8776363957
Connect with us:
LinkedIn link
Facebook link
Twitter link
YouTube link
Gigabit Systems logo
Link to home
Who We AreManaged ServicesCybersecurityOur ProcessContact UsPartners
The Latest News in IT and Cybersecurity

News

A cloud made of diagonal linesA cloud made of diagonal lines
A pattern of hexagons to resemble a network.
Technology
Cybersecurity
Mobile-Arena

Your Phone Might Be Spying on You

December 7, 2025
•
20 min read

Your Phone Might Be Spying on You

A New Spyware Campaign Targets Android Users

ESET cybersecurity researchers have uncovered six malicious Android apps capable of recording conversations, stealing private messages, and remotely accessing devices — all without the user ever realizing it.

While these apps primarily targeted victims in India and Pakistan, the threat is a critical reminder for U.S. smartphone users, SMBs, healthcare organizations, law firms, and schools:

once a malicious app is installed, the attacker owns the device.

How the Attack Worked

The spyware, powered by a remote-access trojan known as VajraSpy, was hidden inside seemingly harmless chat and messaging apps, including one called WaveChat.

Once installed, these apps could:

  • Record calls and background audio

  • Extract WhatsApp and Signal messages

  • Access stored files and images

  • Monitor activity silently in the background

  • Send stolen data to attacker-controlled servers

ESET believes the operators used honey-trap romance scams to trick victims into downloading the infected apps — a classic social engineering tactic.

What Was Found on Google Play

Researchers identified 12 total spyware apps, including six that appeared on the Google Play Store, where users downloaded them more than 1,400 times.

Even though Google removed the malicious apps, the incident highlights a major gap:

App stores are not perfect filters. Malicious apps still slip through.

Why U.S. Users Must Still Care

Although this specific campaign didn’t target Americans, the vulnerability is universal.

Any user — anywhere — who downloads the wrong app can expose:

  • Private messages

  • Financial data

  • Location history

  • Microphone and camera access

  • Corporate login credentials

For SMBs and regulated industries, a single compromised device connected to company email or cloud resources can become an attacker’s direct entry point into the business.

This is how ransomware begins.

This is how breaches spread.

This is how organizations lose everything.

What This Means for SMBs, Healthcare, Law Firms, and Schools

Bring-Your-Own-Device environments drastically widen the attack surface.

When employees install unvetted apps, attackers gain:

  • A foothold inside your network

  • Access to contact lists and corporate messages

  • Authentication tokens for cloud services

  • Potential pathways to EHR systems, case files, and student data

This isn’t just a “consumer phone problem.”

It is a business-level security risk requiring policy, oversight, and mobile device controls.

The Provocative Takeaway

If an app can access your microphone, messages, and files, then so can the attacker who built it.

Your biggest cybersecurity threat might already be in your pocket.

70% of all cyber attacks target small businesses, I can help protect yours.

#️⃣ #cybersecurity #MSP #androidsecurity #spyware #managedIT

AI
Technology
Cybersecurity
Must-Read

Malicious VPNs Are Exploiting Billions

January 12, 2026
•
20 min read

Malicious VPNs Are Exploiting Billions

A Global Warning From Google

Google has issued one of its most urgent security advisories to date—this time not about browser exploits, Android vulnerabilities, or malicious calendar invites, but about fake and weaponized VPN apps targeting billions of smartphone users.

In a world where VPN use is skyrocketing, threat actors are exploiting the moment. Legislative changes, online restrictions, and privacy concerns have driven users—especially younger adults and high-risk consumers—to download VPNs at record levels. Cybercriminals have taken notice, and the results are dangerous.

How Attackers Weaponize “Free” VPNs

Google’s Trust & Safety team warns that attackers are distributing malicious applications disguised as legitimate VPN services across app stores, websites, and social media campaigns.

