ALCON DTS
Managing your business technology With over 15 years of experience, we are the premier IT service provider in Austin.
07/03/2026
If an email asks you to download a tool to "view a document," stop and verify before clicking.
A growing attack pattern is tricking employees into installing real IT software on their own machines.
The software is called RMM (Remote Monitoring and Management), and it lets IT companies remotely control computers for support purposes.
Tools like ConnectWise ScreenConnect, Datto RMM, SimpleHelp, N-able, and LogMeIn are all legitimate and digitally signed by reputable vendors.
That's exactly why attackers love them. Antivirus software doesn't flag them as malicious because they aren't malicious. They're just being installed by the wrong person.
In February 2026, Microsoft documented a campaign that hit 29,000 users across 10,000 organizations.
The lure was a fake "IRS Transcript Viewer" email. The download was actually a repackaged ScreenConnect installer.
Once an employee ran it, the attacker had full remote control of their machine.
The same trick is being used with fake Zoom invites, fake Teams calls, and fake DocuSign emails.
A few things you can do:
▶️ Ask your IT provider to maintain an allow-list of approved RMM tools. Anything outside that list gets blocked from installing automatically.
▶️ Train your team that "download this viewer to see your document" is almost always a phishing attempt. Real documents don't require a new program.
▶️ Audit your endpoints for RMM software your IT provider didn't install. If you see something unfamiliar, fla
06/25/2026
If your business uses a generic email like info@, sales@, or support@, there's a good chance you're paying for it incorrectly.
The default approach most SMBs take is to set up a regular user mailbox, share the password between staff, and call it a day.
That setup creates two real problems.
1) There's no audit trail of who sent what.
When someone leaves, they still have the password. And shared passwords are one of the most common ways small businesses get compromised.
2) You're paying for a Microsoft 365 license on a mailbox that no human owns.
Microsoft 365 has a built-in feature that solves both: Shared Mailboxes.
A Shared Mailbox lets multiple staff access the same email address (info@, support@, etc.) using their own personal logins.
Replies appear to come from the shared address.
Every action is logged under the individual employee. And it does not require a separate license if the mailbox stays under 50 GB.
How to set one up:
1. Sign in to admin.microsoft.com
2. Go to Teams & groups > Shared mailboxes
3. Click Add a shared mailbox
4. Enter a display name and email address
5. Click Add members and choose who gets access
Members can read, send from, and manage the shared address from their own Outlook within an hour.
When an employee leaves, you remove them from the mailbox in 30 seconds.
There are no password changes, and no risk of an ex-employee still reading client emails.
06/22/2026
Pay attention to this fake “Microsoft” scam.
If an email asks you to enter a verification code on Microsoft's login page, don't enter the code.
That request is the giveaway for a phishing technique called device code phishing, which has hit over 340 organizations across the US, Canada, and Europe since February.
What makes this attack dangerous is that it bypasses Multi-Factor Authentication entirely, even strong MFA.
The attacker is tricking you into authorizing their device into your Microsoft 365 tenant.
You get an email about a shared SharePoint document, a payroll bonus PDF, or a meeting invitation from someone who looks legitimate.
The link sends you to login.microsoftonline.com, which is the real Microsoft login page.
The page asks you to type in a short verification code that was included in the email. You enter it and move on with your day.
But what you did was approve the attacker's device into your Microsoft 365 environment.
They now have a valid access token tied to your account.
They can read your email, download your files, and set up mailbox forwarding rules without ever needing your password again.
A turnkey phishing kit called EvilTokens started selling on Telegram in February 2026, which means even low-skill attackers can run these campaigns at scale.
To shut this attack down inside your business:
▶️ Block device code authentication flow in Entra ID for users who don't need it.
This protocol was designed for devices with lim
06/18/2026
If a website ever tells you to press Windows Key + R, close the tab.
That single instruction is the giveaway for a fast-growing scam called ClickFix, which has been behind a wave of infostealer infections all year.
An infostealer is malware that scrapes every saved password, browser cookie, session token, and stored credit card...
You click a Google result that takes you to a hacked website.
A fake CAPTCHA pops up and tells you to press Windows Key + R, then Ctrl + V, then Enter to verify you're human.
The second you hit Enter, you've installed malware on your own machine.
This attack slips past most security tools because you run the command yourself.
No file was downloaded, so antivirus has nothing to scan.
The browser shows no warning.
From the operating system's perspective, you typed a command into a Windows utility, the same as any admin doing real work.
A few things you can do this week:
▶️ Tell your team that if any website prompts the user to press Win+R or paste something into the Run box, they should close the tab and report it.
▶️ Restrict PowerShell for non-IT staff using AppLocker or Windows Defender Application Control. Most office employees have no work reason to run PowerShell scripts.
▶️ Make sure your endpoint protection is doing behavioral monitoring and not just signature scanning. Microsoft Defender for Endpoint and most modern EDR tools have detection rules specifically for this attack chain.
There's no shame in falling
Click here to claim your Sponsored Listing.
Category
Telephone
Website
Address
5900 Balcones Drive #240
Austin, TX
78731