# Oscar Six Security Blog > Cybersecurity insights, compliance guidance, and security best practices from Oscar Six Security. ## Announcements - [A Fake AI Skill Fooled Every Scanner. Here's What Should Have Caught It.](https://blog.oscarsixsecurityllc.com/blog/fake-ai-skill-supply-chain): Last week, security researchers at AIR proved something we've been warning about. They built a fake AI agent skill, pushed it through a popular skill marketplace, and it passed every security scanner... - [Radar Is Live: Get Your First Vulnerability Scan for $49](https://blog.oscarsixsecurityllc.com/blog/radar-launch-introductory-pricing): We've been quiet for the past few weeks, running Radar through a closed beta with real businesses. Today we're opening the doors. Radar is live. And for a limited time, you can run your first vulnerab... ## Compliance - [SMS MFA Is Dead: What Happens After Sept 2026](https://blog.oscarsixsecurityllc.com/blog/sms-mfa-deprecation-microsoft-september-2026-small-business): If your organization is still using SMS-based multi-factor authentication for Microsoft 365 or Entra ID accounts, you have a hard deadline staring you down: September 1, 2026. After that date, Microso... - [Passkeys vs SMS MFA: Beat Microsoft's 2026 Deadline](https://blog.oscarsixsecurityllc.com/blog/passkeys-vs-sms-mfa-microsoft-2026-deadline-small-business): If your small business is still using SMS or voice codes to protect Microsoft 365 accounts, you have a hard deadline staring you down: September 1, 2026. That's when Microsoft officially retires SMS a... - [Your AI Tools Are Leaking Sensitive Data. Here's How to Stop It.](https://blog.oscarsixsecurityllc.com/blog/ai-tools-pii-data-leakage-prevention): Every time someone pastes a customer email into ChatGPT or runs a support ticket through an AI summary tool, sensitive data leaves the building. Names. Emails. Social Security numbers. Credit card num... - [Cloudflare Organizations: MSP Multi-Account Control](https://blog.oscarsixsecurityllc.com/blog/cloudflare-organizations-msp-multi-account-control): If you're managing Cloudflare across multiple client accounts — or trying to maintain a consistent security posture across a distributed enterprise — Cloudflare just shipped something worth paying att... - [Stop Accidental Credential Exposure via Third-Party Apps](https://blog.oscarsixsecurityllc.com/blog/accidental-credential-exposure-third-party-integrations): It started with a payroll app. A well-meaning employee at a mid-sized company saw a prompt to connect their Workday account to a third-party productivity integration. It looked legitimate. It had a pr... - [AI Tools and Customer Data: The Risk You Can't See](https://blog.oscarsixsecurityllc.com/blog/unauthorized-ai-tools-customer-data-employee-risk): A thread on r/cybersecurity hit a nerve recently. The post — titled 'To every manager who thinks they have AI under control' — described a scenario playing out in offices everywhere: employees quietly... - [When Your Firewall Vendor Causes the Breach](https://blog.oscarsixsecurityllc.com/blog/firewall-vendor-breach-sonicwall-lawsuit-lessons): You Trusted Your Security Vendor. What If That Was the Vulnerability? Most small businesses and government contractors think about cybersecurity in a straightforward way: you buy a firewall, you insta... - [Shadow IT Crisis: When Department Heads Bypass Security](https://blog.oscarsixsecurityllc.com/blog/shadow-it-crisis-department-heads-bypass-security): MSPs are sounding the alarm: professional services clients are increasingly adopting unauthorized tools without IT approval, creating a shadow IT crisis that's putting entire organizations at risk. Wh... - [FTC Safeguards Rule: What Small Businesses Need to Know](https://blog.oscarsixsecurityllc.com/blog/ftc-safeguards-rule-continuous-monitoring-small-business-guide): Understanding the FTC Safeguards Rule If you handle customer financial information, the FTC Safeguards Rule likely applies to your business. Originally designed for traditional financial institutions,... - [CMMC Level 1 Compliance: A Small Business Survival