These fake VPNs often use:

  • Sexually suggestive ads

  • “Privacy protection” claims

  • Promises of unrestricted browsing

  • Free or unlimited access

Behind the scenes, they deliver:

  • Password-stealing malware

  • Remote-access trojans

  • Credential harvesting tools

  • Cryptocurrency wallet theft

  • Full exfiltration of browsing history, messages, and financial data

In other words:

The very app people install for privacy becomes the tool that destroys it.

Why SMBs Are Also at Risk

While consumer users are the easiest targets, businesses are not exempt.

Fake VPN apps installed on personal smartphones used for work—especially in healthcare, law firms, and education—can directly compromise:

  • Corporate email

  • Client records

  • Case files

  • PHI and student data

  • Remote access credentials

  • Cloud systems

Shadow IT has always been dangerous, but malicious VPNs raise the stakes dramatically. A single infected phone accessing corporate resources can become an attacker’s perfect entry point.

How a VPN Actually Works

A VPN creates an encrypted tunnel between the user’s device and a remote server. That server handles DNS requests and forwards traffic to the internet, masking the user’s real IP address.

This architecture means the VPN provider can see:

  • Your traffic

  • Your DNS queries

  • Your connection metadata

  • Your browsing history

So the core question becomes:

Do you trust the operator running the tunnel?

With malicious VPNs, the answer is clearly no.

Trusted VPN vs. Fake VPN: The Difference Is Everything

Legitimate enterprise VPNs are designed for authenticated, encrypted access to corporate environments.

But fake consumer VPNs exploit the exact same architecture to perform surveillance and data theft.

Security experts, including the U.K. National Cyber Security Centre, advise organizations to:

  • Prefer native operating system VPN clients

  • Avoid unnecessary third-party VPN software

  • Enforce updated, validated security stacks

  • Block untrusted apps on corporate devices

When a VPN is compromised, every packet of data passing through it becomes compromised as well.

The Provocative Takeaway

The rise of malicious VPN apps exposes a hard truth:

Cybercriminals no longer need to break into your device—they just convince you to install the door.

For SMBs, healthcare organizations, schools, and law firms, the path forward is clear:

strict app-allowlisting, mobile device management, and guidance from an MSP who can prevent these threats before they reach your users.

70% of all cyber attacks target small businesses, I can help protect yours.

#️⃣ #cybersecurity #MSP #managedIT #dataprotection #malware

Technology
Science
Travel
AI

AI Isn’t Ready To Land A Plane

December 10, 2025
•
20 min read

AI Isn’t Ready To Land A Plane

When Curiosity Meets Critical Infrastructure

A recent Airbus A320 simulator experiment—where a YouTuber asked ChatGPT to guide him after “both pilots went missing”—has captured global attention. It’s entertaining, creative, and undeniably bold.

But beneath the spectacle lies a far more serious lesson for every SMB, healthcare provider, law firm, and school relying on AI tools today:

AI can assist, but it cannot replace human training, judgment, or operational controls.

The Simulator Experiment

Using a professional-grade HeronFly Airbus A320 simulator in Spain, the YouTuber gave ChatGPT full responsibility for getting the plane safely on the ground.

The AI responded with a detailed 50-minute step-by-step breakdown—identifying cockpit controls, autopilot modes, ILS frequencies, flap configurations, and descent profiles.

It even coached the user into a workable approach and soft touchdown.

But then something happened that matters far more than the “successful” landing…

AI Handles the Script—Not the Chaos

While ChatGPT helped with:

  • Cockpit orientation

  • Autopilot adjustments

  • Runway alignment

  • Manual flare and touchdown guidance

It completely failed at the unscripted part: stopping the aircraft.

The plane barreled off the runway and plowed through simulated Spanish villas because the AI never instructed the pilot to brake or apply reverse thrust.

This is the exact gap security professionals warn about:

AI performs impressively when conditions match its training, but it collapses under real-world variation.

