Recent Weeks
Earlier stories worth
a second look.
Stories from the past several weeks that are still relevant, newest first.
Identity
Microsoft shut down "EvilTokens," a phishing kit that got around password resets.
Microsoft and UK police took down a phishing service tied to more than 12,000 compromised mailboxes that tricked people into entering a sign-in code on a real Microsoft page. In Microsoft 365, block "device code" sign-in for anyone who doesn't need it, and tell staff never to enter a sign-in code they didn't request.
Backups
September's Windows updates quietly broke File History backups.
Microsoft confirmed that this month's Windows 10 and 11 updates can stop File History from running while it still looks fine. If any PCs rely on it, make sure another backup is actually completing until the fix ships.
Vendor Breach
A third-party store app exposed BigCommerce shoppers' contact details.
Attackers used stolen credentials for the Ribon apps to plant scripts in BigCommerce storefronts for five days, exposing customer names, emails, and addresses. Every add-on in your online store can reach customer data, so remove the ones you no longer use.
Phishing & Fraud
Fake invoice emails are borrowing real vendor branding and fake reply chains.
Microsoft counted over a million invoice-fraud emails in early August, most aimed at U.S. companies and asking for around $50,000. Before paying a new invoice or changing a vendor's bank details, call them back at a number you already have on file.
Identity
Scammers are calling staff and posing as IT to "update" their passkey or MFA.
Two extortion groups have been phoning and texting employees, sending them to fake login pages, then adding their own MFA method to keep access to email and files. Make it a rule that IT never asks for this by phone, and give staff a known number to call back.
Patching
September's Patch Tuesday was Microsoft's largest ever, with two flaws already in use.
The update fixes 974 vulnerabilities, including two that attackers were already exploiting to take full control of Windows machines. Confirm it's installed everywhere, starting with any Exchange, SharePoint, or Remote Desktop server that faces the internet.