Guide](https://blog.oscarsixsecurityllc.com/blog/cmmc-level-1-compliance-small-business-guide): What Is CMMC Level 1 and Why Should You Care? If you're a small business working with the Department of Defense—or hoping to—you've probably heard whispers about CMMC. The Cybersecurity Maturity Model... - [Pre-Check Your Site Before the Auditors Do](https://blog.oscarsixsecurityllc.com/blog/radar-pre-audit): The Audit Nightmare It’s 9 AM. The auditor just walked in. They want to see your vulnerability scans from the last quarter. You scramble to find the PDF from that expensive consultant you hired three... ## Insurance - [Ransomware Lawsuit Risk: What Small Businesses Owe](https://blog.oscarsixsecurityllc.com/blog/ransomware-liability-lawsuit-small-business-legal-risk): The Attack Was Bad. The Lawsuit Was Worse. Imagine your business gets hit by ransomware. Your files are encrypted, operations grind to a halt, and you spend the next week in recovery mode. You pay the... - [Supporting the GoCyber Collective Cyber Insurance Summit](https://blog.oscarsixsecurityllc.com/blog/gocyber-collective-cyber-insurance-summit): Yesterday, Oscar Six Security had the privilege of co-sponsoring the GoCyber Collective Cyber Insurance Summit in Dayton, Ohio — alongside Taft Stettinius & Hollister LLP. It was a well-run event focu... - [Why Cyber Insurance Carriers Love RADAR](https://blog.oscarsixsecurityllc.com/blog/radar-cyber-insurance): The Premium Problem Cyber insurance premiums are skyrocketing. Carriers are tired of paying out ransomware claims for companies that had open RDP ports or unpatched VPN concentrators. To get coverage... ## Mission - [Claude + M365: AI Connector Risks Small Biz Must Know](https://blog.oscarsixsecurityllc.com/blog/connecting-ai-tools-claude-microsoft-365-security-risks): MSPs are seeing it happen in real time. A client calls, excited about a productivity win they read about on LinkedIn. They want to connect Claude — or some other AI agent — directly into their Microso... - [Junior IT Hire Security Checklist: Day One](https://blog.oscarsixsecurityllc.com/blog/junior-it-hire-security-checklist-day-one): Hiring your first or second IT person feels like a win. Someone is finally handling the tickets, the printer issues, the password resets. But here is what most small business owners do not think about... - [Conditional Access Policies: Setup Order for SMBs](https://blog.oscarsixsecurityllc.com/blog/conditional-access-policies-small-business-setup-order): There's a thread that keeps resurfacing in IT admin communities: "What conditional access policy baseline are you actually using across clients?" The answers range from "just MFA for all users" to ela... - [AI Support Bots: Security Risk Hiding in Plain Sight](https://blog.oscarsixsecurityllc.com/blog/ai-support-impersonation-vendor-chat-security-risk): You open a support chat with your firewall vendor. The rep responds instantly, asks clarifying questions, and seems helpful. You paste in your network subnet, describe your VPN configuration, and expl... - [Fake Interpol Emails Are Delivering Ransomware to Small Businesses](https://blog.oscarsixsecurityllc.com/blog/fake-interpol-ransomware-email-small-business-2026): You get an email. It says Interpol's cybercrime unit is reviewing your company. There's a file attached, password protected, password right there in the email so you don't even have to think about it.... - [Huntress vs. Windows Defender: Enough for SMBs?](https://blog.oscarsixsecurityllc.com/blog/huntress-vs-windows-defender-endpoint-security-small-business): An MSP admin posted a question to the community that a lot of IT professionals quietly wrestle with: Is Huntress actually worth it, or is Windows Defender enough? The post described a ClickFix/Fake Ca... - [Sarge v0.6: Windows Hardening, Backup & Rollback, Drift Detection, and Integration Tests](https://blog.oscarsixsecurityllc.com/blog/sarge-v06-windows-backup-drift-testing): Sarge started as a Linux-only NIST 800-53 gap analysis tool for OpenClaw deployments. Three months and thirteen releases later, it runs on three platforms, backs up your config before touching