The Real Lesson for SMBs and IT Leaders

Your organization may already rely on AI copilots for:

  • Drafting emails

  • Writing policies

  • Identifying security risks

  • Managing workflows

  • Automating support tasks

These tools are incredibly powerful—but they are not autonomous. They do not replace training, oversight, compliance, or human judgment.

Just as the simulator exposed AI’s blind spot during a crisis moment, businesses face similar risks:

  • Misconfigurations AI never flags

  • Social engineering attacks AI can be manipulated by

  • Unexpected outages AI cannot improvise through

  • Security decisions AI is not authorized to make

AI is a phenomenal assistant.

But relying on it as the pilot-in-command of your cybersecurity is a recipe for disaster.

Why This Matters for Healthcare, Law Firms, and Schools

These sectors handle:

  • Protected health information

  • Legal evidence

  • Student data

  • Financial records

An AI mistake doesn’t just mean a rough landing—it means regulatory exposure, breach reporting, civil liability, and operational shutdowns.

AI copilots are valuable tools.

But cybersecurity requires trained professionals, layered defenses, and disciplined processes—not improvisation from a chatbot.

The Provocative Takeaway

The viral A320 experiment is fun to watch.

But it quietly proves something essential:

AI can help you fly.

It cannot save you in an emergency.

Your business still needs a real cybersecurity pilot.

70% of all cyber attacks target small businesses, I can help protect yours.

#️⃣ #cybersecurity #MSP #managedIT #dataprotection #technology

AI
Cybersecurity
Technology

Automation Just Changed Forever

December 8, 2025
•
20 min read

Automation Just Changed Forever

Google Workspace Now Lets Anyone Build No-Code AI Agents

Google has unveiled Workspace Studio, a no-code platform that allows Business and Enterprise customers to design and deploy AI agents directly inside Gmail, Drive, Chat, and connected third-party apps. Powered by Gemini 3, these agents move far beyond traditional “rules-based automation” and instead deliver contextual reasoning, adaptive decision-making, and end-to-end workflow execution — all without writing a single line of code.

This marks a major shift in workplace automation: AI agents are no longer limited to technical teams. Every employee can now automate their own tasks, streamline collaboration, and offload repetitive digital work inside the tools they use every day.

What Workspace Studio Can Do

Google’s new platform empowers organizations to deploy operational AI rapidly and securely.

1. No-code agent builder for everyday workflows

Users can create AI agents to automate:

  • Email triage

  • Meeting follow-ups

  • File organization

  • Action-item reminders

  • Task notifications

  • Daily email summaries

These agents run continuously inside Workspace — not as external bots.

2. Gemini 3 powers advanced reasoning and adaptive behavior

Agents gain access to:

  • Multimodal understanding (text, docs, images)

  • Sentiment and priority analysis

  • Context-aware decision support

  • Intelligent routing and escalation

  • Dynamic, personalized responses

This allows automation of workflows that previously required human interpretation.

3. Integrates with third-party business systems

Studio supports external tools such as:

  • Salesforce

  • Asana

  • Mailchimp

  • CRM and marketing platforms

This expands automation across the enterprise ecosystem, not just inside Workspace.

4. Templates accelerate adoption

Google includes several prebuilt agent patterns:

  • Alerts for emails from key contacts

  • Automated labeling and routing

  • Daily unread-mail summaries

  • Post-meeting task generation

  • Real-time Chat highlight mentions

Organizations can deploy immediately and iterate over time.

5. Deep customization for power users

Employees can design agents that:

  • Move attachments to specific Drive folders

  • Generate email replies using referenced documents

  • Request weekly status updates from teams

  • Build recurring workflow loops

This bridges the gap between personal automation and enterprise-scale process orchestration.

Rollout Timeline

  • December 3, 2025: Access for rapid-release domains

  • December 3, 2025: Admin settings available for scheduled-release tenants

  • January 5, 2026: End-user access for scheduled-release domains

Organizations should begin preparing governance policies now.

Why This Matters for SMBs, Healthcare, Law Firms, and Schools

Workspace Studio represents a turning point for operational efficiency.

