Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, the tools those teams are *not* flying blind on (legitimate admin consoles, automation platforms, and self-hosted developer tools) are getting hit with pre-authentication exploits at a pace that should reset every CISO’s priorities.
On July 23, Check Point disclosed CVE-2026-16232, a CVSS 9.3 authentication bypass in SmartConsole, the admin panel used to manage Check Point firewalls and Security Gateways. It is being exploited in the wild right now. There is no patch you can install; there is a fix you have to pull from Check Point’s portal and apply manually. If your firewall’s management interface is reachable from the public internet, and a surprising number still are, the bypass is the only thing standing between an attacker and full administrative control of your perimeter.
This is not a one-off. It is the pattern of the month.
In the last ten days, I count at least six high-severity, pre-authentication or low-privilege vulnerabilities in internet-reachable admin interfaces:
eval() and executing code on the forum server. No account, no admin, no user interaction.Six different vendors. Six different industries. The same shape every time: a web-accessible admin surface, a flaw that does not require valid credentials, and exploitation that lands within days of disclosure.
Ten years ago, the management console was a thing only the sysadmin touched, from a workstation on the corporate LAN, over a jump host. That world is gone.
A few forces pushed the admin panel onto the public internet, and most of them were reasonable at the time:
The CrowdStrike 2026 Global Threat Report pegs roughly 79% of intrusions as malware-free — meaning the attacker uses valid credentials or exploits a legitimate interface rather than dropping a payload. That statistic understates the current moment. The legitimate interface now often ships with a pre-auth hole.

Two numbers from the last two weeks should reshape your patch-priority list:
Microsoft’s July 2026 Patch Tuesday shipped fixes for 570 vulnerabilities — the largest monthly release on record, per Krebs on Security. Of those, 11 were critical RCEs in components most enterprises do not think about: Hyper-V, Remote Desktop Gateway, Windows Routing and Remote Access Service. The defenders’ queue is longer than the attackers’.
Verizon’s 2026 Data Breach Investigations Report (still the cleanest cross-industry baseline) found that exploitation of vulnerabilities tripled as an initial-access pattern between the 2024 and 2026 editions, surpassing stolen credentials for the first time in the report’s history. The methodology shift matches what the news cycle is showing: it is easier for attackers to find a fresh CVE than to phish a credential.
You do not have to patch 570 CVEs. You have to patch the ones in things that are reachable from the internet. The hard part is the second clause.
nmap -p- against your external range, or pull a Shodan report for your CIDRs. Anything with a web UI that is not behind a VPN or zero-trust gateway is your to-do list. Be ruthless. If a contractor needs it, give them a Tailscale/Cloudflare Tunnel path, not a public port.The pattern of the last month is not “attackers got smarter.” It is that the surface area grew faster than the controls did, and the gap is showing up in the news once a week now. The fix is not a new product. It is the boring work of shrinking what the public internet can reach, and treating actively-exploited CVEs as the emergency they are. Your firewall’s admin console should not be one Shodan query away from a stranger. In 2026, it usually is.

Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, Comparitech and Dark Reading put a number on the target that’s getting hit hardest because of that gap: healthcare.
In February, a ransomware attack on the University of Mississippi Medical Center (UMMC) disrupted operations for more than two weeks. The hospital is the only Level 1 trauma center in the state. Surgeries were rescheduled. Cancer patients had to be diverted. The CEO called it “the most significant operational challenge in our history.” It was not a one-off. Comparitech, tracking incidents across the healthcare sector through the first half of 2026, found that attacks against healthcare businesses — not the hospitals themselves, but the vendors, billing providers, and clearinghouses behind them — more than doubled year over year. The 110% surge is the headline. The mechanism is the part that should keep a CIO up at night.
Rebecca Moody, head of data research at Comparitech, said the obvious thing out loud: “Through one central hub, you’re targeting multiple healthcare organizations that often have huge databases or were providing third-party services to hundreds of hospitals.”
The German medical-billing company Unimed learned this in March. Unimed processes billing for roughly 95% of Germany’s university hospitals and more than half of its larger clinics. One intrusion. Tens of thousands of patient records out. The same shape played out in February at TriZetto Provider Solutions, where a breach exposed the data of 3.4 million patients across the company’s healthcare-provider customers. QualDerm Partners disclosed in February that a December 2025 attack had compromised 3.1 million patient records.
Notice the pattern. None of those headlines name a hospital. They name the company the hospitals depend on. The attackers aren’t picking locks anymore. They’re picking the lockmaker.
The small-clinic version of this is real. The 40-physician orthopedic group that outsources its billing to a clearinghouse, the regional imaging center that uses a third-party transcription service, the dental practice that hands its claims processing to a SaaS vendor — every one of those is a single breach away from having to notify tens of thousands of patients they never treated. The vendor may not even tell you before the press release goes out.
The other half of the equation is the hospital itself. The FBI’s Internet Crime Complaint Center said in April 2026 that healthcare was the most-attacked critical-infrastructure sector in all of 2025. That is not a new finding. It is the same finding the FBI has published every year for the past decade. What changed in 2026 is the gap between attacker capability and defender capacity stopped closing.
Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center (Health-ISAC), described the structural trap in plain language: legacy medical-device complexity, always-on clinical operations, and heavy third-party dependence, all under the budget pressure of a 60% gross margin business that the government reimburses below cost. Hospital CISOs are taking the threats seriously. They are also losing the hiring war to payers, pharma, and the vendors they already depend on.
The Shadow AI thread from last week lands directly here. When an overworked nurse pastes a medication list into ChatGPT at 2 a.m. to make sense of a discharge summary, and when a billing clerk uploads a denial letter to Claude to draft an appeal, the data has left the building. There is no DLP rule in the world that catches that on a personal phone on the hospital Wi-Fi. Most hospitals have not even tried.