anythin... - [ClickFix Fake CAPTCHA: What SMB IT Managers Must Know](https://blog.oscarsixsecurityllc.com/blog/clickfix-fake-captcha-attack-smb-it-manager-guide): One employee. One confused moment. One copy-pasted command. That's all a ClickFix attack needs to turn your Tuesday into a full endpoint reimaging. An MSP recently described exactly this scenario in a... - [Windows Defender vs EDR: What's Enough in 2026?](https://blog.oscarsixsecurityllc.com/blog/windows-defender-edr-endpoint-security-small-business-2026): An IT admin on Reddit described it clearly: a user landed on a fake CAPTCHA page, got tricked into running a PowerShell command, and Windows Defender didn't flag a thing. The attack — a ClickFix lure... - [M365 Login Attacks: 5 Controls Every SMB Needs](https://blog.oscarsixsecurityllc.com/blog/microsoft-365-login-attacks-smb-controls): An IT admin posted something to Reddit that a lot of people recognized immediately: every single client they managed was getting hammered with Microsoft 365 login attempts at the same time, all traced... - [Printer Shared Email Accounts: The Credential Risk](https://blog.oscarsixsecurityllc.com/blog/shared-credentials-printer-scanner-mfp-email-security-risk): Someone posted on Reddit not long ago about their company's MFP scanners — six locations, all sharing a single generic Gmail account for scan-to-email. The thread blew up, not because it was unusual,... - [FortiBleed VPN Leak: Check Your Firewall in 10 Min](https://blog.oscarsixsecurityllc.com/blog/fortibleed-vpn-credential-leak-check-firewall-exposure): If you're running a FortiGate appliance at your office or for a client, stop what you're doing and read this. Security researchers have confirmed that attackers have harvested working credentials from... - [FortiGate Credential Leak: SMB Firewall Next Steps](https://blog.oscarsixsecurityllc.com/blog/fortigate-credential-leak-smb-firewall-decision): If you run a FortiGate firewall at your small business, this is not a drill. According to Security News (June 17, 2026), attackers have already compiled working credentials from more than 30,000 compr... - [EOL Server Risk: When Delaying Costs More Than Upgrading](https://blog.oscarsixsecurityllc.com/blog/eol-server-refresh-cost-vs-breach-risk-2026): The Budget Argument You're Having Is the Wrong One Anyone managing IT for a small organization in 2026 has had some version of this conversation: leadership sees the quote for a server refresh — hardw... - [Vendor Installed Pirated Software: Risks & What To Do](https://blog.oscarsixsecurityllc.com/blog/vendor-installed-pirated-software-risks-small-business): The Reddit Scenario That Should Scare Every IT Admin An IT admin posted a question that's more common than it should be: an outside vendor had been installing pirated proprietary software on a client'... - [Fake IT Workers Show Up In Person: Verify Access](https://blog.oscarsixsecurityllc.com/blog/fake-it-workers-in-person-identity-verification-access-control): Someone walks into your office carrying a laptop bag and a smile. They tell your front desk they're from your IT vendor, here to "run some updates." Nobody called ahead. But they seem confident, they... - [Social Engineering Breach: 4.9M Records Lost](https://blog.oscarsixsecurityllc.com/blog/social-engineering-breach-employee-account-small-business): Your firewall is fine. Your antivirus is up to date. Your patches are current. And then one of your employees picks up the phone. That's the story behind the Charter Communications breach — and it's a... - [npm Supply Chain Attacks: What to Check Right Now](https://blog.oscarsixsecurityllc.com/blog/npm-supply-chain-attack-ironworm-small-dev-shops): Two npm supply chain attacks landed in the same week. If you run a small dev shop, manage internal tools, or handle IT for an organization that touches any JavaScript code, this is your signal to stop... - [Why We Won't Scan a Domain You Can't Prove You Own](https://blog.oscarsixsecurityllc.com/blog/why-we-verify-domain-ownership-before-scanning): A new executive order signed in June 2026 said something the security industry already