1. Automation is no longer bottlenecked by IT

Every department — HR, finance, operations, legal, support — can create intelligent agents, reducing workloads and accelerating response times.

2. AI agents reduce operational friction

Agents handle:

  • Coordination

  • Notifications

  • Documentation

  • Routine communication

  • Data retrieval

This frees teams to focus on higher-value strategic work.

3. Standardizes workflows and minimizes human error

Routine tasks become consistent, auditable, and repeatable.

4. Increases organizational velocity

Teams move faster when AI handles the administrative overhead.

5. Reduces third-party automation risk

Internal AI agents minimize reliance on unvetted external tools, reducing data-exposure and compliance concerns.

6. Raises new cybersecurity and governance requirements

As with any agentic AI platform, organizations must establish:

  • Data governance

  • Permission controls

  • Safe automation boundaries

  • Audit trails

  • User training

AI agents are powerful — but they must be deployed securely.

AI agents will soon be as common as email.

Workspace Studio is the first major step toward a fully automated enterprise, where routine digital tasks disappear and human teams focus on outcomes, not busywork.

70% of all cyber attacks target small businesses, I can help protect yours.

#cybersecurity #MSP #managedIT #AIautomation #dataprotection

AI
Science
Technology
Cybersecurity

The New Wave of Consumer Scams Is Already Here And AI Is To Blame

December 4, 2025
•
20 min read

AI Is Reinventing Fraud

The New Wave of Consumer Scams Is Already Here And AI Is To Blame

A disturbing new trend is exploding across social media: people are using AI to fake “evidence” for refunds from delivery services like DoorDash and Uber Eats. The scam is shockingly simple — but the implications are enormous.

Fraudsters:

  1. Order food

  2. Generate an AI image making it look undercooked or spoiled

  3. Submit the fake photo to customer support

  4. Receive a full refund

One click. One fake image. One successful fraud claim.

This isn’t petty misconduct — it’s a preview of the next era of fraud, identity abuse, and digital deception targeting consumers and businesses alike.

AI Is Lowering the Barrier to Fraud

The same tools that generate:

  • Photorealistic images

  • Fake receipts

  • Counterfeit invoices

  • Deepfake videos

  • AI-generated complaint messages

  • Synthetic “proof” of delivery issues

  • Fabricated product damage

…now put industrial-scale fraud into the hands of everyday users.

For SMBs, healthcare organizations, law firms, schools — and especially any business offering refunds, insurance claims, or customer support — this is a turning point.

The problem isn’t that AI can create fake content.

It’s that AI can create fake content that passes as legitimate evidence.

Why This Is a Massive Cyber and Fraud Risk

AI-enabled fraud attacks the weakest link in any system: trust.

1. Refund fraud will skyrocket

Fake product damage. Fake delivery issues. Fake order failures.

Businesses will be forced to handle refund requests they cannot verify.

2. Receipt and invoice fraud becomes trivial

AI can mimic lighting, shadows, ink bleed, and paper texture.

This hits:

  • Accounting departments

  • Procurement systems

  • Insurance claims

  • Vendor reimbursements

3. Deepfake “proof” videos become impossible to challenge

Video once had evidentiary power.

Now? Anyone can falsify a complaint with perfect realism.

4. Review manipulation and reputation attacks will explode

AI can mass-generate:

  • 1-star reviews

  • Fake customer narratives

  • “Photo evidence” of nonexistent problems

5. Identity and document fraud becomes faster and cheaper

ID scans, signatures, contracts — all vulnerable to synthetic forgery.

What Organizations Need to Do Right Now

This is not a social-media fad — it’s a structural shift in fraud and risk.

1. Move to metadata-based verification

Images alone are no longer evidence.

Businesses must validate:

  • Device metadata

  • GPS stamps

  • EXIF signatures

  • Sensor patterns

  • Behavioral indicators

2. Deploy AI-detection tools — but don’t rely on them

AI can detect manipulated images, but attackers will evolve.

