#smb — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #smb, aggregated by home.social.
-
Ok, so here's another #macOS quirk I need help with.
Occasionally, I rsync files to my TrueNAS and when I want to browse the folders I synced into from MacOS Finder, it says it has no permission to do so (a little red 'x' on the folder).
Once I
get infoon the folder, the 'x' vanishes and it works.Why?
I run rsync as follows:
rsync -avh --no-perms <src> truenas:<dst> -
Why does SMB/Cifs suck so bad and why is there no decent alternative?
-
Windows w praktyce: zjawisko korozji domeny, czyli dlaczego istotne błędy często nie mają swojego identyfikatora CVE
Obecność sztucznej inteligencji w świecie technologii można obserwować na każdym kroku. Pomaga ona w tworzeniu oprogramowania, przyspieszaniu i usprawnianiu prac. Warto zwrócić też uwagę na trend szybkości wyszukiwania i łatania podatności przez producentów, czego przykładem może być Google czy Microsoft. Przyglądając się liczbie łatanych podatności, można zaobserwować rosnący trend –...
#Aktualności #Teksty #Certipy #Checkpoint #Cve #Kerberos #LDAP #Ntl #Smb #Szkolenie #Windows
-
SMB Is Mandatory Now: What macOS Dropping the AFP Client Means for Storage Engineers ― Mitaka Digital | DEV Community
"For four decades, the Apple Filing Protocol quietly underwrote every "just works" file-sharing experience in the Apple ecosystem. That era has ended. Apple deprecated the AFP client in macOS Sequoia 15.5, carried a removal warning through macOS 26 Tahoe, and shipped the macOS 27 "Golden Gate" developer beta with no AFP client at all. If your storage estate still serves Mac clients over afp://, the compatibility gap is live today, not on a future roadmap. …"
#AFP #Apple #CIFS #Samba #SMB #NAS #storage #macOS #networking #sysadmin
-
NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.
Pulse ID: 6a71aa488c89bfcbd2814692
Pulse Link: https://otx.alienvault.com/pulse/6a71aa488c89bfcbd2814692
Pulse Author: AlienVault
Created: 2026-08-04 09:00:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault
-
#Zyxel Raises Security Standards for #SMB s and #MSP s in the Era of #AI Attacks
https://gadgetflux.eu/zyxel-ntareste-guvernanta-securitatii-produselor/
-
CostLoop now has two important discovery features:
1. Inbox scanner via Chrome extension
2. Price-hike detection from billing emailsThe goal is simple:
make SaaS spend visible before it turns into waste. -
Outsmarting Cyber Threats: SMBs Need Multi-Layered Security
If you run a small or mid-sized business, you’ve probably told yourself some version of this story: “We’re too small to be a target. Hackers go after the big fish — banks, hospitals, Fortune 500s.”
I get it. I used to think that too. But a recent piece from AI Security & Compliance News made me sit up straight, and I think every SMB owner needs to read it — or at least this summary.
The rules just changed
For decades, cybersecurity followed a predictable rhythm: attackers find a new trick, defenders patch it, attackers find another trick, repeat. Security teams could mostly keep pace because both sides were, roughly, playing the same speed of game.
That rhythm is broken. Attackers equipped with AI are no longer just adapting to defenses — they’re outmaneuvering and outpacing them at a speed human defenders and older automated tools simply can’t match. And here’s the part that should really get your attention as a business owner: this isn’t some far-off, theoretical risk. It’s already happening, and traditional, reactive security postures can no longer keep up with it.
Wait — attacks without malware?
Here’s the stat that stopped me cold.
Roughly 79% of attacks today don’t use malware at all.That number matters enormously for small businesses, because most of what SMBs invest in — antivirus software, a basic firewall, maybe an EDR tool — is designed to catch malicious files. If there’s no malicious file, there’s nothing for those tools to flag.