On July 16, 2026, Owen Flowers (18) and Thalha Jubair (20) were each sentenced to five and a half years in a UK court for the 2024 ransomware attack on Transport for London. The Transport for London case was the headline. The healthcare part of the plea is the part that matters for this article.
Flowers was arrested at home on September 6, 2024 — three days after the TfL intrusion ended. The NCA says officers caught him mid-attack on two U.S. healthcare organizations: SSM Health Care Corporation and Sutter Health. Search warrants turned up devices holding proof of all three intrusions. In chats that prosecutors entered into evidence, Flowers acknowledged that locking those systems down “might kill some 90-year-old on life support.” The arrest is what stopped him.
The DOJ’s September 2025 indictment against Jubair, still untested in court, ties the broader Scattered Spider crew to roughly 120 intrusions, at least 47 U.S. victims, and more than $115 million in ransom payments between May 2022 and September 2025. Healthcare was not a side project. It was a quarter of the work. Scattered Spider’s tradecraft — SIM swap, voice phishing, MFA bypass via the carrier — works against hospitals because hospitals answer the phone and accept SMS codes, the same way every other enterprise does.
For a small hospital, a regional clinic network, or a healthcare-adjacent vendor, the work is unglamorous and the order matters.
The 110% surge is not a peak. It is the new floor. Healthcare is the most attacked critical-infrastructure sector in the United States for the fifteenth year running, the ransomware crews have learned that vendors are a multiplier, and the people behind Scattered Spider are in court because they tried it on SSM Health and got caught. Next time they may not get caught. The hospitals that handle the next eighteen months well are not the ones with the best vendor security questionnaire. They are the ones who accepted early that the lockmaker is the target, not the lock.

Last week’s Bitdefender numbers said 47.4% of IT teams have only partial or no visibility into the AI tools their employees are using. That is the polite version of the problem.
A sales rep pastes a contract into ChatGPT to “summarize the legalese.” An engineer feeds a production stack trace into a chatbot to debug faster. A marketing manager uploads an entire customer persona deck to an image generator for a slide. None of these people think they are doing anything risky. The data is already gone, and your DLP never saw it leave.
That is Shadow AI. The operating environment of 2026, and the single biggest hole in most SMB security programs right now.
Bitdefender’s 2026 Cybersecurity Assessment put a number on it: 51.8% of IT and security pros said they have full visibility into how AI is used in their company. 47.4% said they have only partial or no visibility. That sounds like a coin flip, but the sub-bullets are worse.
58% of managers said they have complete AI visibility. Among frontline practitioners, the number drops to 45.9%. The strategic layer of the business is making decisions based on a picture that does not exist. The people doing the actual work know they are flying blind. The two groups are not talking about it, or the managers are not listening.
For an SMB with 50 to 500 employees and no dedicated AI governance lead, this gap collapses fast. The first time you find out an employee fed customer PII into a free chatbot is when your general counsel gets the call from your insurance carrier. By then, “shadow” is the wrong word.
It is tempting to treat Shadow AI as a single problem. It is at least four, and they have different fixes.
Public LLM paste-and-go. Employees copy text, code, customer data, or contracts into ChatGPT, Claude, Gemini, DeepSeek, or one of the dozen Chinese-origin models employees install on personal phones to bypass corporate restrictions. Prompts are stored on vendor servers. Some are used for training by default. Opt-out exists but the toggle is buried in settings most users have never opened. Samsung learned this in 2023 when engineers pasted source code into ChatGPT and the company banned generative AI company-wide within a month. Three years later, the same mistake is happening in companies that were not paying attention.
Unauthorized copilots and agents. Microsoft 365 Copilot, Google Workspace Gemini, Slack AI, Notion AI, and Zoom AI Companion have shipped into the SaaS tools you already pay for. Most are enabled by default at the tenant level. Most can be configured to respect your existing data boundaries. Most have not been. When Copilot launches in your M365 tenant and starts surfacing summaries of HR investigations, M&A drafts, or terminated employee folders to anyone who asks in Teams, that is not a Copilot bug. That is your tenant configuration.
Browser extensions and meeting summarizers. Read.ai, Otter, Fireflies, Tactiq, Fathom, and a dozen look-alikes join your Zoom and Teams calls automatically and write transcripts to their own cloud. They often capture audio, video, screen shares, and chat. Some pipe everything to a third-party LLM for the “smart summary” feature. Sales calls, customer calls, board calls — all in scope. Most IT teams have no inventory of these extensions.
Local AI tooling and shadow agents. Engineers running Ollama, LM Studio, or llamafile on a laptop to “keep our data local” sounds good in theory. In practice, those models often pull pre-trained weights from unverified Hugging Face mirrors, ship with no SBOM, and run with no sandbox. SMBs that adopted local AI for “security reasons” are often running unsigned binaries from strangers — the opposite of the security reason they thought they had.