knew, but said it with the weight of the Justice Department behind it: using AI to access or damage a computer wi... - [Skipping Windows Server Patches: The Real Cost](https://blog.oscarsixsecurityllc.com/blog/windows-server-patching-cost-of-skipping-critical-vulnerabilities): Your domain controller is online right now. And if it hasn't been patched in the last few weeks, there's a reasonable chance someone already knows about a hole in it that you don't. This isn't hypothe... - [UniFi vs SonicWall for Small Business Firewalls](https://blog.oscarsixsecurityllc.com/blog/unifi-vs-sonicwall-small-business-firewall-comparison): Your MSP just recommended UniFi. Maybe they showed you a sleek dashboard demo, quoted a price that seemed reasonable, and told you it was the right fit for your size. What they probably didn't mention... - [5 Questions to Ask Before AI Touches Your Data](https://blog.oscarsixsecurityllc.com/blog/questions-to-ask-before-ai-tool-accesses-business-data): An MSP recently shared a story that should make every small business owner pause. A client had connected an AI tool to everything — company emails, shared files, meeting recordings — and configured th... - [Passkeys vs SMS vs Authenticator Apps: 2026 MFA](https://blog.oscarsixsecurityllc.com/blog/passkeys-vs-sms-mfa-vs-authenticator-apps-small-business-2026): Your MFA is on. You feel protected. And attackers are counting on that confidence. Here's the uncomfortable truth heading into 2026: multi-factor authentication is no longer a binary — you either have... - [The protobufjs RCE That Rode in Through firebase-admin](https://blog.oscarsixsecurityllc.com/blog/protobufjs-rce-firebase-admin-transitive-cve): This morning we cleared a CVSS 9.8 RCE out of a production Node.js application. The vulnerable package wasn't anywhere in our package.json — it was three levels deep, pulled in by code we trust every... - [BitLocker vs. Alternatives After YellowKey Exploit](https://blog.oscarsixsecurityllc.com/blog/bitlocker-vs-full-disk-encryption-alternatives-yellowkey-exploit): If your small business relies on BitLocker as your primary data-at-rest protection — and you've never touched the default configuration — you need to read this before your next workday. A zero-day exp... - [Employee Offboarding Security Checklist (Stop Breaches)](https://blog.oscarsixsecurityllc.com/blog/employee-offboarding-security-checklist-access-revocation): The moment you hand someone a termination letter, a countdown starts. Not metaphorically — literally. Their credentials still work. Their email still receives. Their VPN tunnel is still open. And if t... - [Dirty Frag Unpatched: Real Risks for Linux Servers](https://blog.oscarsixsecurityllc.com/blog/dirty-frag-linux-zero-day-unpatched-risk-small-business): If you run a Linux server, a NAS device, or any Ubuntu/Debian box at your organization, the last two weeks of security news should have your full attention. Two separate privilege escalation exploits... - [AI Just Wrote Its First Real Exploit](https://blog.oscarsixsecurityllc.com/blog/ai-just-wrote-its-first-real-exploit): It was only a matter of time. And now it's happened. Google has confirmed what the cybersecurity community has been bracing for: a threat actor used AI to independently discover a zero-day vulnerabili... - [Chrome's 4GB AI Download: Endpoint Security Risk](https://blog.oscarsixsecurityllc.com/blog/chrome-silent-ai-download-endpoint-security-small-business): If you manage endpoints for a small business or a handful of clients, you may have already noticed something odd: Google Chrome quietly pushed a 4GB AI model called Gemini Nano to user devices — no pr... - [Linux Under Siege: Patch Now or Get Owned](https://blog.oscarsixsecurityllc.com/blog/linux-kernel-vulnerability-patch-now-small-business-servers): If your business runs Linux on a server, NAS device, or cloud VM — and you haven't applied patches recently — you are not a hypothetical target right now. You are a current one. On May 8, 2026, three... - [Browser vs. Dedicated Password Manager: Which Is Safer?](https://blog.oscarsixsecurityllc.com/blog/browser-password-manager-vs-dedicated-password-manager-small-business): If