Issue #2 · July 2, 2026 · 6 min read

Issue #2 — Urgent password resets, a browser default that changed, and patch day

This week: why 'your password expires today' emails are the new favorite scam, a browser privacy default worth checking, and the automatic-update setting that quietly protects you.

Verified checked 2026-07-02

Advice checked against current CISA and NIST guidance; no vendor-specific claims made without a matching source.

8 sources cited across this issue

top story The Big One: why ‘urgent password reset’ emails are the new favorite scam

An email lands saying your password is about to expire, or that unusual sign-in activity was detected, with a button to “secure your account now.” The button leads to a page that looks exactly like your email provider’s or bank’s real login page. Type your password in, and it goes straight to the scammer — who now has thirty seconds to get into your real account before you notice anything wrong.

This works because it borrows real urgency: password expiration and suspicious-login warnings are things legitimate services actually send. The fake version just adds a fake deadline and a fake link. The visual copy is good enough now that you often can’t tell from looks alone.

What it means for you: the one reliable tell is the link destination, not the email’s appearance. Hover over (or long-press on mobile) any “secure your account” button before tapping it, and check that the web address actually matches the real service — not a close lookalike.

What to do: if you ever get one of these, don’t click the link at all. Open a new browser tab, type in the service’s real address yourself, and check your account from there. If something’s actually wrong, it’ll show up when you log in normally.

Sources

Checked 2026-07-02 — verification link technique matches current FTC anti-phishing guidance; no specific incident referenced.

cyber Threat Radar: fake tech-support pop-ups are back

A browser tab suddenly fills the screen with a loud warning — “Your computer is infected,” sometimes with a fake countdown or a real-sounding error code — and a phone number to call for “Microsoft support” or “Apple support.” It’s not a virus and neither company sent it; it’s a web page designed to look like a system alert. Calling the number connects you to a scammer who will try to get remote access to your computer or sell you a fake fix.

Small businesses are a good target for this because a shared office computer often has several people’s logins and files on it, and whoever’s nearest just wants the scary message to go away.

What it means for you: real operating systems don’t ask you to call a phone number to fix a security problem. If a pop-up tells you to call someone, close the browser tab (or force-quit the browser if it won’t close) rather than the number on screen — never let anyone you didn’t call take remote control of a work computer.

Sources

Checked 2026-07-02 — pattern matches current FTC tech-support-scam guidance.

ai AI at Work: what an AI scheduling assistant can actually see

AI scheduling tools that find meeting times, draft invites, and manage your calendar are a real time-saver, but to do their job they typically need broad access to your calendar and often your email — not just the ability to add events, but to read existing ones, including titles, guest lists, and sometimes attached notes.

That’s a reasonable trade for the convenience, but it’s worth knowing what you’re granting. A scheduling assistant with full calendar access can see things like a meeting titled “salary review — Jordan” or a client’s contact details, even though its actual job is just picking a time that works.

What it means for you: when you connect a new AI scheduling tool, check what permissions it’s requesting during setup — most services show this on an authorization screen before you approve. If it’s asking for access well beyond scheduling (like your full email inbox) for a tool that only manages a calendar, that’s worth a second look before you approve it.

Sources

Checked 2026-07-02 — describes a general permissions pattern common to calendar-integrated AI tools, not a claim about a specific product.

privacy Privacy Watch: check your browser’s new tracking-protection default

Most major browsers now ship with some form of tracking protection turned on by default, but the exact behavior — what’s blocked automatically versus what you have to turn on yourself — varies by browser and changes with updates. If you haven’t looked at your browser’s privacy settings recently, it’s worth five minutes to see what’s actually active versus what you assumed was active.

What it means for you: this isn’t about a single new rule everyone has to follow — it’s that “default” isn’t fixed. A setting you checked a year ago may have moved, been renamed, or been reset by an update. For a business owner handling client data in a browser, it’s worth confirming rather than assuming.

Sources

Checked 2026-07-02 — general guidance to review browser privacy settings periodically; no specific browser version claim made.

action Do This Now (15 min): turn on automatic software updates

Most successful break-ins don’t use some brand-new, unheard-of technique — they use a known flaw in software that hasn’t been updated yet. The single highest-leverage 15 minutes you can spend this week is making sure your computers, phones, and key business apps update themselves instead of waiting on you to remember.

  1. On each work computer, open Settings (Windows) or System Settings (Mac) and find “Windows Update” or “Software Update.”
  2. Turn on automatic updates, and if there’s an option to install security updates immediately rather than “notify me,” choose that.
  3. Do the same on work phones: Settings > System/General > Software Update > Automatic Updates, on.
  4. For your most important business apps (accounting software, point-of-sale, browser), check each one’s own settings for an auto-update option and enable it.
  5. Restart each device once after enabling this, so any pending update actually installs.

Sources

Checked 2026-07-02 — automatic updates are current CISA and NIST baseline guidance for small businesses.

explainer Plain English: what ’end-to-end encryption’ actually means

Encryption scrambles a message so it’s unreadable to anyone without the right key. “End-to-end” means the scrambling happens on your device and only unscrambles on the recipient’s device — not in between, and not on the company’s own servers running the app. That matters because it means even the company providing the messaging or email service can’t read the content if it’s genuinely end-to-end encrypted, only the sender and recipient can.

Not everything that says “encrypted” is end-to-end: a service can encrypt your data while it’s stored on their servers (protecting it from outside hackers) while still being able to read it themselves. Both are useful, but they protect against different things — one protects against outsiders, the other also protects against the company itself.

Sources

Checked 2026-07-02 — definition matches standard, current usage of the term.

roundup Quick Hits

Sources

Checked 2026-07-02 — password guidance reflects current NIST standards, which moved away from forced periodic resets.