Detection should be one signal, not the decision.

3. Require multi-factor evidence for high-risk refunds

Especially for high-value items or recurring complaints.

4. Build fraud-resistant workflows

Replace manual customer-support decisions with:

  • Risk scoring

  • Anomaly detection

  • Pattern analysis

  • Cross-channel checks

5. Train staff to recognize synthetic evidence

Human intuition matters — but training must evolve.

6. Harden customer-support systems

Fraudsters target frontline employees who can be socially engineered.

The Trust Crisis Is Here

AI isn’t just generating images — it’s eroding the reliability of digital proof.

And businesses must adapt immediately.

70% of all cyber attacks target small businesses, I can help protect yours.

#cybersecurity #MSP #managedIT #fraudprevention #dataprotection

Technology
Cybersecurity
Tips
Must-Read

Five Secret Tools That Can Boost Productivity

December 9, 2025
•
20 min read

Windows 11 Hides Serious Power Features

Five Secret Tools That Can Boost Productivity and Reduce Risk

Windows 11 has been out for years, but most users only scratch the surface of what it can do. Beyond the centered Start Menu and Snap layouts, Microsoft quietly added a series of hidden features that can dramatically improve productivity — and for SMBs, healthcare organizations, law firms, and schools, some of these tools even reduce cybersecurity exposure by eliminating third-party apps.

Here are five Windows 11 secret features every user should be taking advantage of by now.

1. AI Object & Background Removal Built Directly Into Photos

Most people assume you need Photoshop to clean up photos, remove objects, or cut out backgrounds.

Not anymore.

Windows 11’s built-in Photos app includes AI-powered editing tools that:

  • Erase people, objects, and backgrounds

  • Cleanly reconstruct images after removal

  • Require no manual masking or paid software

  • Reduce reliance on unknown third-party apps

For organizations, fewer external tools = fewer data leaks, fewer permissions, and less risk.

2. Hidden Calculator Modes You’ve Probably Never Used

The Windows Calculator is secretly several apps in one:

  • Scientific Mode — advanced functions, trigonometry

  • Graphing Mode — visualize equations

  • Programmer Mode — binary, hex, bitwise operations

  • Date Calculator — find differences between dates

  • Converters — temperature, area, pressure, currency, and more

It even has a “Always on Top” mode — perfect when tracking expenses, comparing pricing, or performing quick conversions without switching windows.

3. Built-In OCR: Copy Text From Screenshots With Snipping Tool

Need to extract text from:

  • Images

  • Videos

  • System error boxes

  • Websites that block copying

  • PDFs

  • Apps with non-selectable text

Windows 11 now includes built-in Optical Character Recognition (OCR) via the Snipping Tool.

Just screenshot, click Text Actions, and copy whatever you need.

This replaces insecure third-party OCR apps and reduces data-sharing risk.

4. Add Multiple Time Zones Directly to Your Notification Center

For anyone coordinating with:

  • Remote teams

  • Clients in other countries

  • Vendors abroad

  • Family overseas

Windows 11 lets you add two additional time zones directly to the Notification Center. No more searching “time in Tel Aviv” ten times a day.

These clocks show up instantly when you open Notifications or hover over your taskbar time — ideal for modern hybrid and international workforces.

5. Notepad Now Includes Lightweight Text Formatting

Notepad — the simplest app in Windows — has quietly evolved.

It now supports:

  • Headings (H1, H2, Body)

  • Bold + Italics

  • Bulleted & numbered lists

  • Hyperlinks

  • Markdown view

  • “Save as .MD” for formatted documents

This turns Notepad into a fast, distraction-free editor for notes, documentation, and drafts — all without the weight of large apps like Word or Evernote.

Small features. Big productivity. Zero extra risk.

Windows 11 hides tools that eliminate the need for risky third-party apps, streamline workflows, and reduce friction across your entire organization.

