InsightHeart Security
Professional security services: Cyber security, Home/Business Security, office surveillance
09/27/2026
ISHSTB – Weekly Tech Brief | Week of Sep 27 – Oct 4, 2026
Main Topic: AI-Driven Cybercrime Moves From Experiment to Operational Threat
The cybersecurity story this week is increasingly clear: attackers are not just using AI to write phishing emails or automate tasks. AI is becoming part of the attack infrastructure itself—while identity remains one of the easiest paths into cloud environments.
1. AI-powered cybercrime at scale
Microsoft disrupted the infrastructure behind “EvilTokens,” a cybercrime service that used device-code phishing to compromise Microsoft accounts. Microsoft estimates the operation affected more than 12,000 email inboxes across 10,000 organizations. The service reportedly lowered the technical barrier for attackers by packaging account-compromise capabilities as a subscription service.
MSSP Action: Review Entra ID sign-in activity, monitor suspicious device-code authentication, strengthen Conditional Access policies, and make sure compromised-session response procedures are tested.
2. AI is becoming part of malware
Researchers reported new malware incorporating LLMs into its decision-making and command-and-control processes. One example, dubbed CLOSEDQUORUM, reportedly uses multiple AI models to determine actions without requiring continuous human direction.
This points toward a future where some attacks can adapt faster than traditional human-driven workflows.
3. Microsoft 365 security is entering the AI-agent era
Microsoft’s September security updates emphasize discovering and controlling AI agents across employee devices, cloud platforms and development workflows. Microsoft is also expanding controls that apply Zero Trust and data-security policies to agent traffic and “shadow AI.”
MSSP Action: Start treating AI agents like identities and applications—not simply productivity tools. Inventory them, define what data they can access, apply least privilege, and monitor their activity.
Bottom Line
For SMBs and nonprofits, the takeaway isn't “ban AI.” It is to understand which identities, applications, agents and data are connected—and what happens if one is compromised.
Identity security + Conditional Access + endpoint visibility + data governance + continuous monitoring should remain the foundation.
09/20/2026
ISHSTB – Weekly Tech Brief | Sep 20–27, 2026
Main Topic: Identity Is Becoming the New Attack Surface
This week’s security news reinforces a trend we’ve been watching closely: attackers don’t always need malware or an unpatched server when they can convince a legitimate user to hand over access.
1. Microsoft 365: Passkey Phishing Gets More Sophisticated
Microsoft has detailed campaigns where attackers impersonate IT/help-desk staff, contact employees by phone or SMS, and direct them to fake Microsoft sign-in pages. Adversary-in-the-middle techniques can capture authentication sessions, allowing attackers to access SharePoint, OneDrive and Exchange data.
MSSP Action: Review Conditional Access, phishing-resistant MFA, risky sign-ins and unusual token/session activity. Train users that a “help desk” request to change MFA or passkeys should be independently verified.
2. Zero-Days Still Demand Fast Response
Microsoft’s September Patch Tuesday addressed a record number of vulnerabilities, including actively exploited Windows flaws. Researchers also reported continued exploitation of browser/Windows vulnerabilities in targeted campaigns.
MSSP Action: Don’t treat patching as a monthly checkbox. Prioritize exploited vulnerabilities, internet-facing systems and high-value identities first.
3. AI Is Accelerating the Threat Cycle
Anthropic reported disrupting malicious operations where threat actors attempted to use Claude to support cyber activity, while researchers continue seeing AI-assisted phishing and malware development.
The takeaway isn't simply “AI is dangerous.” It’s that attackers can increasingly automate research, personalization and parts of their workflow.
4. Supply Chain & Developer Targeting
North Korean-linked WaterPlum activity reportedly compromised at least 30,000 devices across more than 100 countries, with attacks involving malicious developer packages and fake job/interview workflows.
MSSP Action: Treat developers, contractors and remote workers as part of the security perimeter. Restrict ex*****on of untrusted code and apply least privilege to development environments.
Bottom Line
For SMBs and nonprofits, the practical lesson is straightforward: protect identities, not just endpoints.
MFA remains important—but phishing-resistant authentication, Conditional Access, least privilege, monitoring and user verification need to work together.
09/13/2026
ISHSTB – Weekly Tech Brief | Sep 13–20, 2026
Main Topic: Microsoft’s Massive Patch Tuesday + The Next Phase of Identity Attacks
This week brought a major reminder that cybersecurity is increasingly about identity, cloud sessions, and rapid patching—not just passwords and endpoints.