So what are attackers doing instead? A few things, all of which are sneakier (and cheaper for them) than writing custom malware:
- “Living off the land”
instead of installing new malicious software, attackers use tools that are already built into your systems — things like PowerShell or remote management utilities — to move around and cause damage. To your systems, it just looks like normal admin activity. - Stolen logins
rather than breaking in through a technical exploit, they simply steal an employee’s password (often through phishing) and log in the front door like they belong there. - Supply chain tricks
they compromise a piece of software or a vendor you already trust, so the malicious code arrives disguised as a routine update. - Misconfigurations
a cloud storage bucket left open, an admin account without multi-factor authentication, a firewall rule that’s too permissive — attackers scan constantly for exactly these kinds of gaps.
None of these leave the obvious fingerprints that traditional antivirus is built to catch. They exploit trust, habit, and human error — which is exactly why smaller businesses, who often don’t have a dedicated security team watching for unusual behavior, are so appealing to attackers. You’re not “too small to be a target.” You may actually be the easier target.
Why “one tool” security doesn’t cut it anymore
The article’s core recommendation for enterprise Security Operations Centers (SOCs) is to move away from relying on a single defensive layer and instead build overlapping layers of detection — behavioral monitoring, network traffic analysis, strict identity controls, cloud configuration checks, and centralized log correlation, backed by people actively hunting for threats that slip through.
That’s great advice. It’s also, frankly, a lot to ask of a 10-person company with no IT department. Enterprises can throw a six- or seven-figure security budget and a dedicated SOC team at this problem. Most SMBs can’t — and honestly, shouldn’t have to.
As the source article puts it, the era of relying on one dominant defense layer is over — an integrated, adaptive, multi-layered strategy is now table stakes for resilience, not an optional upgrade.
What this looks like for an actual small business
Let’s make this concrete.
Imagine a 15-person accounting firm or a small manufacturing shop:- An employee’s email password gets phished on a Tuesday afternoon.
- There’s no malware involved — just a legitimate login, from a slightly unusual location, at an odd hour.
- Without behavioral monitoring, that login looks completely normal. No antivirus alert fires. No malware scanner flags anything.
- By Thursday, the attacker has quietly forwarded invoices to a lookalike domain and is preparing a wire fraud request.
This is exactly the kind of “malware-free” scenario the article warns about — and it’s one that a $40/month antivirus subscription was never built to catch.
How Espresso Labs brings enterprise-grade layers to SMB-sized budgets
This is precisely the gap Espresso Labs was built to close. Instead of asking a small business to piece together — and staff — a SIEM, an EDR platform, a network monitoring tool, an identity management system, and a compliance program on their own, Espresso Labs delivers those layers as one managed, AI-powered service, backed by real humans who actually act on what the system finds:
- 24/7 Security Operations Center — Continuous monitoring, not just alerts sitting in a dashboard nobody checks on a Friday at 5pm. Events are triaged and responded to in real time.
- Endpoint protection (EDR) — Standard protection against traditional malware and ransomware, so the basics are still covered.
- Cloud security monitoring — Automatically flags the misconfigurations and unusual access patterns that “malware-free” attackers rely on, across the cloud apps SMBs increasingly live in.
- Identity-aware device management — Devices are configured, patched, and monitored remotely, closing off the “living off the land” techniques that abuse legitimate admin tools.
- Security awareness training and phishing simulations — Since stolen credentials are one of the top ways attackers get in, training your team to spot phishing attempts closes off that entry point before it becomes a login an attacker can steal.
- Continuous compliance evidence — For SMBs that need to meet frameworks like SOC 2, CMMC, or HIPAA, the same continuous monitoring doubles as audit-ready evidence, instead of a mad scramble every renewal cycle.
The pitch, in plain terms: it’s the multi-layered defense strategy enterprise SOCs are being told they need — delivered as one done-for-you service instead of six tools and a hiring plan you don’t have budget for.
The bottom line
The old assumption — “we’re too small to be worth attacking” — was never fully true, and it’s getting less true by the month as AI lowers the cost and effort of running these attacks at scale.
The good news is that closing the gap doesn’t require building an enterprise security department from scratch. It requires layered visibility, someone actually watching it, and a plan for when something looks off.If you’re an SMB owner and your current security stack is “antivirus and hope,” it might be time for a quick gap check.
EspressoLabs is one place worth a look — but whatever you choose, don’t wait for the Monday-morning disaster to find out your defenses only had one layer.