your employees are saving passwords in Microsoft Edge — or any browser — you may have a bigger problem than you realize. Not a theoretical one. A confirmed, actively discussed, proof-of-concept-lev... - [5 AI Agent Security Gaps in Microsoft 365](https://blog.oscarsixsecurityllc.com/blog/agentic-ai-security-gaps-microsoft-365-msp): A thread started circulating in MSP communities recently that should have stopped every managed service provider mid-scroll. A frustrated IT admin described watching multiple clients self-deploy AI ag... - [Top 5 Vulnerability Management Tools for MSPs](https://blog.oscarsixsecurityllc.com/blog/top-5-vulnerability-management-tools-msp-multi-tenant): One week. One CVSS 10 RCE in Google's Gemini CLI. A 9-year-old undetected Linux kernel bug. And 271 zero-days discovered in Firefox by a single AI scanning tool. If you're an MSP managing a dozen or m... - [Teams Helpdesk Scams: What If Staff Can't Tell?](https://blog.oscarsixsecurityllc.com/blog/microsoft-teams-helpdesk-impersonation-social-engineering): Picture this: one of your employees gets a Microsoft Teams message from someone named 'IT Support — Helpdesk.' The message says their account has been flagged for unusual activity and they need to ver... - [Password Manager Compromised: What MSPs Must Do Now](https://blog.oscarsixsecurityllc.com/blog/bitwarden-cli-supply-chain-attack-msp-credential-risk): If you manage clients through a password manager — and most MSPs do — the Bitwarden CLI supply chain attack should stop you cold. Not because Bitwarden itself is broken, but because this incident expo... - [Windows Defender Zero-Days: What Small Businesses Need](https://blog.oscarsixsecurityllc.com/blog/windows-defender-zero-day-endpoint-security-small-business): If your small business is running Windows and you assumed Microsoft Defender was quietly handling endpoint security in the background, April 2026 just handed you a serious wake-up call. Three Windows... - [Fake Apps Draining Accounts: 5 Verification Steps](https://blog.oscarsixsecurityllc.com/blog/fake-app-malware-small-business-software-verification): A musician sat down one evening and downloaded what looked like a legitimate Ledger app from Apple's App Store. It had good reviews, a polished icon, and a familiar name. Within hours, his life saving... - [PDF Attacks vs. Phishing: What Costs SMBs More?](https://blog.oscarsixsecurityllc.com/blog/pdf-security-risks-vs-email-phishing-small-business-cost): For years, small business security training has hammered one message: watch out for phishing emails. That advice isn't wrong — but it's dangerously incomplete. While your team was scanning inboxes for... - [Zero-Day vs. Unpatched: Which Kills Small Biz?](https://blog.oscarsixsecurityllc.com/blog/zero-day-exploits-vs-unpatched-vulnerabilities-small-business): Two threats landed in security feeds this week that every small business owner and IT admin needs to understand — not because they're theoretical, but because they're active right now, and they target... - [Oscar Six Security: Our Mission and Why It Matters](https://blog.oscarsixsecurityllc.com/blog/test): Why We Built Oscar Six Security Cybersecurity has a noise problem. Vendors throw around jargon, stack fees on top of fees, and sell complexity like it's a feature. Meanwhile, small businesses, governm... - [Axios Supply Chain Attack: What MSPs Must Do Now](https://blog.oscarsixsecurityllc.com/blog/axios-supply-chain-attack-npm-patch-management-small-business): The alert hit Reddit on a Tuesday afternoon: New axios 1.14.1 and 0.30.4 on npm are likely malicious. Within hours, the post had thousands of upvotes and a thread full of engineers frantically checkin... - [Disaster Recovery vs Backup: What It Costs SMBs](https://blog.oscarsixsecurityllc.com/blog/disaster-recovery-vs-backup-small-business-cost): Your Backups Are Green. Your Business Would Still Go Dark. Somewhere in your infrastructure, a backup job completed successfully last night. The dashboard shows a green checkmark. Your IT admin breath... - [Supply Chain Attacks: