CyberHoot’s Cybersecurity Newsletter: August 2026

27th August 2026 | Newsletters CyberHoot’s Cybersecurity Newsletter: August 2026

Editor: Craig Taylor

Welcome to CyberHoot’s August Newsletter!

I started 30 years ago in Cybersecurity working for a firewall company (Border Network Technologies later bought by Secure Computing). Back then the WWW did not exist, email was a text based tool that was opening communications like never before. My psychology degree didn’t help me much initially, but those O’Reilly books – well they became my bibles. TCP/IP, DNS & Bind, SMTP, does anyone reading this remember active vs. passive FTP?

Back to firewalls. In the late 1990s we spent too much time convincing people and companies connecting their internal networks (Token Ring, IPX/SPX, Vines, NetBeui, Appletalk) to the Internet, that a firewall was a minimum essential security requirement. At the time, firewalls were split into two camps – slower, arguably more secure proxy-based firewalls and faster throughput stateful-inspection firewalls. They were the major security perimeter protecting most companies pre and post-WWW. When a firewall had a security issue, the highest priority in anyone’s world was patching and mitigating that risk.

With Frontier Models systematically testing software, including firewalls, with more capabilities than any human ever had, it’s no wonder we’re seeing an enormous increase in the vulnerability discovered and patches released over the last 5 months of 2026! Major vendors have been releasing not double or triple of patches, but closer to between 5x and 20x more patches!

That’s the context with which CyberHoot wrote about two recent zero-days found in SonicWall’s firewall. They are not the only Firewall vendor to have zero-days, rather, they are emblematic of a recent explosion in Frontier AI penetration testing and vulnerability identification. This is the early waves of a storm that’s coming. The storm could be a category 5 hurricane leading to more breaches than we’ve seen in recent history. According to this Five Eyes advisory, we have months to prepare, not years.

CyberHoot’s advice to all of you is to complete an AI readiness assessment (Email AIReadiness@CyberHoot.com and we’ll send one to you). That assessment goes a little beyond the following 6 things you should start with:

  1. Reduce Your Attack Surface: turn off unused Internet ports/protocols. Board up as many windows and doors as possible.
  2. Patch Faster: automate patching where permitted, shorten patch windows to the barest minimum possible.
  3. Isolate aging systems that cannot be upgraded or patched: Place these systems on a separate VLAN or network. Longer term, use AI to port aging systems to modern development languages, hardware, and support.
  4. Reduce Sensitive and Critical Data: This one is most often overlooked. Eliminate unneeded data from your internal network and cloud systems. In a breach you do not want to be contacting clients from 10 to 25 years ago.
  5. Deploy a Honeypot: quick breach detection gives you a better chance at preventing significant damage to your business.
  6. Continue User Education: frontier AI models attacks will lead to a 1-2 year storm after which humans return to the “weakest link” of your cybersecurity program. Encourage awareness training engagement, reward good behaviors (high compliance), and call out high performers publicly. Build positive company culture alongside awareness.

Hope this helps,
Craig Taylor, Editor

In this Newsletter:

Our second blog article explores how organizations are embracing AI without creating unnecessary security and privacy risks. Blocking AI entirely is rarely practical, but ignoring its use isn’t the answer either. Clear guidelines, employee education, and thoughtful controls can help teams take advantage of AI while keeping sensitive company, customer, and employee information protected.

From there, we turn to a different technology raising important questions about privacy and trust: Flock cameras. License plate recognition and similar monitoring technologies can provide valuable security benefits, but they also highlight a lesson that applies to businesses of every size. Collecting data creates responsibility. Customers and employees increasingly want to know what information organizations collect, how it is used, who can access it, and how long it is retained. Review and update your Privacy Policy calling out LLM usage, training, and the security, privacy, confidentiality of the data you collect from your customers in it.

Both stories share a common theme: new technology can deliver tremendous value, but trust depends on how responsibly that technology is used. Whether your organization is adopting AI tools or collecting customer and operational data, transparency, thoughtful policies, and strong security practices are essential.

This month, we encourage you to:

  • Establish clear guidelines for how employees can safely use AI tools at work. Check out our AI Usage Policy under Custom Hoots => Document Library.
  • Remind employees never to enter sensitive, confidential, or customer information into unapproved AI platforms.
  • Review what data your organization collects and make sure there is a clear business reason for keeping it.
  • Be transparent about how information is collected, stored, shared, and protected.
  • Remember that cybersecurity isn’t only about protecting systems—it’s also about protecting the trust people place in your organization.

Laugh. Learn. Hoot Up!

Craig CEO,
Co-Founder, CyberHoot


Meet Manic: The Android Malware With a Sneaky Backup Plan


SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware


Your Team Is Already Talking to AI. Here’s How to Keep IT Safe.


