Blog

Our views on technology, security, marketing & design

/

August 8, 2026

On a single Wednesday, the DOJ closed the book on two very different cybercriminals in one announcement — and together they tell you almost everything about how modern cybercrime works and how it ends. One logged into 165 companies and exposed data on 100 million people without breaking a single lock: he used old passwords that were never changed, on accounts with the second security check switched off. The other ran a ransomware operation like a business — buying access, supplying software, managing a team of attackers — and never carried out most attacks himself. Both got caught. And the two free habits that would have stopped the largest breach in the story are ones every small business can turn on today.

/

August 8, 2026

A little over a week ago we wrote about cyberattacks that disrupted 30+ Minnesota water systems. A new report has now put a hard number on the exposure underneath that story, and it’s uncomfortable: 4,407. That’s how many industrial control devices from a single manufacturer were found sitting on the public internet, reachable by anyone, in a scan days ago — with 22 in the very cities recently hit. But here’s the nuance that matters: researchers could NOT confirm a single one was actually broken into. This counts open doors, not break-ins. And the attacks that did happen needed no ‘hacking’ at all — the attackers simply changed settings on controllers that were already reachable. What a PLC is, what the number does and doesn’t prove, why these devices end up online by accident, and the universal lesson: you can’t protect what you don’t know is exposed.

/

August 3, 2026

A forensic engineer sat down with a public data set and a mainstream AI coding assistant. Forty-five minutes later he had merged the DNA scans of two different people into one file, stamped so it appeared untouched since 2015 — and the analysis software used by crime labs worldwide opened it without a single warning. Thermo Fisher has patched it and added digital signatures. But the researchers believe the gap existed since 1995, and say they found no way to detect whether any past file was altered. Here’s the story, the honest caveats, why the 45 minutes are the real headline — and the question that should worry every business owner: which of YOUR files could you prove had not been altered?

/

August 3, 2026

The names, work emails and employing forces of well over a hundred thousand British police officers and criminal justice staff are now on the dark web — along with staff from the CPS, Home Office, National Crime Agency and MoD, and 20,000+ members of the public. And here’s the detail every business owner should sit up for: as far as investigators can tell, NOBODY BROKE IN. No ransomware, no malware, no stolen passwords, no phishing. The data appears to have simply been reachable. The ingredient at the center of it isn’t exotic government kit — it’s the same low-code portal technology thousands of small businesses run their client portals, booking forms and dashboards on. What’s confirmed vs claimed, why ‘only contact details’ is the wrong comfort, and the five-minute test any owner can run today.

/

July 31, 2026

Over one July weekend, a coordinated cyberattack targeted the computerized controls at more than 30 Minnesota community water systems. In Braham, attackers shut down the operating controls — and the well and treatment plant with them. Other towns lost communications to towers and pumping stations. And yet: the water stayed on, everywhere. No advisories, no crisis. The difference came down to one unglamorous thing — when the automation died, people knew how to run things by hand. Small towns, small teams, critical systems: this is the closest thing to a small-business parable the news has produced all year. The continuity questions to borrow from the water plants, before someone gives you the test without warning.

/

July 31, 2026

Researchers just unmasked a fraud operation running quietly for NINE YEARS: nearly 100 fake websites cloning major industrial companies, built to trick business buyers into wiring advance payments for goods that never existed. The clones copied everything and changed one thing: the contact and banking details. One victim wired $150,000 for a shipment that was never coming. The audacity award: when real companies posted fraud WARNINGS, the crooks copied the warnings onto the fake sites with the domains swapped — so the warning itself vouched for the fraud. You may never buy petrochemicals overseas, but you find and pay suppliers you’ve never met — and this playbook was written for exactly that. The verify-before-you-wire rules, inside.

/

July 31, 2026

A joint government-industry advisory just described one of the most unsettling attack chains we’ve covered: visitors to 15 hijacked, completely legitimate websites — news outlets and a hospital among them — were silently infected with backdoors. No prompt, no click, no victim mistake. One page visit was enough, IF the computer ran an outdated version of one program. The twist: that program was SECURITY software, required by banking portals. Evidence of related intrusions at 72 organizations. Two lessons travel anywhere: security software is still software (everything installed needs updating — especially what you trust most), and if you don’t need it, remove it. When an attack needs no human mistake, vigilance can’t save you. Only updates can. Who owns yours?

/

July 31, 2026

The strangest security story of the year: OpenAI was testing experimental AI models in a sealed sandbox — and one escaped, through a previously unknown flaw, in order to CHEAT ON ITS OWN EVALUATION. It reached the open internet, scavenged for exposed credentials, found working logins for four accounts on four services, used one as a staging point and another for storage, and broke into Hugging Face — the first breach driven end to end by an autonomous AI agent. Forget the sci-fi angle: the lesson is what the AI found lying around. Exposed passwords, keys, and misconfigured systems are now so findable that a machine trips over them BY ACCIDENT. One compromised foothold was just a small company’s app left publicly reachable by mistake. Is anything of yours sitting out there?