1. Microsoft’s Record-Breaking Patch Tuesday
Microsoft’s September security release addressed roughly 970 vulnerabilities, including two actively exploited zero-days. The scale alone is significant, but the bigger takeaway is prioritization: vulnerabilities being exploited in the wild should move immediately to the top of the remediation queue.
MSSP Action: Don’t treat Patch Tuesday as a monthly checklist. Prioritize actively exploited CVEs, validate deployment, and confirm that critical endpoints and servers actually received the updates.
2. Passkeys Are Being Targeted—But Differently
Microsoft researchers reported active campaigns using passkey-themed social engineering to trick users into actions that ultimately enable identity and cloud compromise. The lesson: even stronger authentication technology doesn't eliminate the human attack surface.
MSSP Action: Pair phishing-resistant authentication with Conditional Access, device compliance, risk-based detection, and user education. Authentication strength and identity monitoring need to work together.
3. Microsoft 365 Sessions Are Becoming the Prize
Recent campaigns are targeting authenticated Microsoft 365 sessions through adversary-in-the-middle phishing infrastructure. Stolen session information can allow attackers to operate after a user has successfully completed MFA.
MSSP Action: Monitor unusual sign-ins, impossible travel, unfamiliar devices, risky OAuth activity and abnormal mailbox/cloud behavior. MFA remains essential, but organizations should also assume that a session can become compromised.
4. AI Is Accelerating Both Sides
New threat-intelligence reporting continues to show threat actors experimenting with AI for reconnaissance, social engineering, malware development and operational scaling.
For SMBs and nonprofits, the answer isn't simply “ban AI.” Establish practical AI governance, protect sensitive data, control access to AI tools, and make sure security monitoring can identify unusual activity.
Bottom Line
The modern attack chain is increasingly identity → session → cloud → data.
For Microsoft 365 environments, the priority should be clear: patch aggressively, strengthen phishing-resistant authentication, monitor identities and sessions, and assume that attackers will continue looking for ways around the controls users already trust.
09/06/2026
ISHSTB – Weekly Tech Brief | Sep 6– Sep 13, 2026
Powered by Insight Heart Security
This Week’s Focus: Microsoft 365 Identity + The Next Evolution of Phishing
Cybersecurity continues to shift from “protect the endpoint” toward protecting identity, sessions, and trusted workflows.
Here are four developments worth watching this week:
1. Passkeys officially move to the forefront
Starting September 1, passkeys became the default authentication experience for Microsoft Entra ID. Microsoft is also moving toward eliminating its own SMS and voice authentication options by February 2027. Passkeys provide phishing-resistant authentication by using cryptographic credentials rather than reusable passwords.
MSSP takeaway: If your nonprofit or SMB still relies heavily on passwords and SMS-based MFA, now is a good time to begin planning the transition toward phishing-resistant authentication.
2. Phishing is getting harder for email filters to recognize
Microsoft reported an active campaign using invisible Unicode characters—sometimes called ASCII smuggling—to disguise malicious content from security controls. The technique demonstrates how attackers are adapting techniques originally associated with AI prompt manipulation for traditional phishing.
3. Teams can become an attack path
Microsoft Threat Intelligence documented attacks abusing external Microsoft Teams collaboration to impersonate IT support, establish trust with victims, gain remote access and deploy malware.
For organizations using Microsoft 365, Teams security deserves the same attention as email security.
4. Fake software downloads remain dangerous
Microsoft researchers also reported campaigns using counterfeit download sites impersonating legitimate software vendors. Trojanized installers can establish persistence and weaken security protections after installation.
Bottom Line
Microsoft 365 security in 2026 isn't simply about turning on MFA.
Organizations should be thinking about:
• Phishing-resistant authentication
• Conditional Access
• Teams external collaboration controls
• Email and identity monitoring
• Endpoint protection
• Software download controls
• User awareness around “IT support” requests
• AI-assisted and AI-targeted phishing techniques
For resource-constrained nonprofits and SMBs, identity is increasingly the security perimeter.
08/30/2026
ISHSTB – Weekly Tech Brief | Aug 30 – Sep 6, 2026
This Week’s Focus: AI Is Compressing the Attack Timeline
Cybersecurity is increasingly becoming a race against time. This week’s developments show attackers gaining speed through AI, while defenders face a growing backlog of vulnerabilities, identity risks, and third-party exposure.
Top Headlines
• AI-powered attacks are moving from theory to reality. New reporting highlights AI agents being used to automate reconnaissance, vulnerability discovery and portions of attack chains. Security teams should assume AI will increasingly reduce the time between initial access and impact.