I am going to name specific examples because hand-waving about “AI risks” does not move anyone to action.
EchoLeak (Microsoft 365 Copilot, 2025). Researchers at Aim Labs disclosed a prompt injection vulnerability in Copilot that allowed an attacker to exfiltrate data from a user’s mailbox and OneDrive through a single crafted email. No user interaction beyond receiving the email was required. Microsoft patched it. The class of bug did not go away — every LLM-integrated product has the same shape of problem, and the research community finds new variants every month.
DeepSeek exposure (January 2025). The Chinese AI lab DeepSeek exposed more than a million rows of internal logs, API keys, and user prompts via an unauthenticated ClickHouse database. Any company that had employees using DeepSeek for work had sensitive prompts sitting on an exposed server. No public count of affected corporate users exists, which is itself the story.
Slack AI data leakage pattern. Multiple 2025 disclosures showed Slack AI susceptible to prompt injection through shared files and channels, where hidden text in a document could hijack the AI’s response and exfiltrate data the user had access to. Slack patched. The lesson did not stick — every AI-augmented SaaS tool is in the same boat and the disclosure cadence is a metronome.
The temptation is to write an AI policy and call it done. That does not work. People will use AI tools regardless. The job is to make the safe path the easy path and to know what is happening when it is not. Five moves for a small IT team this quarter.
Turn off generative AI features in your SaaS tenants by default. M365 Copilot, Gemini in Workspace, Slack AI, Notion AI — set them to opt-in per user group, not enabled tenant-wide. The defaults shipped in late 2025 and early 2026 are permissive. Override them.
Publish an approved AI tools list. Three to five tools you have vetted, with the data classification each one is approved to handle. “Approved for public and internal data. Not approved for customer PII, financial records, or PHI.” That single paragraph gives your help desk something to point to when an employee asks “can I use this?”
Make sure tenant-bound AI features are configured correctly. Copilot honors M365 permissions when set up right. The config lives in the Copilot admin center, the audit logs in Purview, and the gaps are the difference between “summarize a public Teams channel” and “summarize every HR investigation in the last five years.”
Block the unsanctioned tools at the network layer. DNS filtering, egress proxy, and CASB products can each take a bite. None of them catch everything. The goal is not perfection; the goal is to make approved tools fast and unapproved ones annoying enough that employees come to IT instead of going around.
Add one line to your incident response plan. “Employee pastes sensitive data into an unauthorized AI tool.” Run the tabletop. You will discover who needs to be on the call, what your regulatory disclosure clock looks like, and which contracts have notification clauses. That tabletop is worth more than another policy doc.
The companies handling Shadow AI well in 2026 are not the ones with the best AI policy. They are the ones that accepted two things early: employees will use AI whether you sanction it or not, and you cannot govern what you cannot see. Everything else — the tool list, the tenant config, the network controls, the runbook — follows from those two facts.
The Bitdefender stat said 47.4% have partial or no visibility. The fix is the unglamorous work of getting your SaaS tenant in order, talking to your teams, and writing down what “approved” means. The work fits in a quarter. The cost of skipping it does not.

The first week of July handed IT teams a worst-case scenario. The interesting part is that the survey data said this was coming.
On Wednesday, CISA added a high-severity SharePoint flaw to its Known Exploited Vulnerabilities catalog. By Thursday, threat actors were actively probing a critical (CVSS 9.8) bug in the official Gitea Docker image, 13 days after disclosure, letting any unauthenticated visitor impersonate any user, including admin. The same day, Progress warned of live exploitation of a pre-auth remote code execution bug in Kemp LoadMaster, a load balancer used heavily in mid-market networks. Adobe patched seven CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic. The Linux kernel dropped a fix for a use-after-free privilege escalation dubbed “Bad Epoll” that an ordinary logged-in user can ride straight to root, including from inside Chrome’s sandbox.
If you read security news, that paragraph sounds normal. That is the problem.
That string of disclosures is not a coincidence and not a fluke. The week of June 29 to July 6, 2026 was ordinary. Run the same exercise next month and you will get a similar wall of CVEs, similar exploitation, similar “patch now” advisories. The cadence is the story.
Bitdefender published its 2026 Cybersecurity Assessment on July 1, surveying 1,200 IT and security professionals across six countries. The headline finding is the one the industry has been quietly avoiding: awareness of cyber risk is at an all-time high, and operational resilience is at an all-time low. The two curves have decoupled, and they are still moving apart.
The numbers tell the same story in different rooms. 51.8% of respondents told Bitdefender they have full visibility into how AI is being used inside their company. 47.4% admitted they have only partial or no visibility into “Shadow AI,” the personal ChatGPT tabs, the unauthorized Copilot installs, the unvetted browser extensions that summarize meetings. When you split that answer by role, the gap is sharper. Nearly 58% of managers believe they have complete AI visibility. Among frontline practitioners, that number drops to 45.9%. The strategic decisions are being made on a picture half the building does not recognize.
The large enterprise has more attack surface, but it also has people whose entire job is to read the CISA KEV catalog on Monday morning and have a remediation plan by lunch. The 80-person logistics company does not. The 200-person law firm does not. The 40-person SaaS startup does not. They have one or two people doing IT, often with no dedicated security hire, and they are reading the same Gitea writeup that a Fortune 500 CISO is reading, except without a team to back them up.
The Bitdefender report is blunt about this part too. “Security teams understand the importance of reducing the attack surface,” it reads, “yet they often lack the skills, resources, or strategy to do so.” That sentence does not get quoted in marketing decks. Awareness without capacity is a tax you pay every quarter and collect no return on.

On the same day the Bitdefender report came out, Microsoft’s Mark Russinovich published a blog post that nobody at a small business had time to read. He announced that Microsoft is pulling its post-quantum cryptography roadmap forward to 2029, two years earlier than the previous schedule. His reasoning: cryptographically relevant quantum computers could arrive sooner than previously expected. For a CISO at a global bank, this is a multi-year migration program. For an IT generalist at a 150-person manufacturer, it is one more line item on a list that is already too long.
The fix is not exotic, though. Microsoft’s own plan rests on three moves small IT teams can start with: adopt TLS 1.3 everywhere you terminate HTTPS, audit where cryptography is hard-coded into your applications and break those couplings, and design for “crypto agility,” meaning your systems can swap algorithms without being rebuilt from scratch. None of this is a 2029 problem. The migration window is what makes it one.
The honest version of a hardening plan for a small team is small. It is not “buy a SIEM.” It is five things, do them this month.
Subscribe to the CISA KEV catalog as an email or RSS feed. Anything that lands on that list gets a 14-day patch or mitigation deadline from the U.S. government. Treat it as a binding SLA. If you cannot patch in 14 days, document why and what compensating control you have in place.
Build a real list of internet-exposed assets. Not a theoretical list. The actual set of hosts, services, and ports exposed to the public internet as of this week. Run an unauthenticated scan from outside your network. The gap between what you think is exposed and what is exposed is where the Gitea bugs live.
Replace “is MFA enabled” with “is MFA enforced on the highest-privilege accounts, with phishing-resistant factors.” Hardware keys (FIDO2) and platform-bound passkeys are not exotic anymore. They are cheap. They are the single highest-ROI control most small businesses are still not using.
Pick one “if this breaks at 2 a.m.” scenario and write the runbook. A Gitea admin compromise, a SharePoint exploit, a VPN appliance RCE, pick the one most likely to hit you, write three pages of what you do, and rehearse it with the team. A 200-person company with a good runbook beats a 2,000-person company with a stale one.
Schedule a 90-minute review of your top five SaaS vendors by data exposure. SOC 2 report, SBOM availability, breach notification clause. The questions alone will reveal the ones that should not be in your stack.
The gap between awareness and resilience is not going to close on its own. The CVE flood is not going to slow down. AI is not going to reduce the attack surface. The post-quantum transition is going to land on the same overstretched IT generalist who is already triaging a Gitea CVE and patching a SharePoint server. The companies that handle the next two years well are the ones that stop pretending awareness is the same as readiness. The job of hardening is unglamorous, mostly invisible, and the actual work of 2026. The week of July 6 made that impossible to miss.