Sources: AI Security & Compliance News, “AI-Powered Attacks Demand Multi-Layered SOC Defenses Now”, which references the CrowdStrike Global Threat Report via The Hacker News.
Rate this:
#AgenticAI #AI #cybersecurity #Developer #SMB #SMBCybersecurity - “Living off the land”
-
What a Law Firm’s Ransomware Nightmare Can Teach Your Startup
I spend most of my time around developers who think “security” means:
npm audit
and a .env file that’s definitely in .gitignore file.If you browse our (= Espresso Labs) pitch to law firms, you realized: the threat model we’re describing for a 40-person law firm is identical to the threat model for your bootstrapped SaaS, your dev agency, or your local accounting shop.
Only the data changes.
The attacker’s playbook doesn’t.Here’s what I learned, and what I think every SMB owner and every engineer who’s ever been “the security person by default” should take from it.
Law firms are basically unencrypted API keys with a bar license
Think about what a law firm actually is, technically: a small team with admin access to an enormous amount of high-value, high-leverage data — M&A deal terms, litigation strategy, medical records, wire transfer instructions — protected by, in a lot of cases, the same IT hygiene as your uncle’s dentist office.
(It’s ugly – I know)That mismatch between value of data and maturity of defenses is exactly what makes a target attractive, and it’s the same mismatch that makes early-stage startups attractive. You might not have client trust funds, but you’ve got:
- Customer PII sitting in a Postgres instance with one shared root password
- Stripe and AWS keys pasted into a Slack channel from 2023
- A single Google Workspace admin account with no hardware key
- A CI/CD pipeline that, if compromised, is basically a printing press for supply-chain attacks
The page cites a few real incidents worth knowing about if you haven’t followed legal-sector security news: Jones Day disclosed a breach traced back to a phishing attack, a firm handling healthcare records exposed data on roughly 300,000 people, and suspected state-sponsored actors breached a prominent D.C. firm.
None of these firms were careless by industry standards.
They just had the same gap most SMBs have: policies on paper, nobody watching in real time.The “5pm Friday problem” every on-call engineer already understands
The line from that page that actually stopped me was this: what happens when an alert fires at 5pm on a Friday?
Is anyone awake to triage it, understand it, and act — or does it sit in a queue until Monday morning?Every engineer who’s carried a pager knows exactly why that question matters.
An unhandled alert isn’t a paperwork problem, it’s a live incident with a clock running.
Ransomware doesn’t wait for business hours — most operators deliberately trigger encryption routines on Friday evenings because they know IT support windows close. If your “security monitoring” is a Gmail filter and good intentions, you don’t have monitoring — you have a very slow smoke detector.The eight controls, translated into developer
Strip the compliance language off the list Espresso Labs put together for law firms, and it maps almost one-to-one onto a hardening checklist for any small technical team:
Their framing What it actually means for youAccess Control & MFAHardware keys (YubiKey/Passkeys) on your IdP, least-privilege IAM roles, no shared root loginsEncryptionTLS everywhere, encrypted volumes/backups, secrets in a vault (not .env in git)Email SecurityDMARC/DKIM/SPF actually enforced, not just configured; phishing-resistant MFA for finance approvals24/7 MonitoringCentralized logging + alerting (even a scrappy stack: Wazuh, Grafana + Loki, or a cheap SIEM) with someone actually on the hook to respond. Incident ResponseA written runbook you’ve actually rehearsed — who kills prod access, who calls the lawyer (ironic, I know), who notifies customersAudit LoggingImmutable logs of who touched what — your future self debugging an incident will thank youVendor & Third-Party RiskKnow what your SaaS vendors and contractors can touch. That Zapier integration with full Drive access? Audit itSecurity Awareness Five minutes teaching your team to spot a fake DocuSign or invoice-change email saves you a six-figure wire fraud lossNone of this is exotic.
It’s the boring 20% that prevents 80% of real-world incidents, and it’s exactly the stuff that’s easiest to skip when you’re three people shipping features at 2am.Build it yourself, or buy the SOC?
