PAconnect

PAconnect For over 40 years, PA Connect has been a trusted IT leader, keeping businesses connected, secure, and efficient.

"'We need you to register a new passkey.' Hang up." A tactic worth warning your team about this week, because it starts ...
08/26/2026

"'We need you to register a new passkey.' Hang up."

A tactic worth warning your team about this week, because it starts with something people don't expect: a phone call.

Attackers call an employee, claim IT needs them to "register a new passkey," and walk them through a fake Microsoft login page in real time. While they're on the phone, the attacker captures the password and the MFA code β€” then quietly enrolls their own passkey on the account. That gives them access that survives a password reset.

It works because everyone's been trained to distrust email links. Almost nobody has been trained to distrust a helpful voice.

**The habit that stops it:** if someone calls asking you to register a passkey or verify security settings, hang up and call IT back on a number you already had. Real IT teams don't enroll credentials for you over the phone.

Worth sharing with your staff today.

` `

Most break-ins at small businesses don't look like break-ins.There's no alarm, no crashed server, no ransom note on day ...
08/24/2026

Most break-ins at small businesses don't look like break-ins.

There's no alarm, no crashed server, no ransom note on day one. Someone on your team gets a phone call, or approves a login prompt that looks routine, and the attacker walks in through the front door using real credentials. By the time anything looks wrong, they've been inside for days.

We've been doing IT in Western PA since 1981. What's changed in the last two years isn't the technology β€” it's that the attacks are aimed at people now, not equipment.

Over the next month we're posting the specific tactics we're seeing hit businesses like yours, and the habits that stop each one. No sales pitch. Just the things we'd want you to know.

Follow along. πŸ‘‰ PAconnect.com

` `

"Microsoft just exposed 'MacSync Stealer' β€” malware that tricks Mac users into pasting a fake 'fix' command into Termina...
08/20/2026

"Microsoft just exposed 'MacSync Stealer' β€” malware that tricks Mac users into pasting a fake 'fix' command into Terminal, then quietly steals Keychain passwords, browser data, SSH keys, and AWS credentials. Mac β‰  immune. Never paste commands from a website you don't trust. πŸŽπŸ” "

Microsoft links 30+ domains to MacSync Stealer, tracing recurring ex*****on and chunked exfiltration of credentials and sensitive data.

AI agents are getting plugged into more business systems every month β€” and security researchers are warning that many of...
08/18/2026

AI agents are getting plugged into more business systems every month β€” and security researchers are warning that many of these integrations store credentials in plain text with way too much access. If your team is adopting AI tools, "set it and forget it" isn't a security strategy. Least privilege still applies.

MCP servers can leak enterprise secrets through plaintext config files or prompt injection. Learn the main risks and how to secure them.

737 fake VPN Chrome extensions were just caught secretly routing users' entire browsing sessions through attacker-contro...
08/14/2026

737 fake VPN Chrome extensions were just caught secretly routing users' entire browsing sessions through attacker-controlled servers. Take 2 minutes today to check chrome://extensions β€” remove anything you don't recognize or no longer use, and only install VPNs directly from the vendor's official site.

737 Chrome VPN extensions with 75,486 installs route browser traffic through SOCKS5 proxies, putting the operator in an AitM position.

A Chrome extension banned for stealing AI chat conversations just quietly came back to the Chrome Web Store β€” after 300k...
08/11/2026

A Chrome extension banned for stealing AI chat conversations just quietly came back to the Chrome Web Store β€” after 300k+ people had already installed it. Take 5 minutes this week to review your browser extensions and remove anything you don't actively use or fully trust.

The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.

New research shows AI browser agents like ChatGPT Atlas and the Claude Chrome extension can be hijacked with ZERO clicks...
08/07/2026

New research shows AI browser agents like ChatGPT Atlas and the Claude Chrome extension can be hijacked with ZERO clicks β€” just viewing a malicious email or post is enough. Both flaws remain unpatched months after disclosure. If your team uses agentic AI tools, now's the time to review your policies.

Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.

Tech tip: If you get an urgent email about a 'security audit' asking you to download and run a tool β€” stop and verify th...
08/06/2026

Tech tip: If you get an urgent email about a 'security audit' asking you to download and run a tool β€” stop and verify through the company's official site first. Scammers are using real breach headlines (like the recent COLDCARD wallet incident) to trick people into installing remote-access malware.

https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/

"

A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.

Tech Tip: Got a "voicemail" or "performance review" email from RingCentral you weren't expecting? Slow down. Attackers a...
08/05/2026

Tech Tip: Got a "voicemail" or "performance review" email from RingCentral you weren't expecting? Slow down. Attackers are spoofing trusted brands like RingCentral to steal Microsoft 365 logins and MFA codes. Before clicking any link, hover to check the real sender domain β€” and never enter your MFA code on a page you didn't navigate to yourself.

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.

Microsoft is warning travelers: nation-state hackers (Midnight Blizzard) are hijacking hotel Wi-Fi to push fake updates ...
08/03/2026

Microsoft is warning travelers: nation-state hackers (Midnight Blizzard) are hijacking hotel Wi-Fi to push fake updates loaded with surveillance malware. If you're traveling for work, treat hotel Wi-Fi as hostile by default β€” use a mobile hotspot when you can.

Microsoft links hijacked hotel Wi-Fi to fake updates that deliver CornFlake, steal cloud tokens, and abuse device codes to target travelers.

Address

789 E Pittsburgh Street
Greensburg, PA
15601

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Telephone

+17248387526

Alerts

Be the first to know and let us send you an email when PAconnect posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to PAconnect:

Shortcuts

Share