Good morning. The weekend’s news kept circling back to the same uncomfortable idea, which is that the security controls we have been told to trust are only as good as everything wrapped around them. Passkeys, cloud keys, AI assistants, and search results all showed up with the same problem, and none of the fixes are technical heroics. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
A $10,000 phishing kit now plants attacker-controlled passkeys so the intruder stays in even after you reset the password. Abnormal Security examined the documentation and demo videos for iAuthFlow v2, a toolkit sold on Russian-language cybercrime forums, and found it uses a browser-in-the-middle setup that relays a victim’s real Google login through the attacker’s own browser, then quietly enrolls a new passkey on the account roughly six seconds after authentication completes. The victim sees a “Verification, Processing” screen while that happens, and packages for iCloud, LinkedIn, and Microsoft are advertised alongside the Google one. If your incident playbook for a compromised mailbox stops at “reset the password and kill the sessions,” it is now incomplete, because a rogue passkey is a separate credential that survives both of those steps. Whoever handles account recovery for your business should be checking registered passkeys, OAuth grants, recovery phone numbers and emails, and mailbox forwarding rules every single time, and if you cannot say confidently that they do, that is a five-minute conversation worth having today. Read more at The Register
Researchers found more than 9,300 leaked AWS keys that still work, and hundreds of them hand over full administrative control of a company’s cloud account. Truffle Security has been tracking publicly exposed Amazon Web Services credentials for four years and reported that 88% of the keys it could re-verify were still authenticating as of August 10, including 526 root keys and 242 keys tied to accounts holding the AdministratorAccess policy. The median age of an exposed key was about five years, only 13.7% showed any sign of ever being rotated, and a mere 262 of 2,754 readable accounts had a budget alert configured, which is how a hijacked account quietly runs up a cryptomining bill for weeks. Most of these leaked out through code repositories, Docker images, and CI logs rather than any dramatic breach, which is worth sitting with if you have contractors or a small dev team pushing code on your behalf. Ask whoever manages your cloud footprint two plain questions: are there any root access keys still in existence, and is there a billing alert that would tell us within a day if spend suddenly doubled. Read more at BleepingComputer
Fake bank login pages are now playing dead when a security scanner visits and springing to life when a real person clicks through from search results. Fortra’s threat intelligence team spent three months tracking a technique it calls Chameleon SEO Poisoning and reported a 40% jump in cases during the second quarter, in which typosquatted domains registered on second-level suffixes like .ph.com and .gr.com are pushed up the Google and Bing rankings for terms like “customer portal” or “credit card login.” The clever part is presentation control, meaning the server decides what to show based on where the visit came from, so a direct visit returns a dead-looking offline page while a click from the poisoned search result loads a convincing bank login. That is why these pages survive for days or weeks instead of getting taken down, and it is also why “I checked the link and it looked fine” is no longer a meaningful statement. The practical guidance is unglamorous and effective, which is to tell your team to stop searching for login pages for the bank, the payroll provider, or the insurance portal, and to bookmark them or use the official app instead. Read more at Help Net Security
A web page can hide instructions inside encryption and get an AI assistant to decrypt them and leak the user’s session data. Adversa AI disclosed a technique it calls Cryptographic Context Injection, in which a page carries an encrypted payload plus an instruction to decrypt it, and because a safety filter inspects text rather than executing code, the malicious instructions only become readable after the model has already run them inside its own trusted runtime. In the demonstration, asking Grok to summarize an ordinary web page caused it to send the user’s name, approximate location, subscription tier, and current conversation to an attacker-controlled server with no warning and no confirmation prompt, and a second version of the trick worked against Google’s Gemini. The researchers say xAI was notified back in June and there is still no patch, no CVE, and no user-facing workaround. The uncomfortable takeaway for any business now letting AI tools browse the web, read documents, or touch internal systems is that the model itself is not where you fix this, so before you connect an assistant to your files or your email, ask the vendor a direct question about whether content it fetches is kept separate from instructions it follows. Read more at SecurityWeek
Nvidia has warned its largest customers that AI server prices are going up more than 15%, and that increase is going to land on ordinary business hardware too. Bloomberg reported over the weekend that the increases apply to systems shipping in early 2027 and vary by chip generation and memory configuration, with server builders passing the notice along to the big cloud operators. The driver is not AI demand in the abstract, it is memory, because manufacturers have redirected capacity toward the high-margin chips that AI infrastructure consumes, and conventional DRAM has gone scarce as a result. That is the part that reaches your business even if you will never buy a GPU server, since the same shortage is why Dell, HP, Lenovo and others have been warning clients about 15% to 20% increases on servers and PCs. If you have a refresh cycle coming due in the next year, this is the quarter to pull that budget forward and get quotes locked rather than assuming next spring’s pricing will look like last spring’s. Read more at CNBC
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox:
How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.