We empower businesses with cybersecurity and IT solutions that protect data, reduce risk, and enable secure growth.

Joined December 2021
164 Photos and videos
Pinned Tweet
Utah's K-12 districts now have new cybersecurity requirements under HB 44. The Utah Cyber Alliance was built to help navigate what comes next. Our inaugural forum is May 29 in Draper. The bill's sponsor, a former university CISO, and the head of UEN are all in the room. Free for all government and education employees. Register: utahcyberalliance.org/events
2
4
330
Harborcoat retweeted
Send this to your parents.
45
372
2,736
138,911
Harborcoat retweeted
do you understand what just happened to Robinhood.. Someone sent a perfect phishing email - real domain, DKIM pass, SPF pass, DMARC pass and Robinhood's own servers delivered it. Here's the chain: → Gmail treats john.doe@ and johndoe@ as the same inbox → Attacker registers a NEW Robinhood account using the dot trick of YOUR email → Sets the device name to raw HTML code → Robinhood's "unrecognized activity" email renders it unsanitized The "Review Activity Now" button? Attacker's phishing site. The email? 100% real.. Sent by Robinhood.. Signed by Robinhood.. Just because it passed every security check doesn't mean it's safe.
Apr 27
New Robinhood phishing chain that's kinda beautiful: 1. Attacker creates an RH account using the Gmail dot trick of your email (same inbox, different address) 2. Sets device name to HTML 3. RH's "unrecognized activity" email renders the device name unsanitized (html injection) The result is a real email from noreply@robinhood.com, DKIM pass, SPF pass, DMARC pass, with a phishing CTA Just because it's real, doesn't mean it's safe... $HOOD
170
656
6,586
2,303,410
Harborcoat retweeted
🚨 BREAKING: Toronto Police just seized “SMS Blasters” fake cell towers never seen before in Canada. These portable devices hijack thousands of phones at once, blast fake bank/Canada Post texts, and knock out real service (even 911 calls). Tens of thousands of phones hit. Over 13 MILLION disruptions. Three men charged 🇨🇳 • Dafeng Lin, 27, of Hamilton • Junmin Shi, 25, of Markham • Weitong Hu, 21, of Markham This is next-level cyber crime on our streets. Stay alert. Never click surprise links. #Toronto #CyberCrime #ScamAlert
Toronto police seize 'SMS blasters,' a cybercrime weapon never before seen in Canada nationalpost.com/news/canada…
1,146
12,187
27,126
2,104,644
Some of the problem is that you only hear mostly about the attacks on big, publicly traded companies that can't hide. Small and medium sized companies are too embarrassed or don't want the fallout from disclosure. So, everyone thinks it won't happen to them. Until it does.
No one cares about cybersecurity.
3
65
This is how SAT training should be. Our partner Beauceron is working on just that. @BeauceronSec
68
Harborcoat retweeted
Here is a video of a North Korean IT worker being stopped dead in their tracks upon being required to insult Kim Jong Un. It won't work forever, but right now it's genuinely an effective filter. I'm yet to come across one who can say it.
I would be interested in seeing data that supports the idea that DPRK workers are stopped dead in their tracks upon being required to insult Kim.
318
1,567
17,515
3,639,933
Classic. I love it when a plan comes together. These scams cost over $300M a year.
1/ Meet Kabir Singh, an Indian scammer who impersonates Apple support and then rips off innocent vulnerable people. He tried to scam me......but instead of paying him money, I hacked into his laptop and redeemed $10,000 worth of giftcards live on webcam!
