by Gloria Bakerian | Sep 25, 2026 | Cybersecurity
TL;DR EvilTokens used device code phishing to trick employees into approving attacker-controlled Microsoft 365 sessions through legitimate Microsoft authentication pages. Businesses should review whether device code flow is needed, train employees to question...
by Gloria Bakerian | Sep 10, 2026 | Cybersecurity, Artificial Intelligence
TL;DR Fourth-party risk comes from the companies your direct vendors rely on, including cloud hosts, payment processors, software components, support providers, and subcontractors. A small business cannot investigate every company in the supply chain, but it can...
by Gloria Bakerian | Sep 8, 2026 | Cybersecurity
TL;DR Microsoft 365 phishing can steal a signed-in session even after an employee completes ordinary multifactor authentication. The BigBear 2.0 investigation illustrates why businesses should require phishing-resistant authentication for sensitive access, review...
by Gloria Bakerian | Sep 3, 2026 | Cybersecurity
TL;DR Microsoft AI security is shifting toward treating AI agents as active participants in the technology environment rather than ordinary software features. Small businesses should know which agents exist, what information they can access, what actions they can...
by Gloria Bakerian | Sep 3, 2026 | Cybersecurity
TL;DR An effective security alert response starts with ownership. Every important alert should have someone responsible for reviewing it, determining its severity, containing confirmed threats, preserving evidence, and communicating with business leadership. Buying...
by Gloria Bakerian | Sep 2, 2026 | Cybersecurity
TL;DR Law firms are attractive targets for phishing, business email compromise, account takeovers, and data theft because they handle sensitive client information and financial transactions. Strong cybersecurity requires more than antivirus or passwords. Law firms...