The part no one wants to say out loud: you can’t audit them all.
Last week, a security research firm named Novee published a finding that should make every CIO in the country uncomfortable. A class of vulnerabilities they’re calling Cordyceps — embedded in GitHub Actions workflows — exposed more than 300 public repositories (including those of Microsoft, Google, and Apache) to full supply-chain takeover. An attacker with the right foothold could push poisoned code into the open source packages that millions of applications depend on. The exposure was wide. The blast radius is the entire internet.
If you’re running a 50-person SaaS company or a regional healthcare network, you probably read that story and thought the same thing I did: I don’t control any of this.
That’s the point. Welcome to the supply chain problem.
Five years ago, “supply chain attack” mostly meant a compromised vendor slipping malware into a software update. The SolarWinds incident of late 2020 fit that model almost perfectly. One point of compromise. Investigate, contain, move on.
The 2026 version is messier, broader, and harder to point at. Three stories from the last ten days alone:
Three different vendors. Three different attack surfaces. One common reality for anyone running a small IT team: the things you depend on to ship software, take payments, or run your website are being attacked in ways you cannot see.
The press coverage tends to focus on the household names. Microsoft, Google, Apache, AWS — these are mature companies with serious security teams. If they miss a bug in their CI/CD pipeline or their extension store, it’s news for a week and then they patch.
The same software is sitting in your stack. A 30-person e-commerce business might run its entire operation on a handful of npm packages, a payment processor, an inventory SaaS, and a small fleet of AWS services. Any one of those is a possible entry point. The smaller company can’t audit the source of every dependency, can’t review the security of every SaaS vendor, and almost certainly doesn’t have a Software Bill of Materials to begin with.
A few uncomfortable numbers, courtesy of Verizon’s 2025 Data Breach Investigations Report: 30% of breaches now involve a third-party component, and that share has been climbing every year since 2021. For small businesses specifically, the figure is higher — somewhere around 40%, depending on which report you read.
You don’t have to be the actual target. You just have to be downstream of one.

The honest answer: you cannot eliminate the risk. Anyone who tells you they can is selling you something. But you can reduce the blast radius and catch problems faster. Here’s what I’d actually do this week if I were running IT for a 50-to-500-person company.
1. Inventory your dependencies. Then inventory them again.
You probably have an official list of approved SaaS vendors and on-prem software. That list is incomplete. The real inventory lives in your developers’ package.json files, your DevOps team’s GitHub Actions, your marketing team’s browser extensions, and your sales team’s Chrome plug-ins. Get a Software Bill of Materials (SBOM) tool — CycloneDX or SPDX-format generators are free and plug into most CI systems. You can’t protect what you can’t name.
2. Lock down browser extensions.
The StegoAd case is a reminder that the attack surface you can see is not the only one. Browser extensions run with the same privileges as the user who installed them. Set a corporate policy. Audit which extensions are installed across the team. Don’t allow employees to install extensions on company-managed browsers without a review. This sounds pedantic. It is not.
3. Watch the maintainers, not just the packages.
A growing share of supply chain attacks in 2026 target the humans behind the software. Compromised maintainer accounts. Social engineering of project owners. Hijacked email addresses used for password resets. Miasma works exactly this way. If your business depends on a small open source library maintained by one person in another time zone, that is a single point of failure. Know who they are. Have a contingency plan for what happens if their account gets hijacked.
4. Treat vendor security like vendor pricing.
If you evaluate SaaS vendors on price, uptime, and feature set, add security to that list and make it count. Ask vendors for SOC 2 reports. Ask how they handle dependency updates. Ask whether they have their own SBOM. The answers vary wildly, and the questions alone will weed out vendors who shouldn’t be in your stack.
5. Have an “off switch.”
When the next big npm or Python package gets compromised — and there will be a next one — how fast can you pin your dependencies to known-good versions, roll back your last build, or block traffic to the affected vendor? That is your incident response plan for supply chain failures. Most companies don’t have one. Spend an afternoon writing it.
The uncomfortable trend is that the perimeter is dissolving. The work of securing your business used to mean securing your network, your laptops, and your office. It now means securing every package, every service, every extension, and every developer tool that touches your stack. The number of those things grows every quarter. The number of people you have to secure them with doesn’t.
For a 200-person company, the practical move isn’t to out-tech the attackers. It’s to be a less attractive target than the next 200-person company. That means knowing your dependencies, limiting the third-party surface, and having a plan for the day one of them fails. None of this is glamorous. All of it is the actual job in 2026.