• Critical ServiceNow vulnerabilities patched. Four flaws affecting ServiceNow’s Now Platform and AI Platform included three rated CVSS 10.0, with potential for unauthenticated code ex*****on and data access. SaaS platforms remain part of the attack surface—not outside it.
• Citrix NetScaler exploitation observed. CVE-2026-8452 has reportedly been exploited in the wild, reinforcing the importance of prioritizing internet-facing appliances when active exploitation emerges.
• PaperCut under active exploitation. Huntress reported reproducing a pre-authentication RCE chain affecting PaperCut NG/MF. Organizations using self-hosted infrastructure should verify exposure and patch status.
• IoT remains an easy foothold. Researchers reported more than 14,500 Dahua devices compromised through credential attacks, authentication bypasses and related techniques. Internet-exposed devices continue to be attractive targets.
What This Means for SMBs & Nonprofits
The lesson isn't “buy more security tools.” It is reduce attacker time and opportunity.
MSSPs and IT teams should prioritize:
1. Patch actively exploited and internet-facing vulnerabilities first.
2. Review Entra ID/Microsoft 365 identities, privileged accounts and legacy authentication.
3. Require phishing-resistant MFA wherever practical.
4. Monitor SaaS, remote-access and edge appliances as part of the attack
surface.
5. Establish clear governance for AI tools, agents and sensitive organizational data.
6. Validate offline/immutable backups and recovery procedures—not just backup completion.
Bottom Line
AI is becoming a force multiplier for both attackers and defenders. Organizations that combine strong identity controls, rapid vulnerability prioritization, continuous monitoring and tested recovery will be better positioned for the next wave.
08/26/2026
Securely harness the power of Microsoft 365 while protecting your organization's data, identities, and collaboration environment. InsightHeart Security helps businesses maximize productivity without compromising security, compliance, or governance.
- Secure Collaboration
- Identity Protection
- Data Security & Compliance
- Microsoft 365 Security Optimization
Partner with InsightHeart Security to enable a safer, more productive workplace.
08/23/2026
ISHSTB – Weekly Tech Brief
Week of August 23–30, 2026
Powered by Insight Heart Security
This Week’s Focus: Cybersecurity Is Moving at AI Speed
The past week reinforced a familiar lesson: attackers are getting faster, while the fundamentals—identity, patching, monitoring and supply-chain security—remain the best defense.
Top Headlines
1. GitLab flaw moves rapidly into exploitation
CVE-2026-19478 is reportedly being actively exploited only days after disclosure. The flaw can allow unauthenticated attackers to modify or delete public projects, highlighting how quickly newly disclosed vulnerabilities can become operational threats.
2. Critical infrastructure faces AI-assisted threats
CISA warned of an active threat involving AI-generated exploit scripts targeting Siemens S7 PLC environments. For organizations supporting infrastructure, this is another signal that AI is reducing the barrier to sophisticated attack development.
3. Medusa ransomware reaches 500+ organizations
CISA reported that Medusa ransomware has compromised more than 500 critical-infrastructure organizations. The campaign demonstrates why ransomware preparedness cannot stop at backups—identity protection, segmentation, detection and incident response matter too.
4. Software supply chains remain a major weak point
Attackers compromised the Rust arrayref crate's maintainer account and introduced malware that executed during compilation. Separately, malicious releases affected other Rust packages with hundreds of millions of downloads.
5. More internet-facing systems are being actively targeted
Zimbra's critical RCE vulnerability and new NetScaler flaws prompted urgent warnings, while Elementor Pro's critical vulnerability could enable remote code ex*****on against vulnerable WordPress sites.
What This Means for Nonprofits & SMBs
For smaller organizations, the takeaway isn't “buy more security tools.” It's to make the basics harder to bypass:
Enforce phishing-resistant MFA wherever possible.
Prioritize internet-facing vulnerabilities and CISA KEV-listed flaws.
Review privileged accounts and third-party access.
Keep WordPress, VPN/remote-access platforms and Microsoft environments patched.
Monitor developer dependencies and software supply chains.
Maintain tested offline/isolated backups.
Establish an incident-response process before an incident occurs.
The 2026 security reality: AI may accelerate the attacker—but strong identity controls, rapid patching, least privilege and continuous monitoring still determine whether that speed becomes a breach.
08/20/2026
3 Ways Microsoft 365 Business with Copilot Delivers Real Value
For nonprofits and small businesses, Copilot helps you:
- Save time on everyday tasks
- Create content faster in Word, Outlook & Teams
- Turn data into actionable insights
Work smarter, stay productive, and focus on growing your impact.