This is really the interesting question for an SMB owner, and it’s a classic build-vs-buy tradeoff, not a moral one.
DIY is very doable if you’re technical (and a security/IT expert).
These are some options that you might want to try (or just use EspressoLabs’ platform):- Identity: Google Workspace/Entra ID + enforced hardware-key MFA
- Secrets: 1Password Teams or HashiCorp Vault instead of Slack pastes
- Endpoint: osquery or a lightweight EDR agent, even on a handful of laptops
- Monitoring: Wazuh (open source SIEM) or a $20/mo Grafana Cloud + Loki setup, feeding Slack alerts
- Backups: restic or borgbackup to an immutable, versioned bucket — test restores quarterly, not never
- Network: Tailscale instead of a flat VPN, so a stolen laptop doesn’t equal a stolen network
Managed makes sense when the “24/7” part is the actual bottleneck.
This is the honest pitch behind Espresso Labs and the other competitors in that space.A two-partner law firm or a five-person agency genuinely cannot staff a real SOC.
Paying for continuous monitoring and incident response is often cheaper and more reliable than one overworked engineer trying to be security, compliance, and IT support simultaneously — which is a real, common failure mode, not a hypothetical.The mistake I’d flag for SMB owners either way: don’t buy point solutions that don’t talk to each other.
Antivirus from one vendor, backup from another, email filtering from a third, none of it correlated — that’s the same “disconnected tools” trap regardless of whether you assembled it yourself or a vendor sold it to you piecemeal.The goal is one place where signals actually connect into an alert a human can act on.
A minimum-viable security checklist for your next Friday afternoon
If you run or work at an SMB and want the 80/20 version of everything above, block a day (or a few hours if you are fast) and do this:
- Turn on hardware-key or passkey MFA for your identity provider, email, and cloud console.
No exceptions for the founder nor the lazy CEO. - Rotate every credential that’s ever touched Slack, email, or a shared doc in plaintext.
- Set up DMARC enforcement (p=reject) on your domain — most companies never get past p=none.
- Write a one-page incident response plan: who has authority to cut off access, who calls customers, who calls a lawyer.
- Test one backup restore, today, for real.
- Ask every SaaS vendor with write access to your data: “what happens if you get breached?” You’ll be surprised how many can’t answer.
None of this requires a five-figure retainer.
It requires about an afternoon and the discipline to actually finish it instead of filing it under “Q3 goals.”The real takeaway
Attackers don’t care whether your letterhead says “LLP” or “Inc.”
They care whether you’re an easy, high-value target.
Law firms are having a rough couple of years for the same reason a lot of SMBs will eventually have a rough week: sensitive data, thin security staffing, and a reactive-instead-of-continuous posture.The fix isn’t glamorous — MFA, monitoring, backups, and a plan you’ve actually rehearsed — but it’s the difference between a Friday night that’s annoying and one that ends your company.
Btw, if you found this useful, I’d love to hear what your own SMB security stack looks like.
Be strong and safe!Rate this:
#AI #devops #entrepreneur #infosec #security #SMB #startups -
@ifun Bei der Gelegenheit könnte man übrigens alte #TimeCapsule ebenfalls Fit für das neue #MacOS machen, indem man #SMB aktualisiert: https://github.com/jamesyc/TimeCapsuleSMB
-
Stop lateral movement with a simple GPO script. Block SMB ports 445 and 139 from non-domain subnets via Windows Firewall, allow trusted IPs (e.g., 192.168.1.0/24), and block outbound SMB to prevent exfiltration. Works on Server 2016-2022. #windows #smb #firewall
https://www.valtersit.com/vault/block-smb-lateral-movement-via-windows-firewall-with-gpo-9e519c/
-
Xerocon London 2026, took place on 8th to 9th July 2026 at Olympia, Kensington. It served as the setting of Xero’s push into “agentic” AI for small businesses, accountants and bookkeepers. The significance of this is that Xero claims to serve 5 million customers globally thus raising the stakes for how it introduces automation without eroding trust or advisor oversight.