A deepfake video call cost Arup $25M. The same playbook is hitting SMBs every week — and most security programs haven’t caught up.
In early 2024, an accountant at the engineering firm Arup sat down for what looked like a routine video conference. The CFO was on the call. So were several other colleagues. Everyone looked right. Everyone sounded right. The only problem: none of them were real. A finance worker wired roughly $25 million to attackers who had fabricated the entire meeting with deepfake video and cloned voices.
That case made global headlines. The quieter story is the one playing out at thousands of small and mid-sized businesses every week: an “executive” emails an AP clerk asking for a wire transfer, a “vendor” calls about updating payment details, a “Microsoft technician” leaves a voicemail that sounds exactly like your IT director. Generative AI has turned social engineering from a craft into a production line, and most security programs have not caught up.
For most of the last decade, phishing emails were easy to spot. Bad grammar, mismatched sender domains, generic greetings. The defenders’ advantage was that attacks were expensive to personalize at scale. An attacker could blast a million generic “Nigerian prince” emails, or send a hundred highly targeted ones. They chose the first.
That trade-off is gone. Large language models let attackers produce clean, fluent, locally appropriate phishing copy in any language. Voice cloning tools need as little as ten seconds of audio to mimic a specific person. Deepfake video has moved from research demos to real-time face-swaps on a commodity laptop. The cost of a targeted attack has dropped by orders of magnitude, and the volume has followed.
A 2024 study by IBM’s X-Force found that AI-generated phishing emails had a click-through rate about 70% higher than the human-written kind. A separate analysis from the UK’s National Cyber Security Centre warned that the average employee can no longer tell the difference. We are past the point where user-reported “this email felt weird” is a reliable defense.
Three patterns are showing up over and over in incident reports.
1. The impersonated vendor. Attackers research a company’s real suppliers, then email the AP team from a look-alike domain saying banking details have changed. The invoice is real, the dollar amount matches a known contract, and the signature line includes a plausible employee whose LinkedIn profile they scraped last week. AI writes the email in flawless English, including the small talk about the recipient’s recent promotion.
2. The cloned executive. Voice cloning needs a target’s voice from a podcast, earnings call, or public video. Most executives in a public company have hours of this content online. The attacker calls an employee, often outside business hours, with a calm “I’m in a meeting, can you do me a quick favor” request. The request is usually a gift card purchase, a wire transfer, or the disclosure of an MFA code.
3. The deepfake meeting. The Arup case is the template. A fabricated Teams or Zoom meeting with multiple fake participants, all of whom look and sound like real colleagues. The goal is usually authorizing a financial transaction or harvesting credentials. The sophistication has been climbing through 2025 and 2026.

Big banks and tech firms have spent twenty years building layered defenses. They still get hit, but the cost per attempt is high enough to push attackers elsewhere. A 50-person marketing agency or a regional medical practice has none of that. The CEO’s voice is on the company website. The accounting team’s job titles are on LinkedIn. The whole org chart is one Google search away.
The defender’s math is also worse. A large enterprise can absorb a six-figure loss. A small business that loses $200,000 to a fraudulent wire transfer is often looking at layoffs, or closing. Ransomware actors know this, which is why attacks on companies under 200 employees have roughly doubled in the last two years.
There is no silver bullet, but a few practical moves close most of the gap.
Use a verbal callback on any out-of-band financial request. If the CFO emails asking for a wire transfer, call her back on a number you already have. Not a number in the email. A cloned voice sounds real on a first listen, but the attacker cannot answer your callback because they do not control your executive’s actual phone. This one habit stops the majority of BEC fraud in incident data, and it costs nothing.
Treat any change-of-payment-details request as hostile by default. Require that changes be confirmed through a known channel, with a second person signing off. The friction is real. It is also the reason your finance team has not already been robbed.
Train on the new reality, not the old one. Most security awareness programs were built around 2015 phishing: bad grammar, obvious scams, hover-to-preview. Update the curriculum. Show staff real AI-generated phishing samples. Run a tabletop exercise that uses voice cloning. The goal is not to make people paranoid; it is to make them skeptical in a structured way.
Lock down public executive content where you can. You do not have to delete the CEO’s podcast appearances. But you can stop posting new high-quality video of their face and voice on public pages, and you can coach executives to use work accounts for sensitive calls. Audio and video of a person walking through an airport is enough to build a convincing clone.
Adopt phishing-resistant MFA. Hardware security keys (FIDO2/WebAuthn) and platform-bound passkeys cannot be phished by a fake login page, no matter how convincing. They are the single highest-ROI control most small businesses are still not using.

AI has not invented a new category of attack. Social engineering has always worked because humans are the easiest part of any system to fool. What AI did was make the cost curve bend sharply in the attacker’s favor. The defenses that worked when attacks were expensive and rare are eroding, and the ones that work now (out-of-band verification, hardware MFA, structured skepticism) require actual process change, not just another product.
The companies that are handling this well are the ones that stopped expecting email to be a trustworthy channel for money, credentials, or sensitive instructions. That is a cultural shift more than a technical one, and it is the work of the next few years.
If you do one thing this week, pick the highest-risk workflow in your business (the one where a single email or phone call can move money or grant access) and add a verbal callback step. It will feel slow. It is also the reason you will not be in the next incident report.
The December 2024 NPRM ends the “addressable vs. required” loophole. Here’s what healthcare IT teams need to do in the next 90 days.
In February 2024, a single ransomware group compromised Change Healthcare and walked away with the medical records of 192.7 million Americans. That’s more than half the country. The attack vector was almost embarrassingly simple: a Citrix portal without multi-factor authentication.
The company paid a $22 million ransom. UnitedHealth Group, Change’s parent, has since reported breach-related costs north of $3 billion. And yet — until very recently — the federal baseline for protecting patient data hadn’t meaningfully changed since 2013.
That’s about to change. And a lot of healthcare organizations are nowhere near ready.
HHS published a Notice of Proposed Rulemaking on December 27, 2024. Public comments closed in early 2025. The final rule is expected sometime this year, with a compliance window of 6–12 months after publication. The changes are the most significant to the Security Rule in over a decade.
The biggest shift is the end of the “addressable” vs. “required” loophole. Under the current rule, a safeguard can be marked “addressable” — meaning you can skip it if you document a reasonable alternative. In practice, that became an excuse to skip encryption, MFA, and other things organizations didn’t want to budget for. The NPRM basically eliminates that distinction. Things that were “addressable” become required, full stop.
The requirements getting teeth:
If you’re reading that list and feeling a bit of acid reflux, you’re not alone.
The 2013 rule was written for a world of Windows XP workstations on flat networks and clinicians logging in from a single office. The attackers of 2026 are not playing by those rules.
Three patterns define the modern healthcare threat:
Third-party vendors are the new front door. The Change Healthcare breach wasn’t a hospital being hacked. It was a clearinghouse used by virtually every US provider. Ascension’s May 2024 ransomware incident started with a contractor downloading a malicious file. When a single vendor handles billing, scheduling, or credentialing for thousands of practices, that vendor’s security posture becomes your security posture.
Medical devices are a soft target. A 2022–2024 wave of FDA safety communications flagged vulnerabilities in devices from Medtronic, BD, Illumina, and others. Many run outdated embedded operating systems, have hardcoded credentials, and can’t be patched without taking the device offline. The new rule will require device inventories, SBOMs (software bills of materials), and a documented plan for addressing known vulnerabilities.
Initial access brokers are running a SaaS model. Groups like Scattered Spider, BlackCat/ALPHV, and LockBit-affiliated crews specialize in selling access rather than running ransomware themselves. Healthcare organizations with exposed RDP, unpatched VPN appliances, and help desks that don’t do callback verification are paying the price.

