RT Solutions

RT Solutions IT & Cybersecurity services.
(1)

If a website tells you to press Windows+R and paste in a command to 'verify you're human,' close the tab. That's a scam ...
08/04/2026

If a website tells you to press Windows+R and paste in a command to 'verify you're human,' close the tab. That's a scam called ClickFix, and it installs malware the second you hit Enter. No real website ever asks you to run a command. CAPTCHAs just make you click pictures.


ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked tooling.

08/03/2026

Your cyber insurance might not pay out. Insurers now require MFA, real endpoint protection, tested backups, and security training, and if you claimed to have them but didn't, they can deny the claim. Read your policy's conditions now, not after an attack.

For years, the advice has been simple: “Be careful what you click on in Google.”Now we might need to start saying the sa...
08/02/2026

For years, the advice has been simple: “Be careful what you click on in Google.”

Now we might need to start saying the same thing about AI 🤖

Microsoft has warned that cybercriminals are finding ways to manipulate AI tools into recommending fake software downloads.

And honestly, it makes sense when you think about how people use the internet now.

A lot of us don’t search the way we used to anymore 🔦

Instead of typing something into Google and scrolling through websites, people are asking AI questions directly…

“What’s the best tool for checking PC temperatures?”�
“Where can I download this app?”�
“What software should I use for…?”

The problem is that attackers are adapting to that behavior.

Researchers found criminals creating fake websites pretending to be popular tools.

Somehow, they’re managing to get these malicious sites recommended by AI systems.

Instead of tricking search engines, they’re now trying to trick AI.

And if someone trusts the recommendation and downloads the file, malware gets installed on the device.

In some cases, that malware gives the attacker remote access to the computer. They can then explore the network and steal data.

They may even install something called a “crypto jacker”.

That’s software which uses your computer’s power to mine cryptocurrency for the attacker.

Your machine slows to a crawl while somebody else profits from your electricity bill 💸

The bigger point here is that cybercriminals follow behavior.

If people move from search engines to AI, attackers move there too.

That means we need to treat AI recommendations with the same level of caution we’d use for search results or emails ⚠️

Helpful doesn’t always mean safe.

AI is an incredible tool, but it doesn’t “fact check” the internet in the way many people assume.

It can still surface bad information, fake sites, or manipulated recommendations.

So, if you’re downloading software, especially business software, you should still check the source properly before clicking install.

💭 Have you started using AI instead of Google for searches yet?

08/02/2026

Anyone can send an email that looks like it's from your company. Three DNS records stop it: SPF, DKIM, and DMARC. The catch is DMARC is often set to 'monitor only,' which watches spoofing happen without blocking it. Ask your IT provider: is ours set to reject, or just none?

The FBI has issued a warning about a new type of phishing attack targeting Microsoft 365 users 😰And this one is a little...
08/01/2026

The FBI has issued a warning about a new type of phishing attack targeting Microsoft 365 users 😰

And this one is a little different…

Normally with phishing, the attacker tries to steal your password.

This time, they’re trying to steal something called an “OAuth token”.

A what?!

An OAuth token is like a temporary digital pass that proves you’ve already logged in successfully.

It’s what keeps you signed into apps like Outlook, Teams, and OneDrive without needing to enter your password every few minutes.

If an attacker steals that pass, they can potentially access those services as if they were you 🥸

The phishing emails themselves are becoming incredibly convincing, thanks to AI.

They can look like document shares, meeting invites, or account notifications. And they often lead to real Microsoft login pages.

So, when someone approves the request, it feels legitimate.

That’s the trap 🪤 The attacker is effectively getting you to approve access on their behalf.

This is why cybersecurity is changing so much right now.

For years, businesses focused heavily on passwords and antivirus software, and those are still important.

But attackers are increasingly finding ways to work around them by targeting normal human behavior instead.

A rushed click, an approval without thinking, a moment of distraction during a busy day. That’s often all they need.

Fortunately, there are protections you can put in place behind the scenes, especially around how Microsoft 365 handles authentication requests.

And remember, if you receive an unexpected login request, verification prompt, or email asking you to approve access to something, slow down and think before clicking anything 🔎

Even if it looks genuine.

👉 Have you noticed that phishing emails are harder to spot lately?

Many ransomware groups delete your backups before they lock your files, so paying becomes the only way out. Keep one bac...
08/01/2026

Many ransomware groups delete your backups before they lock your files, so paying becomes the only way out. Keep one backup copy offline with its own login, separate from your admin password, and test a restore this month. If you've never tried it, you don't know it works.


INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.

07/31/2026

Want to mirror your phone or laptop to your PC? There’s a wireless trick in Windows 11…

07/31/2026

Your team is using AI right now, whether you have a policy on it or not.

ChatGPT, Gemini, Copilot, Claude, and a dozen niche business tools are in the workflow of someone in your business this week. These tools learn from what you type, sometimes retain it for training, and live outside whatever data security setup you've built for the rest of the business.

Without a written policy, you have no way to know what client data is being pasted into prompts, which business decisions are being made with AI assistance, or how your insurance views any of it if something goes wrong.

An AI Acceptable Use Policy doesn't have to be 30 pages. A one-page version covers the essentials: which tools are approved, what data is forbidden as input, what disclosure rules apply to AI-generated work, and who reviews AI output before it goes to a client.

If you want a full AI Acceptable Use Policy template to implement in your business, comment below with "AI Policy" and we'll send it to you.

07/30/2026

Smishing is text message phishing, and it's now more effective at reaching people than email phishing.

The reason is mechanical. Most businesses spent the last decade hardening their email gateways and training people on suspicious links. Almost nobody applied the same effort to text messages. The result is a channel where employees still tap first and think later.

The patterns repeat: a "delivery failed" message with a link asking for login credentials, a "this is your CEO" text from a number nobody recognizes asking for gift cards or a wire, a fake account-lockout message that looks identical to a real bank alert, and a "hey, I'm in a meeting, can you help me with something quick?" text impersonating a senior person.

These work because texts feel personal in a way email doesn't. They land on the same screen where your spouse, your kids, and your coworkers reach you, which makes the brain default to trusting them. That's the entire attack.

The rules to give your team:

1. No business decision happens over text. That includes wire transfers, vendor changes, payroll changes, gift card requests, and password resets.
2. If a text claims to be from a coworker, verify through a different channel before responding. A 30-second Slack message or phone call kills most of these attacks.
3. Never click a login link inside a text. Open the app or website directly.
4. Forward suspected smishing to 7726 (which spells SPAM on a phone keypad). Carriers use it to block the source.

Smishing works when the response happens before the thinking. Train your team to slow down, and most of these attacks dead-end before the attacker has time to react.

07/29/2026

AI is starting to do more than just help your team.

It’s making decisions and taking actions on your behalf.

Everything runs and work gets done faster.�

But if something doesn’t look right, could you explain why?

Address

416A N. Main Street
Hutchinson, KS
67501

Opening Hours

Monday 8am - 5pm
Tuesday 8am - 5pm
Wednesday 8am - 5pm
Thursday 8am - 5pm
Friday 8am - 5pm

Telephone

+16206088228

Alerts

Be the first to know and let us send you an email when RT Solutions posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to RT Solutions:

Shortcuts

Share