Recap here: https://www.techfinitive.com/xero-brings-agentic-ai-to-small-business-finance-at-xerocon-london/
#AccountingSoftware #AgenticAI #Business #FinanceManagementSoftware #SMB
-
The Cheapest Way Into Your Business Isn’t Malware. It’s a Phone Call.
It’s 4:45 on a Friday.
Someone on your finance team gets a call.
The voice is calm, knows the CFO’s name, references a real invoice number, and just needs “one quick correction” on a wire transfer.
Ninety seconds later, the money is gone.Nobody wrote a single line of malicious code to make that happen.
That’s not a scare story. It’s the new baseline. CrowdStrike found that 79% of detections in 2025 involved no malware at all — no virus, no exploit kit, nothing your antivirus was ever built to catch. The attacker just… logged in. Or called. Or asked nicely.
If you run a small or midsize business, 2026 is the year to stop thinking about cybersecurity as “did we install the right software” and start thinking about it as “can someone talk, click, or log their way into something they shouldn’t.”
Here’s what the data actually says, and what to do about it.
Why SMBs, specifically
Big enterprises get the headlines.
Small businesses get the volume.You’re targeted not because you’re important, but because you’re reachable — connected to customers, suppliers, cloud platforms, and whatever IT vendor you outsourced to three years ago and haven’t thought about since.
The numbers make the case on their own. Ransomware showed up in 88% of SMB breaches in Verizon’s 2025 Data Breach Investigations Report. Third-party involvement in breaches doubled to 30%. And business email compromise — the unglamorous, no-malware, “just ask for money” scam — accounted for $2.77 billion in reported losses in the FBI’s 2024 IC3 data.
None of that requires a nation-state hacker.
It requires you to have a weak admin password, an unpatched VPN, or a finance process that runs on trust and speed instead of verification.The good news: if the cheap attacks are what’s working, the fixes are also cheap relative to the risk.
You don’t need to outspend attackers. You need to close the doors they’re actually walking through.Ransomware: still huge, but not the story you think it is
Ransomware isn’t going anywhere — it showed up in that 88% of SMB breaches — but the old mental model of “someone opened a bad attachment” is outdated. Sophos found that exploited vulnerabilities, not phishing emails, were the leading root cause in ransomware cases, and Mandiant has watched attackers get more deliberate: they now go after your backup infrastructure, your identity systems, and your virtualization layer specifically, because that’s what makes recovery expensive instead of routine.
That’s the real shift. Ransomware in 2026 is rarely “one infected laptop.” It’s a combined failure of identity, patching, and recovery planning, and the attacker knows exactly which piece to break first.
The money reflects that. Verizon puts the median ransom payment at $115,000. Sophos puts the average recovery cost — consulting, downtime, lost customers, the whole mess — at $1.5 million. Whatever the ransom demand says on the note, the real bill is usually the business interruption, not the extortion itself.
Your people are the new perimeter
Phishing used to mean a suspicious email. Now it means phone calls, fake IT support tickets, QR codes, and multi-step impersonation that plays out over days, not seconds.
CrowdStrike measured a 442% increase in voice phishing between the first and second half of 2024 alone. Mandiant’s latest data shows voice phishing now accounts for 11% of intrusions — ahead of email phishing at 6%. Somewhere along the way, the phone became a bigger threat than the inbox.
For small businesses, the exposure isn’t technical, it’s cultural. Lean finance teams run on familiarity: “that’s definitely how our vendor sounds,” “the CEO does ask for rush payments sometimes.” Attackers know this, and that’s exactly what business email compromise exploits — not a firewall gap, but a process gap. The single highest-leverage fix here costs nothing but discipline: callback verification on every payment or payroll change, using a number you already have on file, never one provided in the request itself.
Identity is the whole game now
If there’s one sentence to take away from this entire report, it’s this: identity is now the primary battlefield, for both sides.
Verizon names credential abuse and vulnerability exploitation as the top two ways attackers get in. CrowdStrike found that stolen-but-valid credentials were behind 35% of cloud incidents in the first half of 2024. IBM reported that roughly one in three incidents now involves credential theft. And Fortinet found something genuinely unsettling: 1.7 billion stolen credential records circulating on underground forums — meaning the “market” for access into your systems is now industrial-scale, not artisanal.