You don’t have to wait for the final rule. The practices that get ahead of this now will be the ones that pass their next OCR audit with a handshake instead of a subpoena.
Inventory everything that touches ePHI. Laptops, phones, printers, fax servers, imaging systems, infusion pumps, badge readers that store biometric templates — all of it. If you can’t list it, you can’t protect it.
MFA everywhere, no exceptions. This is the single highest-ROI change. The Change Healthcare attackers walked in through a single Citrix account with no MFA. Don’t let that be your story.
Review your BAAs, then actually test the vendors. A signed Business Associate Agreement is not a security posture. Ask your clearinghouses, billing vendors, and EHR hosting providers for SOC 2 Type II reports and recent penetration test summaries.
Run an actual tabletop exercise. Pretend your EHR is down for 48 hours. Who calls whom? What’s the manual fallback for prescriptions and lab orders? How do you notify patients? Write it down. Then test it again in six months.
Patch the worst things first. CISA’s Known Exploited Vulnerabilities catalog is a free, opinionated list. Work through it. The 15-day SLA for critical flaws isn’t aspirational under the new rule.
If you’re a solo practitioner or a small group, the list above is intimidating. You’re running a medical practice, not a security operations center. The good news: HHS has signaled that some new requirements will scale based on size and complexity. The bad news: “we’re small” has not been a winning defense in OCR enforcement actions for years. The 2024 settlement with Plastic Surgery Associates — $500,000, six affected patients — made that point clearly.
Consider a vCISO arrangement (a fractional security officer, typically $3–8k/month) or a managed detection and response provider that knows healthcare. The per-provider cost is a lot smaller than a breach.
The HIPAA Security Rule is finally catching up to the threats healthcare has been facing for a decade. The final rule will land this year, and the compliance clock will start immediately. The practices that use the next 90 days to get MFA in place, finish their asset inventory, and pressure-test their vendors will spend 2026 focused on patient care. The ones that wait will be explaining to OCR why their Citrix portal didn’t have multi-factor authentication.

Why “we have multi-factor authentication” stopped being a reassuring sentence in 2026 — and what SMBs should do this week.
If you bought MFA in 2020 and forgot about it, this article is for you.
On May 24, 2026, the FBI put out an unusual flash alert. A phishing kit called Kali365 — sold as a subscription on Telegram, of all places — was hitting Microsoft 365 accounts at hundreds of organizations. The headlines screamed that it “bypasses MFA.” A few hours of reading made me realize that’s the wrong way to think about it. Kali365 doesn’t bypass MFA. It bypasses you — the part of the system that is still, embarrassingly, the easiest thing to attack.
If you run IT for a 50-to-500-person company, here’s what changed, why it changed, and what to do before the next vendor breach shows up in your inbox.

For a long time, MFA was the line in the sand. You drew it between “people who got phished” and “people who didn’t.” In 2026, that line is somewhere it isn’t useful anymore.
Three things happened in the last month that I think every IT leader should know about:
1. Kali365 and the rise of consent phishing. The FBI alert describes a kit that tricks a user into clicking “Allow” on a malicious OAuth app. No password is typed. No MFA prompt is shown. The user authorizes an app, the app gets a refresh token, and from that point forward the attacker is the user — until someone revokes the token or it expires. Microsoft 365 sits behind more than a million U.S. companies. Most of them have no idea which third-party apps their employees have already authorized. (FBI warning, May 24, 2026; reported by TechRadar, HotHardware, TechTimes.)
2. CrowdStrike’s 2026 Financial Services Threat Report found that the single most common attacker against banks and insurers last year never phished a password at all. They phished a session. Once a user authenticated successfully, the attacker stole the cookie and rode it across the rest of the network. The report’s framing is sharp: MFA verifies who logged in. It has no idea what they do next.
3. SonicWall CVE-2024-12802. A previously-patched SSL-VPN authentication bypass got re-bypassed by a new flaw disclosed in mid-May. The lesson isn’t about SonicWall specifically. It’s that identity-layer bugs are showing up in the patches designed to fix identity-layer bugs. Every appliance you expose to the internet deserves a second look this quarter.
Put those three stories next to the GitHub breach on May 20 (a poisoned VS Code extension on an employee’s laptop, 3,800 internal repos gone in a single worm) and the picture is hard to argue with: the attackers have moved past your login screen.
When I say “you have MFA,” I want to know which kind. The difference matters more than it used to.
| Method | Can Kali365 / token-theft beat it? |
|---|---|
| SMS codes | Yes. SIM swap, SS7 routing, prompt bombing. |
| Authenticator app (TOTP) | Mostly yes. Real-time phishing proxies relay the code before it expires. |
| Push notifications (Duo, Microsoft Authenticator push) | Yes. Prompt bombing (“are you sure? are you sure?”) and adversary-in-the-middle kits. |
| FIDO2 / WebAuthn / Passkeys (YubiKey, Windows Hello, Apple passkeys) | No. The key is bound to the real domain. A fake login page can’t complete the handshake. |

Microsoft, Google, and CISA have all said, in writing, that FIDO2-based credentials are the only MFA worth buying for new deployments. If your authenticator app has a green “Approve” button, you should be planning a migration. Hardware keys cost roughly $25-$50 per employee. For a 100-person shop, that’s a one-weekend project and a meaningful dent in your attack surface.