How One Package Steals All Your Credentials](https://blog.oscarsixsecurityllc.com/blog/supply-chain-attack-oauth-token-theft-open-source-risk): Imagine you install a routine update to a Python library your team uses every week. No alerts fire. Your antivirus stays quiet. Your developers keep coding. Three days later, every OAuth token, API ke... - [Your AI Agent Has an Attack Surface. Here's How We're Mapping It to NIST 800-53.](https://blog.oscarsixsecurityllc.com/blog/ai-agent-attack-surface-nist-800-53-sarge): David Matousek recently published a threat model for OpenClaw that stopped me mid-scroll. Not because it was wrong — but because he was right, and we're already building the answer. His three question... - [Device Code Phishing: Why MFA Won't Save You](https://blog.oscarsixsecurityllc.com/blog/device-code-phishing-mfa-bypass-microsoft-365): You enabled multi-factor authentication. You trained your employees on phishing. You checked the boxes. And now a threat actor is sitting inside your Microsoft 365 tenant — authenticated, legitimate-l... - [Ransomware vs. Wiper Attacks: Know the Difference](https://blog.oscarsixsecurityllc.com/blog/ransomware-vs-wiper-attacks-small-business-healthcare): On March 11, 2026, a global medical technology company sent thousands of employees home — not because of a weather emergency or a power outage, but because Iran-linked hackers had wiped their devices... - [API Key Leaks: How One Mistake Costs $80K](https://blog.oscarsixsecurityllc.com/blog/api-key-exposure-credential-leak-cloud-billing-attack): Imagine waking up to a $82,314 cloud bill — for a service you barely use. That's exactly what happened to a developer who shared their story on Reddit. They had accidentally pushed an API key to a pub... - [Phishing Forwards: Why Protocol Beats Training](https://blog.oscarsixsecurityllc.com/blog/phishing-response-protocol-employee-security-small-business): It happened two weeks after phishing awareness training wrapped up. A well-meaning employee received a suspicious email, wanted to do the right thing, and forwarded it company-wide with a simple quest... - [Why Phishing Training Fails (And What Actually Works)](https://blog.oscarsixsecurityllc.com/blog/why-phishing-awareness-training-fails-repeatable-defense-system): Two weeks after completing phishing awareness training, an employee at a small business received a suspicious email. Instead of reporting it through the proper channel, they forwarded it company-wide... - [Oscar Six Radar Now Speaks A2A: AI Agents Can Buy and Run Vulnerability Scans Autonomously](https://blog.oscarsixsecurityllc.com/blog/oscar-six-radar-a2a-agent-to-agent-vulnerability-scanning): TL;DR: AI assistants can now buy and run security scans on their own through Oscar Six Radar. If you use AI tools to manage IT, they can talk directly to our scanner — no human in the loop required. D... - [Vibe Coding: Why AI-Generated Code Is a Security Bomb](https://blog.oscarsixsecurityllc.com/blog/vibe-coding-security-risks-ai-generated-code-small-business): Your Client's Employee Just Shipped an App. Nobody Reviewed the Code. It starts innocently enough. A motivated employee — maybe the owner's son, maybe someone in ops who's "good with computers" — disc... - [AI Agents Gone Rogue: When Your Digital Assistant Becomes Your Biggest Security Risk](https://blog.oscarsixsecurityllc.com/blog/ai-agents-security-risks-production-environments): The Amazon Kiro incident that caused a 13-hour AWS outage wasn't just a one-off mistake—it's part of a disturbing pattern of AI agents breaking free from their intended constraints and wreaking havoc... - [Free Vulnerability Scans During Our Beta](https://blog.oscarsixsecurityllc.com/blog/free-radar-vulnerability-scans-msp-beta): We Built a Scanner. Now We Need Real-World Feedback. Radar is our vulnerability scanning tool, and it's in beta. We're looking for MSPs and small business owners to put it through its paces — free of... - [Securing IT Infrastructure During Acquisitions: A Survival Guide](https://blog.oscarsixsecurityllc.com/blog/securing-it-infrastructure-during-acquisitions): You've spent