Multi-factor authentication was supposed to fix this. It helped — but it’s not enough on its own anymore. Cisco Talos found that many organizations they assisted still lacked full MFA coverage, including 19% with no MFA at all on VPN access — one of the most obvious front doors there is.
Meanwhile, Microsoft is seeing 7,000 password attacks per second, and reports that passkeys are succeeding at sign-in far more reliably than passwords ever did. Passwordless authentication has quietly gone from “nice future idea” to “thing you should already be rolling out for your admins and finance team.”
If you do nothing else this year: put phishing-resistant MFA or passkeys on every admin, finance, and executive account. Separate admin logins from daily-use accounts. That one change raises attacker cost more than almost anything else on this list.
The browser is now a front door, not a window
Here’s a stat that surprises people: Unit 42 found that 44% of incidents involved a web browser somewhere in the chain. Malicious redirects, drive-by downloads, stolen session tokens, fake login pages that look pixel-perfect. Mandiant separately documented attackers using help-desk social engineering to steal session tokens straight into SaaS platforms like Microsoft 365 and Google Workspace — no password needed at all.
Treat your browser like the security perimeter it’s become: DNS filtering, managed browser policies, extension review, and session protections for anyone with elevated access. It’s an unglamorous fix, and it matters more than most of the “AI security” tools being pitched to you right now.
Your vendors are your problem too
Verizon’s finding that third-party involvement in breaches doubled to 30% should make every SMB owner pause. You might have decent security. Does your bookkeeper? Your MSP? The logistics company with a login into your inventory system?
Attackers have figured out that the smaller supplier is often the easier target — and just as useful a stepping stone into you. This risk tends to be invisible until it isn’t: an incident happens, and only then does anyone realize a contractor’s account was never disabled, or a vendor had far more access than the relationship ever required.
The fix is unsexy but effective: keep an actual inventory of every third party with administrative access to anything of yours, review those permissions on a schedule, and hold critical vendors to real contractual and logging standards — not just a handshake.
AI didn’t invent new attacks. It made the old ones faster.
Let’s cut through the hype: generative AI is not spawning some new category of attack. It’s making the existing playbook cheaper and more convincing. Better-written phishing emails. Faster reconnaissance. More believable fake support calls. IBM saw infostealer-delivery emails jump 84% in a single year, and Fortinet is now tracking roughly 36,000 automated scans per second hitting the internet — up nearly 17% year over year.
The right response isn’t panic-buying an “AI security” product. It’s tightening the same verification habits that already stop social engineering — because AI is aimed squarely at your people’s judgment, not your firewall.
Where the money actually goes to work
If you’re triaging a limited budget and limited time, here’s the order that matches the actual data, not the sales pitch:
1. Identity first. Phishing-resistant MFA or passkeys for admins, finance, and executives. Separate admin accounts from daily accounts. Kill legacy authentication protocols that don’t support modern MFA at all.
2. Patch what’s exposed to the internet. Firewalls, VPNs, remote access tools, and identity platforms should be on an emergency patch track, not the quarterly one. This is still one of the top entry paths across Verizon, Sophos, and Mandiant’s data.
3. Fix the money process, not just the inbox. Callback verification for wires and payroll changes. Help-desk identity proofing before anyone resets a password or re-enrolls MFA. This single process change addresses the highest-dollar-loss attack path in the entire report.
4. Treat the browser as a control point. Managed browser policies, DNS filtering, and session protections for anyone with real access.
5. Test your backups like you mean it. Not “did the backup job complete” — can you actually restore identity systems, cloud data, and your core line-of-business applications, in the right order, under pressure? Keep at least one immutable or offline copy, because attackers are now targeting backup infrastructure directly to remove your leverage.
6. Audit your vendors like you audit your employees. Because increasingly, they’re the same risk.
Mandiant’s numbers explain why the ordering matters so much: once an attacker is in, the median handoff to a second threat group was 22 seconds, and CrowdStrike’s average breakout time to lateral movement was 48 minutes. There is no “catch it later.” Identity and access controls are the only layer fast enough to matter before an attacker is already three systems deep.