If I were running IT at a small business and could only pick five things, this is the list — in order of how much risk it actually buys down:
Turn on conditional access. In Entra ID (Azure AD) or Google Workspace, require device compliance, block legacy authentication, and restrict sign-ins by country or IP range. Legacy auth is where most of the OAuth-token attacks still land. Microsoft has a one-click toggle in the Entra admin center. Do it this afternoon.
Audit OAuth consents. Go to https://myapps.microsoft.com (or the Google equivalent) and click “My Apps.” Look at every third-party app a user has authorized. You will be horrified. Revoke anything you don’t recognize. The Kali365 attack leaves a long trail of “Mailbox.Read” or “Files.ReadWrite” grants with publisher names like “K365Sync” or “CloudBackup365.” Train your finance and HR teams to never click “Accept” on a Microsoft 365 consent screen — full stop.
Move admin accounts to phishing-resistant MFA. Domain admins, finance, anyone who can move money or change payroll. Hardware key only. No exceptions. The single biggest dollar-loss events in 2025 all started with a privileged account.
Set session lifetime to 8 hours or less. A stolen token is only useful until it expires. Shorter sessions mean more re-auth prompts, but the alternative is a 30-day refresh token that an attacker can hand around the dark web.
Watch the post-authentication behavior, not the login. This is the conceptual shift. Push alerts, Slack messages, MFA prompts — those are login-layer signals. You also need post-login signals: which mailbox rules were created, which OAuth grants were added, which file-share permissions were changed in the last 24 hours. Microsoft Defender, Huntress, and a dozen newer tools now do this. Pick one and turn it on.
I don’t say this to scare anyone. The attackers aren’t smarter than they were in 2022. They just got more patient. A Kali365 subscription costs a few hundred dollars a month. An hour of a junior analyst’s time at your company is worth more than that. The economics have flipped, and the defense has to flip with it.
MFA is still the best thing most of you have done. It’s just no longer the last thing. The next layer — what happens after a user proves who they are — is where the work is now. The good news: most of it is policy, not purchases. You can do a meaningful chunk of it this week, before the next alert shows up in your inbox.
Have a question about your own MFA setup? Reply to the newsletter — I read every message. If you want a second pair of eyes on your Microsoft 365 or Google Workspace tenant, that’s exactly the kind of thing we do.
Word count: ~1,090
Three weeks ago, OpenAI confirmed what many in the security community already suspected: two of its employees had their devices compromised through a supply chain attack on TanStack, a popular open-source framework. The attackers made off with internal credentials. OpenAI is not a small business. It has dedicated security teams, strict DevOps hygiene, and resources that most companies would envy. Still, the attackers got in.
That fact should unsettle every small-business owner and IT manager who thinks supply chain security is someone else’s problem.
The numbers from 2026 make the threat concrete. Ransomware attacks against SMBs are projected to rise 40% by year’s end, according to Cobalt. Small businesses report a cyberattack every seven seconds. The average breach costs roughly $254,000 — a figure that puts survival into sharp relief, since 60% of attacked firms close within six months. Those aren’t abstract statistics. They’re the beginning of a conversation about whether your business can absorb that kind of loss.
But the more significant shift in 2026 isn’t the volume of attacks. It’s the target selection and the methods. SMBs now account for 43% of all cyberattacks, per recent industry surveys. And the attack on SAP’s npm ecosystem in late April — a campaign researchers dubbed “Mini Shai-Hulud” — shows exactly how threat actors are exploiting the smaller, less-defended perimeter.
On April 29, 2026, four official npm packages from SAP’s development ecosystem were republished with malicious versions. For roughly two to four hours, anyone running npm install against the wrong version pulled a credential-stealing payload. Researchers found references to the campaign in over 1,000 GitHub repositories — each one a developer’s project, recently poisoned without their knowledge.

The mechanism was a preinstall script embedded in the malicious package. When a developer ran npm install, the script executed silently, in the background, harvesting credentials from the local environment. No zero-day exploit. No sophisticated vulnerability. Just a trusted package, briefly compromised, doing exactly what it was designed to do.
This is the supply chain attack model: compromise the tool, not the target. One successful poisoning can yield hundreds of downstream infections. The attacker invests once; the payoff multiplies across every organization that pulls the poisoned package.
For a small business that relies on open-source dependencies — which is to say, almost all of them — this means your security posture is partially determined by maintainers you’ve never met, at companies you’ve never heard of, whose CI/CD pipelines you’ve never audited. You inherit their risk.