70% of all cyber attacks target small businesses, I can help protect yours.

#cybersecurity #managedIT #MSP #dataprotection #SMBsecurity

Cybersecurity
Mobile-Arena
Technology
AI

Israeli Army Bans Android for Commanders-iPhone Now Mandatory

December 1, 2025
•
20 min read

Security Demands Controlled Ecosystems

IDF Bans Android for Commanders—iPhone Now Mandatory

Israel’s military has issued a sweeping new directive: senior IDF officers may no longer use Android phones for operational communication. Only iPhones will be permitted going forward — a dramatic escalation driven by national-security threats, espionage attempts, and ongoing cyber campaigns targeting Israeli personnel.

The move comes just weeks after Google publicly emphasized Android’s improved security posture. But for the IDF, the risk calculus is clear: in high-stakes environments, ecosystem control outweighs openness, and even incremental differences in device hardening can have life-or-death consequences.

Why the IDF Made This Decision

Israel’s commanders have been repeatedly targeted by foreign intelligence groups, including Hamas, Hezbollah, and now Iranian-linked operators running sophisticated digital espionage campaigns.

Key drivers behind the ban:

1. Android’s openness remains a liability in military contexts

Even with Android 16’s Advanced Protection Mode and new restrictions on sideloading, fragmentation persists:

  • Different manufacturers = different security baselines

  • Varied update schedules

  • Inconsistent hardware protections

  • Broader opportunities for compromise through malicious apps or misconfigurations

For militaries, this variability is unacceptable.

2. iOS offers uniformity and tighter control

Apple’s closed ecosystem provides:

  • Standardized security across all supported devices

  • Long patch cycles

  • Strong hardware isolation (Secure Enclave)

  • Limited app-installation pathways

  • Predictable update distribution

Operational units need reliability. iOS provides it.

3. Persistent “honeypot” attacks targeting soldiers

Attackers have routinely used:

  • Fake profiles

  • Social-engineering lures

  • WhatsApp impersonation

  • Dating-app traps

  • Malicious links

  • Location-tracking exploits

These tactics often exploited device vulnerabilities or weak app-layer security. By moving officers to a single, locked-down platform, the IDF is lowering exposure.

A New Iranian Espionage Campaign Raises the Stakes

Reports now confirm a highly targeted IRGC-linked operation called SpearSpecter, which uses:

  • WhatsApp lures

  • Impersonation campaigns

  • Social engineering

  • A PowerShell-based backdoor

  • Long-term surveillance objectives

The shift from broad attacks to precision espionage reinforces why militaries must harden the entire communications chain — and why device choice matters.

What This Means for Organizations Everywhere

While the IDF’s environment is unique, the underlying lessons apply directly to:

  • SMBs

  • Healthcare systems

  • Law firms

  • Schools

  • Critical-infrastructure providers

1. Standardize devices wherever possible

Mixed fleets (iPhone + dozens of Android models) create uneven protection and inconsistent update coverage.

2. Eliminate sideloading and unsanctioned app installs

This is one of the most exploited attack vectors on Android.

3. Treat mobile devices as primary attack surfaces

Social engineering overwhelmingly begins on smartphones — not laptops.

4. Harden messaging apps

WhatsApp, SMS, Signal, Telegram, and Teams are all used in targeted operations.

5. Assume attackers will exploit personal devices

If employees mix personal and work accounts on one phone, organizations inherit hidden risks.

iPhone isn’t invincible — but uniformity makes defense achievable.

Android isn’t unsafe — but variability creates blind spots defenders can’t always close.

For militaries and high-risk sectors, controlled ecosystems win.

70% of all cyber attacks target small businesses, I can help protect yours.

