Microsoft Is Retiring Text Message Logins for Microsoft 365!

If any of your employees log into Microsoft 365, Teams, SharePoint, or any connected business application by receiving a text message code as their primary way of proving who they are, that method is going …

CISA Flags Actively Exploited Flaws in F5 and What Your Business Needs to Patch Now

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on September 22, 2026, affecting Check Point security gateways, Arista's VeloCloud Orchestrator, and F5 BIG-IP — all network-edge systems that sit directly on …

Passkeys vs. Passwords

Passkeys now log people in successfully 93% of the time, compared to 63% for passwords, and businesses that deploy them see a 73% reduction in average sign-in time and an 81% drop in login-related support …

Finally! Microsoft Teams Is Getting a Security Upgrade

If you have been following TechTips Tuesday for a while, you know we have covered Microsoft Teams as an attack surface more than once. Criminals have used it to impersonate IT staff, deliver malware through …

AI Voice Cloning Is Now Behind 40% of Business Email Compromise Attacks

AI-generated deepfakes — mostly cloned voices — now show up in roughly 40% of business email compromise (BEC) attacks, up from under 5% in 2023, and the average loss per AI-deepfake incident has climbed to …

What Insurers Now Require Before They'll Cover a Cyberattack

Cyber insurers in 2026 require multi-factor authentication almost universally, endpoint detection or response tools on every device, and immutable, regularly tested backups before they'll issue or renew a policy — and 41% of small business …

Hackers Are Calling Your Employees and Pretending to Be IT, Again

We covered IT impersonation attacks on TechTips Tuesday earlier this year. At the time, attackers were using email bombing followed by fake Microsoft Teams messages to trick employees into installing malware. That attack worked because …

CMMC Phase II Pause Is Now Locked In, What Defense Contractors Still Must Do

The Department of Defense's pause on CMMC Phase II just became much harder to reverse. On September 3, 2026, DoD's principal director for defense pricing, contracting and acquisition policy issued a class deviation directing contracting …

That App You Connected to Google Workspace Two Years Ago Could Still Have Access to Everything

Think about how many apps and tools your team has connected to Google Workspace over the past few years. A project management tool here. An email automation platform there. A scheduling app, a survey tool, …

Windows 10 Security Updates: What Businesses Need to Know Before the October 2026 Deadline

Businesses still running Windows 10 need to act before October 13, 2026, when the first year of Microsoft's Extended Security Updates (ESU) program expires. After that date, staying protected means either paying for a second …