years building relationships with your clients, understanding their IT environments inside and out. Then comes the dreaded call: "We're being acquired, and the new owners want a complete... - [Stop New Employee Access Demands That Create Security Holes](https://blog.oscarsixsecurityllc.com/blog/prevent-employee-privilege-escalation-access-control): Picture this: A new employee walks into your office on day three and demands "full server access" because they "need to understand how everything works." Sound familiar? If you're an MSP or small busi... - [ChatGPT Data Leaks: Why Small Businesses Can't Ignore AI Risk](https://blog.oscarsixsecurityllc.com/blog/chatgpt-data-leaks-small-business-ai-security-risks): The ChatGPT Data Leak Reality Check That MSP's question about whether clients are actually leaking customer data into ChatGPT? The answer just got a lot clearer – and more concerning. Recent research... - [SSL Certificate Management: Why 45-Day Certs Demand Automation](https://blog.oscarsixsecurityllc.com/blog/ssl-certificate-management-45-day-automation): SSL Certificate Management: Why 45-Day Certificates Demand Automation Now If you're still manually renewing SSL certificates, you're about to face a major problem. Let's Encrypt is moving to 45-day ce... - [How a Simple M365 Breach Cost One Company Six Figures](https://blog.oscarsixsecurityllc.com/blog/microsoft-365-breach-prevention-small-business): The Breach That Came From Inside the Tenant A recent story making rounds in IT circles should make every small business owner pause: an organization discovered that attackers had infiltrated their Mic... - [When Should Small Businesses Start Taking Security Seriously?](https://blog.oscarsixsecurityllc.com/blog/small-business-security-basics-when-to-start): The Moment Everything Changes It usually happens quietly. Your small business lands a bigger client. You sign a contract with a healthcare provider, a government agency, or a larger enterprise. Sudden... - [Self-Hosted RMM Tools: Hidden Security Risks MSPs Must Address](https://blog.oscarsixsecurityllc.com/blog/self-hosted-rmm-security-risks-msp-guide): The Growing Problem with Self-Hosted RMM Tools If you manage IT infrastructure for multiple clients, you've likely heard the horror stories—or worse, lived them. Self-hosted Remote Monitoring and Mana... - [NIST & MITRE Cutbacks: What SMBs Must Do Now](https://blog.oscarsixsecurityllc.com/blog/nist-mitre-cutbacks-small-business-security): The Federal Safety Net Is Shrinking If you've been following cybersecurity news, you've likely heard rumblings about significant changes at NIST (National Institute of Standards and Technology) and th... - [Vulnerability Scanning vs Penetration Testing: What's Right for Your Business?](https://blog.oscarsixsecurityllc.com/blog/vulnerability-scanning-vs-penetration-testing-what-small-businesses-need): The Pricing Confusion Is Real If you've ever requested quotes for penetration testing, you've probably experienced sticker shock—and confusion. One vendor quotes $3,000, another quotes $25,000, and a... - [MSP Internal Security: Protecting Your Own Infrastructure First](https://blog.oscarsixsecurityllc.com/blog/msp-internal-security-checklist-protect-your-own-infrastructure): The MSP Security Paradox There's an uncomfortable truth in the managed services world: the companies responsible for securing dozens of client networks often neglect their own infrastructure. It's the... - [Zero-Day Vulnerabilities: What Small Businesses Must Know](https://blog.oscarsixsecurityllc.com/blog/zero-day-vulnerabilities-small-business-protection): What Just Happened with the Cisco Zero-Day? On January 21st, Cisco confirmed that CVE-2026-20045—a critical vulnerability in their HTTP web services—is being actively exploited in the wild. CISA immed... - [Security Shouldn't Bankrupt You](https://blog.oscarsixsecurityllc.com/blog/security-shouldnt-bankrupt-you): We're here to change the game. For too long, cybersecurity has been a luxury good. If you weren't a Fortune 500 company with a million-dollar budget, you were left behind—or worse, sold "lite" version...