#cybersecurity #managedIT #MSP #mobilesecurity #dataprotection

Technology
Mobile-Arena
Cybersecurity
News

America Scrolls More Than Ever

November 30, 2025
•
20 min read

America Scrolls More Than Ever

New Pew Data Reveals How the U.S. Really Uses Social Media

A new nationwide Pew Research survey of 5,022 U.S. adults shows that Americans’ social media habits are shifting — and fast. YouTube, Facebook, and Instagram still dominate the landscape, but generational divides are widening, emerging platforms lag behind, and younger users are gravitating toward more immersive, algorithm-driven platforms like TikTok.

For SMBs, healthcare organizations, law firms, and schools, this data reshapes how audiences should be reached, informed, and protected online.

The Platforms America Uses Most

According to Pew’s findings:

  • YouTube remains king with 84% of U.S. adults using it.

  • Facebook stays entrenched with 71% usage despite stagnation among younger users.

  • Instagram hits 50% adoption, especially strong with adults under 35.

These three continue to anchor the digital experience for most Americans — but beneath the surface, major demographic shifts are underway.

Younger Americans Are Driving a New Era

Users under 30 show dramatically different behaviors:

1. TikTok dominates youth attention

  • 63% of Americans ages 18–29 use TikTok

  • About half visit daily

  • Usage patterns show high engagement and longer session times

This makes TikTok one of the most influential platforms for youth culture — and a high-risk environment for misinformation, scams, and psychological manipulation.

2. YouTube is universal across generations

Younger adults continue to use YouTube at near-total saturation levels.

It remains the gateway for:

  • Short-form content

  • Education

  • Gaming

  • News

  • Influencer-driven discussions

3. WhatsApp is quietly growing

Usage is now 32%, up 9 points since 2021, fueled by private group chats and encrypted communication.

Winners and Losers in the New Social Landscape

Rising Platforms

Reddit jumps from 18% to 26% — a massive leap connected to community-driven news, niche hobbies, and anonymous discussions.

Declining Platforms

X (Twitter) continues losing its U.S. user base following ongoing platform volatility and trust concerns.

Minimal Adoption Among Young Americans

  • Threads: 15%

  • Bluesky: 6%

  • Truth Social: 1%

These platforms have failed to capture meaningful engagement, especially under 30.

What These Patterns Mean for Organizations

Whether you’re an SMB, a healthcare network, a law firm, or a school, these trends reshape digital communication and cybersecurity risk.

1. Younger audiences live in algorithmic ecosystems

TikTok, YouTube, and Instagram Reels drive behavior — and attackers exploit these environments for:

  • Phishing

  • Fraud

  • Data-harvesting challenges

  • Social engineering trends

  • Fake job offers and scams

2. The rise of encrypted private messaging complicates oversight

WhatsApp, Messenger encrypted mode, and Instagram DMs limit visibility into harmful content and misinformation.

3. Older adults remain highly active on Facebook

This demographic is most vulnerable to:

  • Romance scams

  • Phishing

  • Identity theft

  • Fake marketplace listings

  • Political manipulation campaigns

4. Reddit’s growth introduces new risk surfaces

Communities are targeted for credential theft, malware, and impersonation campaigns.

America’s digital habits are evolving — and so are the risks.

Where people spend their attention is where attackers follow.

70% of all cyber attacks target small businesses, I can help protect yours.

#cybersecurity #MSP #managedIT #dataprotection #SMBsecurity

Cybersecurity
Travel
Must-Read

Microsoft Teams Guest Accounts Can Strip Away Defender Protection

November 28, 2025
•
20 min read

Guest Access Creates Invisible Vulnerabilities

Microsoft Teams Guest Accounts Can Strip Away Defender Protection

A newly uncovered cross-tenant blind spot in Microsoft Teams is allowing attackers to bypass Microsoft Defender for Office 365, placing organizations at risk whenever employees join an external tenant as a guest. The problem isn’t a bug—it’s a structural flaw in how Microsoft handles identity and security boundaries across tenants.

When a user accepts a Teams guest invitation, they temporarily leave their organization’s security perimeter.

Their home Defender policies no longer apply.

Their enterprise-grade protections vanish.