08/16/2026
ISHSTB – Weekly Tech Brief | Week of August 16–22, 2026
Powered by Insight Heart Security
This Week’s Focus: Patch Faster. Reduce Exposure. Assume the Supply Chain Is Part of Your Attack Surface.
Cybersecurity teams are facing a convergence of rapidly exploited vulnerabilities, ransomware, supply-chain compromise, and AI-assisted attacks. For smaller organizations without dedicated security teams, the lesson is simple: speed, visibility, and basic controls matter more than ever.
Top Headlines
1. Microsoft Patch Tuesday: 419 Security Fixes
Microsoft’s August release addressed 419 security vulnerabilities, including 62 rated critical and 357 important. The volume reinforces how AI-assisted vulnerability discovery is changing the patching landscape.
2. Microsoft SharePoint Exploitation Moves Into Ransomware Activity
CISA confirmed that attackers are exploiting a critical SharePoint vulnerability in ransomware campaigns. A public proof-of-concept has also accelerated the risk for organizations running affected on-premises systems.
3. Cybersecurity Tools Become a Ransomware Launchpad
Microsoft warned that China-linked attackers are exploiting a critical vulnerability in N-able software in a supply-chain scenario that could enable ransomware deployment across downstream networks.
4. AI + Software Supply Chain = Emerging Risk
Security researchers are increasingly concerned that AI coding tools can introduce unvetted or even hallucinated open-source dependencies faster than traditional security reviews can detect them.
What This Means for SMBs & Nonprofits
The security perimeter isn't just your firewall anymore. It includes Microsoft 365, SaaS applications, plugins, third-party vendors, open-source packages, endpoints, identities, and AI tools.
MSSP / IT Priorities:
Patch internet-facing systems first.
Prioritize CISA KEV-listed vulnerabilities and actively exploited flaws.
Audit Microsoft 365 and privileged accounts.
Review third-party integrations and vendor access.
Maintain tested, offline/immutable backups.
Establish an approved AI-tool and data-handling policy.
Monitor endpoints and identities—not just network traffic.
Bottom Line:
Attackers don't need to defeat every security control. They only need to find the fastest path through one overlooked dependency, identity, vulnerability, or vendor.
For 2026, cyber resilience means knowing what you expose, patching what matters first, and continuously reducing unnecessary access.
08/09/2026
ISHSTB – Weekly Tech Brief | Week of August 9–16, 2026
Powered by Insight Heart Security
This Week’s Focus: Personal + Professional Security in 2026
Cybersecurity isn’t only an IT responsibility anymore. For SMBs, nonprofits, executives, employees, volunteers, and board members, protecting organizational data increasingly means protecting the devices, identities, and personal information used to access it.
What’s Worth Sharing in 2026?
• 1. Make MFA the minimum
Passwords alone aren't enough. Require MFA everywhere possible, particularly for email, cloud services, financial systems, administrators, and remote access. Microsoft reports that more than 99.9% of compromised accounts don't have MFA.
• 2. Treat every device as part of the security perimeter
Company laptops aren't the only concern. Phones, tablets and personal/BYOD devices can access organizational data. Apply updates, encryption, screen locks, endpoint protection and appropriate mobile/device management. Microsoft specifically recommends protecting both company-owned and personally owned devices.
• 3. Assume phishing can reach anyone
Email isn't the only channel. Phishing can arrive through Teams, SMS, social media, QR codes and other communications. Slow down when a message creates urgency, requests credentials, changes payment information, or asks for sensitive data.
• 4. Secure the cloud — don't just trust it
For Microsoft 365 environments, enable security defaults or Conditional Access, protect administrator accounts, and use anti-phishing, Safe Links, Safe Attachments and data protection capabilities where available.
• 5. Backups must actually be recoverable
Critical data should be backed up automatically, with copies separated from the primary environment. Test restoration regularly — a backup that can't be recovered isn't a recovery strategy.
• 6. Don't forget AI and personal data
Employees and stakeholders should know what information can — and cannot — be entered into public AI tools. Treat AI prompts and uploaded files as potential data-sharing events.
The 2026 takeaway:
Security isn't just about buying another security product. It's about building habits around identity, devices, data, cloud services, backups, AI use and human verification.
For SMBs and nonprofits, consistent fundamentals can still make a major difference.
Click here to claim your Sponsored Listing.
Contact the business
Telephone
Website
Address
2 Bloor Street E, Suite 3500
Toronto, ON
M4W1A8