Threat Intelligence & Commentary

Security briefings and IT field notes
for real-world SMB operations.

Practical security briefings and IT field notes for business owners, operators, and teams who need clear context without the technical noise.

Asteri Blog
Updated Weekly
Every Story Linked to Its Source
Built for SMB Decision Makers
Coverage Areas

The issues that actually show up
inside business environments.

The security and IT topics that come up most often in SMB environments, broken down into areas you can explore.

Identity

Access, MFA, sign-ins, and token misuse

Coverage focused on the ways attackers move through modern cloud identity systems and the controls that still matter for smaller teams.

Backups

Verification, failure visibility, and recovery readiness

Not whether a backup exists, but whether it is current, monitored, and recoverable under real operating conditions.

Patching

Risk windows, active exploitation, and update discipline

Why timing matters, where delays become risky, and how SMB teams can patch without creating constant operational drag.

Operations

Process gaps that become security gaps

Vendor changes, approval loops, remote access, endpoint drift, and the day-to-day decisions that often create the real attack surface.

Earlier stories worth
a second look.

Stories from the past several weeks that are still relevant, newest first.

Microsoft shut down "EvilTokens," a phishing kit that got around password resets.

Microsoft and UK police took down a phishing service tied to more than 12,000 compromised mailboxes that tricked people into entering a sign-in code on a real Microsoft page. In Microsoft 365, block "device code" sign-in for anyone who doesn't need it, and tell staff never to enter a sign-in code they didn't request.

September's Windows updates quietly broke File History backups.

Microsoft confirmed that this month's Windows 10 and 11 updates can stop File History from running while it still looks fine. If any PCs rely on it, make sure another backup is actually completing until the fix ships.

A third-party store app exposed BigCommerce shoppers' contact details.

Attackers used stolen credentials for the Ribon apps to plant scripts in BigCommerce storefronts for five days, exposing customer names, emails, and addresses. Every add-on in your online store can reach customer data, so remove the ones you no longer use.

Fake invoice emails are borrowing real vendor branding and fake reply chains.

Microsoft counted over a million invoice-fraud emails in early August, most aimed at U.S. companies and asking for around $50,000. Before paying a new invoice or changing a vendor's bank details, call them back at a number you already have on file.

Scammers are calling staff and posing as IT to "update" their passkey or MFA.

Two extortion groups have been phoning and texting employees, sending them to fake login pages, then adding their own MFA method to keep access to email and files. Make it a rule that IT never asks for this by phone, and give staff a known number to call back.

September's Patch Tuesday was Microsoft's largest ever, with two flaws already in use.

The update fixes 974 vulnerabilities, including two that attackers were already exploiting to take full control of Windows machines. Confirm it's installed everywhere, starting with any Exchange, SharePoint, or Remote Desktop server that faces the internet.

Security news that's
actually useful to you.

Most security news is written for security researchers. Each week we pick a few stories that matter to smaller businesses and explain what happened and what to do about it, with a link to the original reporting.

We cover identity security, backup and recovery practices, patching timelines, endpoint protection, and the operational process gaps that create real risk for smaller organizations.

If something you read here applies to your business and you're not sure where to start, that's exactly what a free assessment is for.

Not every headline needs panic.
Most need translation.

Asteri helps businesses turn security news into concrete action: patching priorities, backup validation, identity hygiene, and operational controls sized for real SMB environments.