2
57
Harborcoat retweeted
NIST just launched an AI Agent Standards Initiative for identity, security, and interoperability. AI agents are becoming economic actors with zero legal infrastructure in place. We require businesses to register to operate. Why expect less of AI agents? nist.gov/news-events/news/20…
56
258
928
110,720
Treating your SD-WAN like 'set it and forget it' infrastructure? That assumption is being exploited right now. CISA confirmed active global exploitation of Cisco SD-WAN vulnerabilities -- including an auth bypass that requires *zero credentials*. A compromised controller isn't one device. It's your routing, your segmentation, your visibility. Three things to do today: 1. Confirm patch status on your SD-WAN controllers -- not your MSP's word, actual confirmation 2. Audit who has management-plane access and from where 3. If a third party manages this for you, ask for their patch cadence in writing
56
Patched the Ivanti EPMM zero-days and moved on? Stop. These backdoors survive patching -- meaning you may have locked an attacker *inside* your MDM. MDM owns every managed mobile device. Audit for compromise first, then patch. #CyberSecurity #MDM
46
Bargain time?
MASSIVE CRASH IN CYBERSECURITY STOCKS SINCE ANTHROPIC LAUNCHED CLAUDE CODE SECURITY. Over $52.6 billion wiped out in just 2 days. CrowdStrike is down 20%, wiping out $19.6 billion. Palo Alto Networks is down 8.9%, wiping out $11.7 billion. Cloudflare is down 18.5%, wiping out $11.2 billion. Zscaler is down 17.3%, wiping out $4.6 billion. Infosys is down 3.4%, wiping out $2.9 billion. Okta is down 16.7%, wiping out $2.6 billion.
1
1
36
A Qilin ransomware gang breached Romania's national oil pipeline operator Conpet S.A., exfiltrating sensitive data and disrupting operations. The attack highlights the growing threat to critical infrastructure. Organizations can mitigate such risks by enforcing network segmentation, maintaining immutable backups, and implementing rapid incident‑response playbooks. Regularly patching systems and monitoring for anomalous privileged‑access activity are also essential. How are you strengthening defenses around your critical assets? For more details visit harborcoattech.com
66
A member of the Crazy ransomware gang was caught hijacking legitimate employee‑monitoring software and the SimpleHelp remote‑support tool. The abuse gave them persistent footholds in corporate networks, evaded detection and primed ransomware deployment. This highlights how trusted IT utilities can become a backdoor for attackers. Organizations should audit remote‑support access, enforce least‑privilege, and monitor for abnormal activity. How are you tightening controls on monitoring and support tools? harborcoattech.com
44
The EU Commission was hit by a hack at the end of January, targeting its mobile device management system. Attackers likely leveraged two fresh Ivanti Endpoint Manager Mobile flaws (CVE‑2026‑1281, CVE‑2026‑1340) to steal employee names and phone numbers, though no devices were compromised. The agency sealed the breach in nine hours, underscoring the value of rapid incident response and strict Zero‑Trust controls. Patch management and continuous monitoring are now non‑negotiable. How are you hardening your supply‑chain and MDM stack? More details at harborcoattech.com
1
71
A Phorpiex botnet‑aided phishing campaign is using malicious Windows shortcut (.lnk) files to drop the offline‑only Global Group ransomware. The LNK payload silently runs PowerShell, pulls the encryptor and encrypts files locally, sidestepping network‑based detection. Experts urge disabling hidden extensions, tightening LNK execution policies, and boosting endpoint behavior monitoring to spot the rapid encryption. How are you strengthening your endpoint defenses? harborcoattech.com
25
Today BeyondTrust disclosed a critical RCE vulnerability in its Remote Support and Privileged Remote Access tools that lets unauthenticated attackers execute code on any managed endpoint. The bug scores high on CVSS and affects every organization using the platform for remote assistance. Rapid patching and network segmentation are the first lines of defense, while continuous monitoring can spot any surprise command execution. Have you verified your remote support stack is up‑to‑date? More details at harborcoattech.com
70
BridgePay, a major U.S. payments gateway, confirmed a ransomware strike that knocked key systems offline Friday, sparking a nationwide outage across its platform. Attackers encrypted transaction databases, halting card processing for merchants east of the Mississippi. Experts say robust backups, network segmentation, and real‑time anomaly monitoring can limit damage. As the industry races to restore services, organizations are re‑evaluating their incident‑response playbooks. How are you protecting your payment infrastructure? More details at harborcoattech.com
1
81