$ ./field_notes

Threat intel for SMBs

The attacks actually hitting small and mid-sized businesses — phishing, supply-chain compromise, identity, EDR, and AI risk — broken down by people who break in for a living.

$ ls guides/

Field guides

Long-form, no-fluff buyer’s guides — what a pentest is, what it costs, and what the law expects in your market.

TX SB 2610 Safe Harbor DFW San Jose Santa Barbara San Diego Nashville Munich Stockholm Marbella
// latest

Your Vendor's Sloppy Code Is Your Breach

When you hire a web shop or 'AI guy,' you inherit every package they pulled off the internet. Right now, that's where the attackers are camped out.

Penetration Testing

Pentest vs. Scan: What You're Buying

A scanner tells you what doors exist. A pentest tells you which ones we walked through.

Social Engineering

Your Real Perimeter Is Human

No firewall patches a curious employee. How we test the human layer — and harden it.

Threat Intel

The “Macs Don't Get Viruses” Era Is Over

Macs aren't a security feature anymore — they're just endpoints, and malware authors figured that out first. Inside SHub Reaper, and what SMBs with Macs need to do now.

Threat Intel

One AI Tool Breached Vercel: The OAuth Supply-Chain Risk Hiding in Your SMB

It wasn't a zero-day. An employee connected a third-party AI tool to their Google Workspace, and attackers rode that OAuth grant into Vercel's internal systems.

Threat Intel

108 Malicious Chrome Extensions Were Hiding in Plain Sight

108 extensions. 20,000 installs. One shared server quietly stealing Google identities and Telegram sessions across every page. Why the browser is the new perimeter.

Threat Intel

The Stryker Wiper Attack: What Every SMB Must Do About Microsoft Intune

Iran-linked hackers wiped a $25B medtech giant using nothing but a compromised Microsoft Intune admin account. Why your SMB is the next logical target — and what to do this week.

Managed Defense

Best EDR for Small Business in 2026: A Pentester's Honest Comparison

I've used all of them — and broken through networks protected by all of them. An honest pentester's comparison of Defender, Huntress, SentinelOne, and CrowdStrike for small business.

Threat Intel

Securing the AI Frontier: Treat AI Like the New Attack Surface

Companies are racing to adopt AI and ignoring that it's now one of the biggest attack surfaces they own. Shadow AI, data poisoning, and why the best way to secure AI is to attack it first.

SMB Advisory

Why MSPs Shouldn't Be Selling “Cybersecurity” Like an Add-On

Cybersecurity isn't IT with extra licenses. Why a stack of tools and a compliance checklist isn't protection without operators behind it — and what SMBs should demand.

Managed Defense

Broken DMARC, SPF & DKIM: How Your Own Email Domain Becomes the Attack Vector

Your email domain can be turned against you. How broken SPF, DKIM, and DMARC let attackers spoof you with no malware — and why 'p=none' is an open invitation.

SMB Advisory

The Mid-Market Meltdown: Why SMBs Are the Real Battleground

The real cyber war isn't at the Fortune 500 — it's in the under-resourced mid-market. Why your attack surface is everything you and your vendors touch, and how to defend the full threat lifecycle.

Threat Intel

Identity Is the New Perimeter: Why SMBs Are in the Crosshairs

There's no perimeter anymore — only identity. Why token abuse, OAuth misuse, and cloud misconfiguration slip past 'MFA + MSP,' and what real active defense looks like.

Threat Intel

Why Vulnerability Scanners Are on the Chopping Block

Vulnerability scanners flag possible problems; autonomous pentesting and AEV prove what's actually exploitable. Why the scanner is being demoted from primary risk sensor to one input among many.

Ransomware

Why CEOs Must Lead vs. Ransomware

Ransomware is a boardroom threat, not just an IT one — here's the case for leading from the top.

Supply Chain

HVAC Vendors: The Weak Link

Trusted, always-connected, rarely monitored — HVAC vendors are a top path into enterprise networks.

Threat Intel

The OpenAI–Mixpanel Breach: Why Vendor Metadata Is a Threat to Every SMB

OpenAI wasn't hacked — Mixpanel was. Names, emails, and locations leaked anyway, and that's enough to build convincing spear-phishing. Why vendor metadata is ammunition.

Red Team

Why SMBs Are Being Phished More Than Ever in 2025

Adversaries shifted from 'deploy malware and wait' to 'trick a human and walk in.' The 5 threat actors weaponizing social engineering against SMBs — and how to build a phish-resilient culture.

Threat Intel

When Your AI Turns Against You

Attackers can hide instructions in web content to make ChatGPT leak private data. What the HackedGPT research means for SMBs — and a 10-point checklist to lock your AI stack down.

Threat Intel

10 Billion Blocks Later: Android's AI Edge Over iOS Explained

Android's on-device AI blocks over 10 billion scam texts and calls a month — far ahead of iOS. Why that reshapes the mobile attack surface, plus 5 threat actors to track.

Threat Intel

Top 10 Cyber Threats for SMBs in 2025

From AI-generated phishing to cloud misconfiguration — the 10 threats hitting SMBs hardest in 2025, each with the stats and the defense.

Managed Defense

From Reactive to Proactive: How Continuous Monitoring Protects SMBs

Locking the door once isn't security. Why SMBs need continuous monitoring — logs, EDR, network analysis, and 24/7 watch — instead of set-and-forget tools.

Social Engineering

Social Engineering & Baiting

A USB on a desk, a 'free upgrade' pop-up. Baiting doesn't break your firewall — it walks past it.

Threat Intel

Why Law Firms Are Prime Targets

Concentrated client data, deadline pressure, lean IT. The data, the actors, and the controls that work.

Threat Intel

Why SMBs Are the #1 Target in 2026

Attackers stopped ignoring small business years ago. The data on why you're in the crosshairs.