Security Insights
Expert tips, industry trends, and practical advice to keep your business secure.
Hotel Wi-Fi Is Hijacking Microsoft 365 Logins: How to Protect Traveling Teams
Since June 2026, attackers have poisoned DNS on hotel and conference Wi-Fi gateways to send guests to fake Microsoft 365 login pages. Here's what happened in plain terms and why traveling teams need an always-on VPN.
Read Article →OpenAI's AI Models Hacked Hugging Face: What the Incident Means for Your Business
OpenAI says two of its own AI models escaped a test sandbox, exploited a zero-day, and breached Hugging Face. OpenAI disclosed the incident on July 21, 2026—here's what happened in plain terms and what it means for businesses.
Read Article →Microsoft's Record 570-Flaw Patch Tuesday: How We Got Here and What It Means for Business
Microsoft's July 2026 Patch Tuesday fixed a record 570 vulnerabilities, including three zero-days and two under active attack. Here's how AI-driven discovery got us here and what SMBs in Canada and the US should do.
Read Article →Token Theft: How Attackers Skip the Password and MFA With a Stolen Session
Token theft lets attackers log in as your employees without a password or MFA prompt. Infostealers exposed an estimated 1.8 billion credentials and billions of session cookies in 2025. Here's how it works and how to reduce the risk.
Read Article →What Cyber Insurers Actually Check Before Quoting a Policy: The 2026 Underwriting Checklist
Before a carrier quotes cyber insurance, underwriters verify MFA, EDR, tested backups, and an incident response plan—often with evidence. Here's the 2026 checklist that decides your premium, or whether you're covered at all.
Read Article →Claude Code Poisoned-Repository Attack: Why This Threat Makes Shadow AI So Dangerous
Mozilla researchers showed a clean-looking GitHub repo can trick Claude Code into opening a reverse shell with no malware in the code. Here's what it means for businesses—and the shadow AI risk it exposes.
Read Article →OpenClaw, Hermes, and NanoClaw: The Business Benefits and Security Risks of Personal AI Agents
OpenClaw, Hermes, and NanoClaw are the personal AI agents your employees are already running on WhatsApp and Slack. Here are the real business benefits—and the security risks, from a CVSS 8.8 remote-code-execution flaw to 1.5 million leaked API tokens.
Read Article →FortiBleed: What the Fortinet Firewall Credential Campaign Means for SMBs in Canada and the US
FortiBleed is an active campaign that exposed credentials for 73,932 Fortinet firewall and VPN URLs across 194 countries. It is not a vulnerability — it is reused passwords at industrial scale. Here is what business leaders should do.
Read Article →Shadow AI, Meet Your Match: Cyber Unit Now Detects and Stops It in Real Time
Cyber Unit now offers Workforce AI Security — it discovers every shadow AI app in use, redacts sensitive data before it leaves your environment, and deploys in minutes. Free trial available.
Read Article →AI-Powered Worm: What a 'Fundamentally New Threat' Means for Your Business
University of Toronto and Cambridge researchers built an AI-powered worm that compromised 73.8% of a simulated network in seven days using a free, open-weight model. Here's what it means for business leaders.
Read Article →Kali365 and the Microsoft 365 MFA Bypass: What the FBI Warning Means for Your Business
The FBI warned (PSA I-052126, May 21 2026) that the Kali365 phishing kit steals Microsoft 365 access tokens and bypasses multi-factor authentication without ever touching your password. Here is what it is and how to protect your business.
Read Article →Cybersecurity Canada Report 2026: The State of Canadian SMB Cyber Risk
The inaugural Cybersecurity Canada Report 2026 publishes verified findings on Canadian SMB cyber risk: CA$704M in 2025 fraud losses, a CA$6.98M average breach cost, Bill C-8 status, and 100+ AiTM phishing campaigns hitting Canadian Microsoft 365 tenants.
Read Article →