April 2026 brought another quiet shift that compounds the problem. NIST’s National Vulnerability Database, the canonical source that most organizations rely on for CVE information, formally gave up on enriching the long tail of older vulnerabilities. As of mid-April, approximately 29,000 legacy CVEs are now marked “Not Scheduled” — not because they’re resolved, but because NIST no longer has the resources to process them.
New submissions in Q1 2026 ran about a third higher than the same period last year. The NVD is working faster than ever, but falling further behind. Only an estimated 15 to 20 percent of new CVEs receive full enrichment now. That means the detailed analysis, the severity scoring, the context that helps teams prioritize — it’s missing for the majority of newly published vulnerabilities.
For a small business that relies on automated vulnerability scanning, this creates a dangerous gap. Your scanner may flag thousands of CVEs without the context to know which ones are actually exploitable in your environment. You’re flying partially blind just when attackers are getting more sophisticated.
The security community has spent years warning that AI would lower the barrier for threat actors. In 2026, that warning is materializing. Agents are now deploying fully autonomous attack campaigns with no human operator steering the intrusion. Ransomware groups are using AI to identify vulnerable supply chain links faster, to craft convincing phishing content, and to adapt in real time when a lure gets burned.
But AI cuts both ways. The same models that generate convincing social engineering content are being integrated into security tooling — automated threat hunting, anomaly detection tuned to your specific network traffic, and incident response that starts containment before a human analyst finishes reading the first alert. The organizations making progress on defense are the ones treating AI as a force multiplier for their existing team, not a magic solution.
This is where the advice gets uncomfortable, because there is no single fix. Supply chain security requires discipline across multiple layers.
Audit your dependency tree. Most small businesses have more open-source packages in their projects than they’d estimate. Run npm audit or its equivalent regularly. Pin your package versions and review your package-lock.json — don’t let your CI/CD pull unchecked updates from registries you trust by default.
Implement a software bill of materials. A SBOM sounds like enterprise bureaucracy, but the cost of generating one has dropped dramatically. Knowing exactly what you’ve pulled in is the prerequisite for knowing what’s been compromised when the next advisory drops.
Rotate credentials regularly, especially within CI/CD pipelines. The SAP attack harvested developer credentials. Long-lived tokens, unused service accounts, and old deploy keys are the quiet accumulation of technical debt that becomes a breach vector.
Prioritize by exploitability, not just severity scores. With 80% of new CVEs arriving without full NVD enrichment, you need to make your own prioritization calls. If a CVE has a known proof-of-concept exploit in the wild, treat it as critical regardless of what the official score says.
Apply the principle of least privilege to your vendor relationships. The attack on OpenAI started with two employee devices. That means the initial access path didn’t require hacking the company — just one person’s workstation. Your vendors are an extension of your attack surface. Know what access they’ve been granted and why.
The hardest part of supply chain risk is that it moves through channels you don’t control and often don’t monitor. You’re trusting that the SAP developer who republished those npm packages had secure credentials. You’re trusting that the TanStack maintainer’s account wasn’t phished. You’re trusting that the Cemu project’s GitHub builds were properly secured — and 20,000 Linux users learned the hard way that those trusts were misplaced.
Supply chain attacks are not new. What’s new in 2026 is the combination of AI-accelerated exploitation, an overwhelmed NVD, and threat actors specifically targeting the smaller, less-defended organizations in the chain. The attackers have made the math work in their favor: small businesses are profitable targets precisely because they can’t afford dedicated security teams, but they depend heavily on open-source tooling and vendor software that the attackers can compromise at scale.
The good news is that most supply chain attacks have a window. The SAP packages were malicious for two to four hours. If your monitoring is fast enough, you can catch the infection before it spreads. The question is whether your team will be looking when that window opens.
The phone buzzes. Your CEO’s name appears on a text message: “Hey, are you around? Need you to grab some gift cards for a client emergency. I’ll pay you back tomorrow.” It looks legitimate. The number matches. The wording feels normal.
But the number was spoofed, and the voice was cloned from a LinkedIn video posted three years ago. By the time you realize what happened, $12,000 is gone.
This isn’t science fiction. It’s happening to real businesses right now, and the attacks are getting harder to spot.

The FBI’s Internet Crime Complaint Center reported $20.88 billion in losses to cybercrime in 2025 alone. That’s a 26% spike from the year before. More than a million Americans filed complaints.
For small and medium businesses, the math is brutal. Sophos found the average ransomware recovery cost for companies with 100-250 employees hit $638,536 excluding ransom payments. That figure covers downtime, forensic work, lost business, and rebuilt systems. No wonder 75% of SMBs surveyed by CyberCatch said a single ransomware incident could shut them down for good.
And here’s the statistic that keeps chief information security officers up at night: 95% of cybersecurity incidents trace back to human error. Not zero-days. Not sophisticated nation-state tooling. People clicking links they shouldn’t, reusing passwords, or responding to messages that feel urgent and real.
The 2026 Verizon Data Breach Investigations Report, published this spring, surfaced another shift. For the first time in nearly two decades, vulnerability exploitation overtook stolen credentials as the leading initial access method. Attackers aren’t always hacking in. They’re walking through unlocked doors that developers forgot to close.

Phishing has been the top threat to SMBs for years, and it’s not going away. The volume is staggering. According to CyberTec Security’s February 2026 analysis, millions of phishing attempts launch every quarter. SMBs are favorite targets because they’re accessible, often understaffed on security, and frequently lack the awareness training that enterprises run routinely. An attacker can spray 10,000 emails at a Fortune 500 with sophisticated filters working overtime, or they can hit a 50-person accounting firm where everyone shares a single Microsoft 365 admin account.
The human factor compounds the problem. When People.ai analyzed breach causes, they found 68% of cybersecurity incidents came from human error. Human error is cheap to exploit. You don’t need to find a zero-day when an email promising “your payroll is ready” will do.
The thing that separated 2025-2026 from earlier years wasn’t just phishing — it was the weaponization of AI. Deepfake audio attacks emerged as a genuine threat to businesses of every size. The most documented case: a Hong Kong firm where a CFO received a call he swore was his UK-based CEO. Voice, cadence, even background noise. He transferred $25 million in a single afternoon.
AI-generated phishing emails are now indistinguishable from legitimate correspondence. They carry proper grammar, correct tone, and personalized content pulled from LinkedIn profiles or recent company announcements. Spelling errors — once the telltale sign of a fraudulent message — are largely gone.

Most security advice reads like a to-do list that goes nowhere. Here’s what actually moves the needle for SMBs with limited budgets and even more limited time.
Verify first. Any request involving money or sensitive data should go through a secondary channel. Call the person back on a known number — not the one that just texted you. If the CFO calls asking for an urgent wire transfer, hang up and dial the extension you have on file.
Run table-top exercises. Once a quarter, walk your team through a hypothetical breach scenario. Not to scare them, but to build the reflex to question unusual requests. The people who catch phishing attempts most reliably are the ones who’ve thought about what one looks like before they encounter it.
Lock down multi-factor authentication everywhere. Email, banking, cloud storage, remote access tools. If it doesn’t have MFA enabled, it’s a single point of failure. Time-based authentication apps or hardware keys are the gold standard — SMS is better than nothing but remains spoofable.
Practice your incident response before you need it. Know who you’re going to call, what you’re going to disconnect first, and who has the authority to make decisions at 2am on a Saturday. Breaches handled in the first hour cost a fraction of those that spread while teams figure out their own playbook.
Your team isn’t the weakest link in your security posture. They’re your biggest risk and your best defense. Invest accordingly.