And attackers know it.

This creates a silent, dangerous gap for SMBs, healthcare systems, law firms, and schools—especially those that rely heavily on Teams for external collaboration.

The Core Issue: Security Policies Don’t Follow the User

According to new research from Ontinue:

When you join another tenant as a guest, you inherit their protections—not your own.

Microsoft Defender Safe Links, Safe Attachments, anti-malware scanning, and phishing protections are applied only by the hosting tenant.

If the hosting environment is poorly secured—or deliberately malicious—your users become exposed:

  • No Safe Links → phishing URLs go unchecked

  • No Safe Attachments → malware is delivered directly

  • No threat detection → attacks bypass your SIEM, SOC, and alerts

  • No visibility → IT has no record of the attack

Your organization remains completely blind because the attack happens outside your tenant, even though it targets your users.

The Attack Path Is Shockingly Simple

Researchers showed how attackers can weaponize this architecture using a low-cost Microsoft 365 tenant.

1. Attacker creates a malicious tenant

They choose a license like Teams Essentials or Business Basic—no Defender protections included.

2. They disable every available safeguard

They create a “protection-free zone” where malware and phishing flow freely.

3. They target your employees with a Teams guest invitation

Teams automatically sends the invite from Microsoft’s own infrastructure, meaning:

  • It passes SPF

  • It passes DKIM

  • It passes DMARC

  • Email security tools do not flag it

It looks completely legitimate.

4. Your user accepts the invite

With one click, they leave your protected environment and enter the attacker’s unprotected tenant.

5. Attacker delivers malware, phishing links, or data-theft payloads

Your organization sees nothing

Your controls trigger nothing

Your user is now exposed to threats your policies would normally block

And the entire attack happens off your radar.

This is one of the most dangerous forms of cross-tenant exploitation in the Microsoft cloud ecosystem.

Why This Threat Hits SMBs, Healthcare, Law Firms, and Schools Hard

These sectors rely heavily on Teams for collaboration:

  • Doctors and clinics sharing information with partner facilities

  • Law firms coordinating with clients and external counsel

  • Schools interacting with vendors and partner districts

  • SMBs relying on Teams to communicate with suppliers, subcontractors, and customers

Every external communication becomes an attack surface if guest access isn’t controlled.

Even more concerning:

Microsoft is rolling out “chat with anyone via email” in Teams by early 2026—dramatically expanding the guest-invite exposure window.

What You Must Do Immediately

Organizations need layered controls to close this gap before attackers exploit it.

1. Restrict guest access to trusted domains only

Limit B2B collaboration to approved partners you trust.

2. Implement cross-tenant access policies

Use Entra ID settings to enforce conditional access and apply security boundaries based on tenant trust.

3. Disable external Teams messaging where not required

If Teams is internal-only, restrict or fully block external chat.

4. Train employees to treat Teams invites like phishing

If the user isn’t expecting the invite, they should not accept it.

5. Monitor for unusual cross-tenant authentication patterns

SIEMs and identity protection tools can often detect anomalous tenant switching.

6. Review your TeamsMessagingPolicy settings

Set UseB2BInvitesToAddExternalUsers = false to restrict outbound invitations—but also confirm inbound ones are controlled.

Collaboration is critical — but so is controlling who your users collaborate

with

.

Guest access is now a top-tier cloud attack vector, and organizations must treat it as such.

70% of all cyber attacks target small businesses, I can help protect yours.

#cybersecurity #MSP #managedIT #Microsoft365 #dataprotection

Previous
Next
About
Managed ServicesCybersecurityOur ProcessWho We AreNewsPrivacy PolicyTerms & Conditions
Help
FAQsContact UsSubmit a Support Ticket
Social
LinkedIn link
Twitter link
Facebook link
Have a Question?
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Copyright © {auto update year} Gigabit Systems All Rights Reserved.
Website by Klarity
Gigabit Systems Inc. BBB Business Review