It is Friday, May 22, 2026, and we are heading into the weekend. While you are probably thinking about your Saturday plans, a few digital shifts happened this week that are worth a quick look. Most of these situations are just minor hurdles that can be cleared with a few clicks. If you feel like your security hasn't been perfect lately, it is just because you haven't found the right rhythm yet. We are here to help you get there.
This week’s roundup covers some new tricks hackers are using in Microsoft 365, a necessary update for your browser, and why some "gentlemen" aren't actually being very nice to small businesses.
Microsoft 365 has some new update needs
Microsoft 365 is the heart of most small businesses. Because so many of us use it, hackers spend a lot of time trying to find ways inside. This week, we saw a few new methods that just require a bit of extra attention.
The Kali365 "Digital Key" trick
There is a new service out there called Kali365. It doesn't actually try to guess your password. Instead, it tries to steal your "OAuth token." Think of this token like a digital keycard. Once you scan your badge to get into the office, you don't have to keep scanning it at every single internal door.
Kali365 sends out fake emails that look just like a real Microsoft login page. If someone accidentally follows the steps, the hacker "just" grabs that digital keycard. Since the key is already validated, the hacker can walk right past your Multi-Factor Authentication (MFA). It is a sneaky move, but it is solvable. You can learn more about how these attacks work in our guide on why built-in security isn't always enough.
A quick fix for Outlook (CVE-2026-45803)
A new bug was found in Outlook this week, labeled CVE-2026-45803. It has a high "danger score" of 9.8 out of 10. This sounds big, but it is just a matter of running your updates. The bug could allow someone to run code on your computer just by sending a specifically crafted email. Microsoft has already released the fix, so you just need to make sure your team hits the "Update" button before they log off for the weekend.
Copilot and your data
AI tools like Copilot are making work much faster, but they can sometimes be a little too helpful. If your settings aren't just right, Copilot might accidentally show a sensitive file to someone in your company who shouldn't see it. It is just a configuration issue, and we can help you set up safe AI growth guardrails to keep your private data private.
Google Chrome requires a quick restart
If you use Google Chrome or Google Workspace, there are a couple of things to handle. Google released some emergency patches this week to fix "Remote Code Execution" bugs. This is just a fancy way of saying a website could try to take control of your browser.
There is also a new trend where "Background Botnets" are being found. Some malicious websites are using a trick to stay active in the background of your browser even after you close the tab. It is just a stealthy way for them to stay connected to your computer. Restarting your browser and keeping it updated usually clears these right up. At Black Clover, we keep 365 days of forensic logs, so if one of these sneaky background bots ever does pop up, we can see exactly when it arrived and what it tried to do.
Hackers are using your own tools against you
One of the biggest trends this month is a massive 277% surge in hackers using Remote Monitoring and Management (RMM) tools. These are the actual tools that IT teams use to help you fix your computer remotely.
Hackers love these tools because they are "legitimate." Most security software won't flag them because they look like they belong there. The hackers just trick a user into downloading a tool like AnyDesk or ScreenConnect, and then they have a permanent backdoor into your business.
The "Gentleman" Hacker
We also saw the rise of a new group calling themselves "Gentleman Ransomware." They target small businesses specifically. They don't use big, loud attacks. Instead, they use very polite phishing emails and sneaky tactics to slowly move through your network. They are trying to be quiet so they don't get caught.
The good news is that these "gentlemen" still leave digital footprints. We look for the identity signals they leave behind. By validating who is actually using your RMM tools, we catch the abuse that standard tools usually ignore. This is a core part of the essential cybersecurity practices we recommend for every SMB.
Keeping your cloud safe is part of the routine
Managing all these risks might feel like a lot, but it is just about having the right system in place. If your small business cloud is like a modern smart home, Black Clover Cyber Security is the team that monitors the sensors.
Microsoft and Google provide the walls and the doors, but we install the 24/7 monitoring systems. We watch over 50 different risk points in Microsoft 365 and 30+ points in Google Workspace.
- If a "digital keycard" is stolen, we see it.
- If a "gentleman" hacker tries to log in from a weird location, we lock the door.
- If your AI starts sharing files it shouldn't, we get an alert.
We don't just tell you there is a problem; we help you fix it. Most of our clients start with a simple assessment to see where they stand. It is a great way to get a prioritized 90-day hardening plan so you know exactly what to do next.
The Friday To-Do List
To make sure your weekend is as relaxing as possible, here is a quick list of three things you can do right now. They are just small steps that make a big difference:
- Update your apps: Open Outlook and Chrome, go to settings, and make sure you are running the latest version. This fixes that 9.8 score bug and the browser backdoors.
- Ask about your RMM: Ask your IT person or team which tools they use to access your computers remotely. If there are tools on your computers that you don't recognize, it might be time for a quick cleanup.
- Check your tokens: You can book a discovery call with us to see if your company's "digital keys" are being leaked on the dark web. It is a fast way to get peace of mind.
You've got this
Cybersecurity can feel complicated, but you don't have to handle it alone. Most of the risks we see are just opportunities to make your business a little stronger and more efficient. By staying aware and taking these small steps, you are already ahead of most other businesses.
Have a great, secure weekend. We’ll be here watching the monitors so you don't have to.
Ready to see if your digital office is secure? Book a Discovery Call today, or take our Cyber Security maturity Check or AI Readiness Quiz to get a head start on your safety plan. We are here to help you secure, defend, and protect your business.
If you’re unsure where to start, we are happy to walk through a quick assessment or answer any questions. DM us directly if you’d like help...
Let’s Make Sure Your M365 or Google Workspace Is Safe
✅ No pressure. Just a friendly checkup.
👉 Book your free consultation / assessment today at: info@blackclover-cyber.com





























