Blog
From practice, not from a brochure
What we see every day in company servers, websites and AI roll-outs, written up as guides. Every post ends with a to-do list.
Phishing · 9 October 2026 · 3 min read
A fake Microsoft login window you can't spot by eye: how Browser-in-the-Browser works
In September 2026 researchers described a campaign that leads through DocuSign and Adobe to a perfectly forged Microsoft 365 login window. One simple test exposes it.
Phishing · 9 October 2026 · 2 min read
“Press Win+R and paste”: a fake CAPTCHA has already infected thousands of small-business websites
Netskope found more than 5,400 hacked websites, mostly of small businesses, showing visitors a fake verification. What to do as a user, and how to check your own site isn't one of them.
Website security · 9 October 2026 · 2 min read
Three vulnerabilities in WordPress itself, exploited in attacks. What a site owner must do
In July and September 2026 CISA added three vulnerabilities in WordPress core to its catalogue of actively exploited ones. That's rare: usually plugins are the problem. A 15-minute checklist.