of Proposed Rulemaking on December 27, 2024. Public comments closed in early 2025. The final rule is expected sometime this year, with a compliance window of 6–12 months after publication. The changes are the most significant to the Security Rule in over a decade.
The biggest shift is the end of the “addressable” vs. “required” loophole. Under the current rule, a safeguard can be marked “addressable” — meaning you can skip it if you document a reasonable alternative. In practice, that became an excuse to skip encryption, MFA, and other things organizations didn’t want to budget for. The NPRM basically eliminates that distinction. Things that were “addressable” become required, full stop.
The requirements getting teeth:
If you’re reading that list and feeling a bit of acid reflux, you’re not alone.
The 2013 rule was written for a world of Windows XP workstations on flat networks and clinicians logging in from a single office. The attackers of 2026 are not playing by those rules.
Three patterns define the modern healthcare threat:
Third-party vendors are the new front door. The Change Healthcare breach wasn’t a hospital being hacked. It was a clearinghouse used by virtually every US provider. Ascension’s May 2024 ransomware incident started with a contractor downloading a malicious file. When a single vendor handles billing, scheduling, or credentialing for thousands of practices, that vendor’s security posture becomes your security posture.
Medical devices are a soft target. A 2022–2024 wave of FDA safety communications flagged vulnerabilities in devices from Medtronic, BD, Illumina, and others. Many run outdated embedded operating systems, have hardcoded credentials, and can’t be patched without taking the device offline. The new rule will require device inventories, SBOMs (software bills of materials), and a documented plan for addressing known vulnerabilities.
Initial access brokers are running a SaaS model. Groups like Scattered Spider, BlackCat/ALPHV, and LockBit-affiliated crews specialize in selling access rather than running ransomware themselves. Healthcare organizations with exposed RDP, unpatched VPN appliances, and help desks that don’t do callback verification are paying the price.

You don’t have to wait for the final rule. The practices that get ahead of this now will be the ones that pass their next OCR audit with a handshake instead of a subpoena.
Inventory everything that touches ePHI. Laptops, phones, printers, fax servers, imaging systems, infusion pumps, badge readers that store biometric templates — all of it. If you can’t list it, you can’t protect it.
MFA everywhere, no exceptions. This is the single highest-ROI change. The Change Healthcare attackers walked in through a single Citrix account with no MFA. Don’t let that be your story.
Review your BAAs, then actually test the vendors. A signed Business Associate Agreement is not a security posture. Ask your clearinghouses, billing vendors, and EHR hosting providers for SOC 2 Type II reports and recent penetration test summaries.
Run an actual tabletop exercise. Pretend your EHR is down for 48 hours. Who calls whom? What’s the manual fallback for prescriptions and lab orders? How do you notify patients? Write it down. Then test it again in six months.
Patch the worst things first. CISA’s Known Exploited Vulnerabilities catalog is a free, opinionated list. Work through it. The 15-day SLA for critical flaws isn’t aspirational under the new rule.
If you’re a solo practitioner or a small group, the list above is intimidating. You’re running a medical practice, not a security operations center. The good news: HHS has signaled that some new requirements will scale based on size and complexity. The bad news: “we’re small” has not been a winning defense in OCR enforcement actions for years. The 2024 settlement with Plastic Surgery Associates — $500,000, six affected patients — made that point clearly.
Consider a vCISO arrangement (a fractional security officer, typically $3–8k/month) or a managed detection and response provider that knows healthcare. The per-provider cost is a lot smaller than a breach.
The HIPAA Security Rule is finally catching up to the threats healthcare has been facing for a decade. The final rule will land this year, and the compliance clock will start immediately. The practices that use the next 90 days to get MFA in place, finish their asset inventory, and pressure-test their vendors will spend 2026 focused on patient care. The ones that wait will be explaining to OCR why their Citrix portal didn’t have multi-factor authentication.
