Skip to main content

Scotchtown Technology

Check Out

Category: Security

The Scam Surge Hitting Business Owners Right Now and What Actually Stops It

The Scam Surge Hitting Business Owners Right Now and What Actually Stops It

The volume of fraudulent texts, fake bank alerts, and counterfeit delivery notices landing on business owners’ phones has increased sharply to start the year, and the timing is not accidental. Scammers operate with the same seasonal awareness that legitimate businesses do, targeting periods when inboxes are full, attention is divided, and the combination of post-holiday […]

Continue Reading

Why Your Business Is Probably One Software Update Away From a Serious Security Problem

Why Your Business Is Probably One Software Update Away From a Serious Security Problem

The cybersecurity conversation in most businesses focuses on the perimeter: the defenses that keep attackers from getting in through the front door. What that conversation frequently misses is that modern software does not have a single front door. It has hundreds of them, in the form of third-party libraries, open-source components, cloud services, and automated […]

Continue Reading

When the Cybersecurity Professionals Are the Threat

When the Cybersecurity Professionals Are the Threat

Two U.S.-based cybersecurity professionals have pleaded guilty to participating in ransomware attacks carried out under the ALPHV BlackCat affiliate program, including at least one successful extortion and multiple attempted ones. A third individual remains under investigation. These were not outsiders who stumbled into the cybersecurity industry as cover. They were trained practitioners with the kind […]

Continue Reading

A Maximum-Severity SmarterMail Flaw Is Giving Attackers a Free Pass to Your Server

A Maximum-Severity SmarterMail Flaw Is Giving Attackers a Free Pass to Your Server

Business email servers sit at the center of daily operations, which makes them a high-value target. When a maximum-severity flaw surfaces in widely deployed email software, the window between disclosure and active exploitation can close fast. That is the situation with CVE-2025-52691, a critical remote code execution vulnerability in SmarterMail that earned a perfect 10.0 […]

Continue Reading

The Security Risks Hiding Inside Your Network Are the Ones Most Small Businesses Are Not Watching

The Security Risks Hiding Inside Your Network Are the Ones Most Small Businesses Are Not Watching

Most small businesses have invested something in perimeter security. There is a firewall at the network edge, antivirus software on workstations, and some version of an understanding that the boundary between the internal network and the internet is where threats need to be stopped. That investment is not wasted. But the threat model it addresses […]

Continue Reading

A Logging Tool Running Inside Every Major Cloud Platform Has Serious Security Flaws

A Logging Tool Running Inside Every Major Cloud Platform Has Serious Security Flaws

Researchers at Oligo have published findings on critical vulnerabilities in Fluent Bit, an open-source log processing tool deployed across AWS, Google Cloud, and Microsoft Azure, as well as inside container environments and Kubernetes clusters running on those platforms. The vulnerabilities allow attackers to manipulate log data, bypass authentication controls, and execute arbitrary code on affected […]

Continue Reading

ASUS AiCloud Routers Have a Critical Vulnerability and Attackers Are Already Looking for Them

ASUS AiCloud Routers Have a Critical Vulnerability and Attackers Are Already Looking for Them

ASUS has issued an urgent security advisory and released a firmware patch addressing CVE-2025-593656, a critical authentication bypass vulnerability in its AiCloud remote-access feature. The flaw allows an attacker to access the router without valid credentials and execute operating system level commands remotely. If your organization has an ASUS router with AiCloud enabled and has […]

Continue Reading

Cybercriminals Stopped Trying to Break AI’s Rules and Started Building Their Own

Cybercriminals Stopped Trying to Break AI’s Rules and Started Building Their Own

Researchers at Palo Alto Networks’ Unit 42 have documented what happens when cybercriminals stop attempting to circumvent the guardrails on legitimate AI systems and simply build their own without any. The two underground language models they analyzed are not experimental projects or proof-of-concept demonstrations. They are functional tools, trained on stolen code, leaked datasets, and […]

Continue Reading

A Hashtag Is Now a Weapon, and Your AI Browser Does Not Know the Difference

A Hashtag Is Now a Weapon, and Your AI Browser Does Not Know the Difference

Security researchers at Cato Networks have documented a technique called HashJack that allows attackers to embed hidden instructions inside URLs and have those instructions executed silently by AI-assisted browsers. The mechanism is a fragment identifier, the portion of a URL that follows the hashtag symbol, a component that web servers never process and that traditional […]

Continue Reading

Your Calendar Is Now a Phishing Vector, and Most Teams Have Not Noticed

Your Calendar Is Now a Phishing Vector, and Most Teams Have Not Noticed

The calendar application sitting at the center of your workday has become an active target for a category of attack that most organizations have not incorporated into their threat awareness. Security researchers have identified a pattern of abuse targeting calendar subscription features in Google Calendar, Outlook, and Apple Calendar, where malicious events appear directly in […]

Continue Reading

FREE REPORT

Free IT Assessment Report

The Hudson Valley Business Owner's Guide To I.T. Support Services And Fees

"What You Should Expect to pay for I.T. Support For Your Hudson Valley Business"

[contact-form-7 id="afc3d58" title="Free Report Form"]