The passwordless shift is no longer optional
One more data point worth sitting with: Microsoft now sees nearly a million passkeys registered every single day, across more than 15 billion accounts that support passwordless sign-in. That’s not an early-adopter trend anymore — it’s the direction the entire industry is moving, and sign-in success rates back it up.
For an SMB, this doesn’t mean ripping out every password overnight. It means starting with the accounts that would hurt the most if compromised — admins, finance, execs — and moving them to passkeys or FIDO2 hardware keys now, while it’s a choice, rather than later, after it’s a incident report.
The bottom line
None of this requires predicting the next zero-day or outspending a nation-state. The attacks doing the most damage to small businesses right now are boring: stolen passwords, unpatched VPNs, a convincing phone call, an over-trusted vendor. Boring problems have boring, achievable fixes — you just have to actually do them, on a schedule, instead of hoping this is the year nobody calls.
Start with identity.
Everything else gets easier from there.The numbers, all in one place
- 88% of SMB breaches involved ransomware — Verizon DBIR, 2025
- 30% of breaches involved a third party, double the year before — Verizon DBIR, 2025
- $2.77B in BEC losses across 21,442 reported incidents — Proofpoint / FBI IC3, 2025
- 442% increase in voice phishing, H1 to H2 2024 — CrowdStrike, 2025
- 79% of detections were malware-free — CrowdStrike, 2025
- 44% of incidents involved a web browser — Unit 42, 2025
- 22 seconds — median handoff window to a second threat group — Mandiant M-Trends, 2026
- 7,000 password attacks per second observed — Microsoft, 2025
- 1.7 billion stolen credential records seen in underground forums — Fortinet, 2025
- 63% of ransomware victims cited a lack of people or skills as a contributing factor — Sophos, 2025
Sources
- Verizon DBIR 2025
- Proofpoint (citing FBI IC3 2024)
- CrowdStrike 2025 Global Threat Report
- Google Cloud/Mandiant M-Trends 2025 & 2026
- Palo Alto Networks Unit 42 Incident Response Report 2025
- Sophos State of Ransomware 2025
- IBM X-Force Threat Index 2025
- Microsoft Security Blog 2025
Rate this:
#AI #cybersecurity #risk #SMB #SMBSecurityBestPractices #technology -
Bruteforcing SMB with domain auth? Hydra's smb module negotiates NTLM sessions, using -m for domain context. Works on Kali, Ubuntu, WSL. #hydra #smb #ValtersIT
https://www.valtersit.com/vault/smb-bruteforce-with-domain-authentication-b6f9ad/
-
Growing a business isn't about doing everything yourself. Our latest feature explores how SMEs are using AI to automate routine work, improve decision-making and free up time for strategy and growth. Featuring insights from Embridge Consulting, Clear Strategy, ScreenHits TV and Intuit, the article looks at why effective delegation now includes both people and AI.
Read the full article here: https://www.techfinitive.com/features/why-every-size-of-busines-must-learn-to-delegate-to-ai/
-
Security Week 2627: поддельные инструменты ИИ как приманка для малого бизнеса
На прошлой неделе исследователи «Лаборатории Касперского» опубликовали разбор ландшафта угроз для малого и среднего бизнеса. По данным отчета, небольшие компании остаются мишенью как для операторов массовых вредоносных кампаний, так и для тех, кто использует подрядчика как точку входа в инфраструктуру более крупной организации. Авторы статьи отдельно отмечают, что в 2026 году одной из главных приманок стали популярные ИИ-сервисы. Главная новость в отчете: с января по апрель 2026 года защитные решения «Лаборатории Касперского» зафиксировали 33 352 атаки на малый и средний бизнес, в которых вредоносное или потенциально нежелательное ПО маскировалось под один из пяти популярных ИИ-сервисов. Это почти в пять раз больше, чем за аналогичный период 2025 года. Всего было обнаружено более 1100 уникальных образцов такого ПО — на 21% больше, чем в прошлом году. В основном это разнообразные троянские программы, в том числе загрузчики, которые подтягивают на скомпрометированную машину дополнительную нагрузку. Среди приманок авторы называют сервис Claude и приложение OpenClaw (бывший Clawdbot, он же Moltbot), ставшие особо популярными в 2026 году. Как и следовало ожидать, чем более на слуху конкретный инструмент, тем выше вероятность столкнуться с его поддельной копией в Сети. Разбивку по типам популярных сервисов, под которые маскировались вредоносные кампании, можно посмотреть на скриншоте выше.
-
Loongson's 3C3000 targets budget SMB servers with 16 LoongArch cores, focusing on practical low-power workloads like file, web, and database hosting.
-
for better, more performant local reverse proxy (through your vps via vpn) go with more cores, more ram. maybe we got spoiled, secondary mkts were affected less and mkts will normalize, some degree of ai crash likely needs to happen
will it be the straw that broke the mkt mkrs back or crash the entire mkt? my personal opine is that several corrections will happen but not a crash; rates are high enough that things won't overheat #stress tests results #monetary policy #black swan events #vix #smb mkt #subprime ai derivatives mkts
-
I wrote an article not long ago which I think might be interesting for this community. Happy to hear your thoughts or ideas. Always open to discussions.
https://blog.mousa-cloud.com/posts/smb-common-mistake
#smb #saas #cybersecurity #cloudsecurity #databreach #research
-
Before FreeBSD 15.0-RELEASE, a planning document applied: <https://github.com/bsdjhb/devsummit/blob/main/15.0/planning.md>. Items included:
― smbfs replacement (v2 or better).
Looking ahead to 16.0-RELEASE, <https://github.com/bsdjhb/devsummit/blob/main/16.0/planning.md> applies. The initial version from BSDCan 2026 was committed four days ago.
I assume that an item for SMB/CIFS will appear in due course.
Cc @emaste
-
ICYMI: The high-traffic trap: Fractl data shows SMBs are pitching the wrong media: Fractl and SparkToro studied 358 data points across 8 industries, finding niche publishers deliver 1.7x higher audience affinity than high-traffic outlets. https://ppc.land/the-high-traffic-trap-fractl-data-shows-smbs-are-pitching-the-wrong-media/ #SMB #DigitalMarketing #ContentMarketing #NichePublishing #AudienceAffinity
-
Retrofit for Apple's Time Capsule: Open-source project keeps SMB alive
With macOS 27, Apple is finally dropping Time Capsule support for Macs. Developer James Chang has published a small hack for it on GitHub.
-
Nachrüstung für Apples Time Capsule: Open-Source-Projekt hält SMB am Leben
Mit macOS 27 dreht Apple endgültig den Time-Capsule-Support für den Mac ab. Entwickler James Chang hat auf GitHub einen kleinen Hack dagegen publiziert.
-
Can a PDF carry a virus? Yes — SMBs are prime targets. A single malicious PDF can install spyware, steal credentials, or trigger ransomware. Scan attachments, limit internal sharing, enforce MFA, train staff. Read more: https://proton.me/business/blog/blog-pdf-virus 🔒📄 #CyberSecurity #SMB #Infosec
-
Mini Bucket 3.6.2: от беты к релизу. Полная установка со скринами и комментариями
Почему Debian 9, PHP 7.0 и никаких фреймворков. И как поднять HTTPS за 5 минут Предисловие для тех, кто не читал первую статью В прошлый раз я рассказал, как хотел сделать две странички для SAMBA и NFS, а получилась панель управления NAS на 20+ страниц. Проект назвал Mini Bucket. Важно: та версия была бета . Сырая, с недоработками, но живая. Её задача — показать концепцию. А народ заинтересовался. Значит, надо доводить до ума. Теперь — версия 3.6.2 . Исправлена куча проблем, добавлена безопасность, появился отдельный домен, форум и вики. И сегодня я по шагам покажу установку со скринами . Но сначала — кратко о том, что изменилось. А потом — чистая практика....
https://habr.com/ru/articles/1043530/
#nas #raspberrypi #debian #control_panel #server_manager #smb #nfs #ftp #rsync #home_nas_server
-
CIFSwitch: Linux-Sicherheitslücke ermöglicht Root-Rechte über CIFS-Komponente