What Flock Cameras Teach Every Business About Data and Trust


CyberHoot has officially achieved a long-standing goal of being featured on the legendary “Security Now!” podcast with Leo Laporte and Steve Gibson. To be 100% clear, this is a paid sponsorship of the podcast.

In addition to that, Leo Laporte personally endorsed CyberHoot:

“When we got phished [before CyberHoot] it became pretty clear we needed to do more to protect our company. The same old training just wasn’t working. CyberHoot came to the rescue. It’s fun, our team loves it, and best of all, it’s helping to keep us safe. Hoot on!” — Leo Laporte

Please watch this quick 3-minute feature as Leo Laporte shares his experience with HootPhish and explains why CyberHoot’s positive reinforcement approach to phishing education caught his attention.


Liking CyberHoot? We need your help. Please leave us your review at G2.com!


G2 –

For more information on how to leave a CyberHoot review, please watch the brief video overview below.  Note: to avoid fraudulent reviews, each review website will require to you to create and validate your identity through an email account registration process.



We’re excited to share several new additions to our Partner Integrations page, making it easier for partners to connect CyberHoot with the tools they already use every day. These new integrations help streamline client and user syncing, simplify training management, and make it easier to keep documentation up to date across your systems.

“Our partners asked us to meet them inside the tools they already use every day, so that’s what we did. Partners sync clients and users into CyberHoot in minutes, and view training progress inside their existing tools. This means less manual work, automated billing, better retention, lower costs, and safer clients!” said Craig Taylor, CISSP, CEO and Co-Founder of CyberHoot.

New integrations are now available for HaloPSA, Autotask PSA, ConnectWise PSA, Hudu, and IT Glue. Whether you’re looking to sync companies and users into CyberHoot for training or publish tenant training status directly into your documentation platform, these integrations are designed to reduce manual work and help you manage your clients more efficiently.


We’ve been quietly building the largest upgrade to cyber awareness gamification in CyberHoot history — and it’s going to change how your users experience training. Think points you can actually earn, achievements worth bragging about, avatars, leaderboards, and a whole new way to show off your organization’s cyber strength.

Complete your training. Report those phish. Every action is about to count like never before.

Stay tuned — the flock is about to take flight.


Please note: CyberHoot is upgrading all Power Users to Autopilot for free. Contact support@cyberhoot.com to schedule your free upgrade. Power platform will be retired later this year Sept. 2026.

Autopilot Platform Release Notes

  • Added Guided tutorial to HootPhish Challenge.
  • HootPhish now opens with an interactive guided tutorial that users must complete before their first graded test.
  • Make AttackPhish email attachments clickable links to the landing page.
  • Sync user language from Entra ID and Google on user creation.
  • Add admin ability to manually mark an assignment complete for a user. 
  • Show count of AttackPhish emails a user has reported.
  • Allow editing the manager of Entra/Google-synced users.
  • Preserve manually-assigned local managers when syncing Entra/Google users.
  • Simulations: show optional HootPhish walkthrough link.
  • Show AttackPhish relay delivery status + detail in partner Email Logs.
  • Add tenant Integrations page (Microsoft/Google/Slack) and Slack setup page. Slack integration: deliver assignment first notices and reminders via Slack DM. Microsoft Teams assignment notification delivery.
  • Launch HootPhish training from the AttackPhish failure landing page.
  • Added ability to export custom report in excel format. Added report format selection for custom reporting in settings.
  • Give Admins ability to merge duplicate users and move users between tenants. Users page: Merge User Into / Move To Another Tenant (single + bulk).
  • Support mixed assignment types in CustomHoots training programs (Let CustomHoots programs mix videos, documents and HootPhish).
  • Add CSV export for AttackPhish report results.
  • Export a phishing campaign’s results and assigned training results to CSV.
  • Ingest and show AttackPhish relay delivery status in Email Logs.
  • Partners can pause their subscription for 90 days instead of cancelling.
  • Allow editing videos and dates on pending training programs.
  • Allow editing videos and dates on pending Custom Hoot programs.
  • Added ability to pause a tenant’s training.
  • Added Assessments power-up.
  • HaloPSA integration: sync clients and end users into CyberHoot for training.
  • Autotask PSA integration: partner UI for connecting, mapping companies, and syncing. Sync companies and contacts into CyberHoot for training.
  • ConnectWise PSA integration: partner UI for connecting, mapping companies, and syncing. Sync companies and contacts into CyberHoot for training.
  • Hudu integration: publish per-tenant training status into partner documentation. Partner UI for publishing tenant training status.
  • IT Glue integration: publish per-tenant training status into partner documentation. Partner UI for publishing tenant training status.

Power Platform Release Notes

  • Added Guided tutorial to HootPhish Challenge.
  • HootPhish now opens with an interactive guided tutorial that users must complete before their first graded test.
  • Make AttackPhish email attachments clickable links to the landing page.
  • Sync user language from Entra ID and Google on user creation.
  • Add admin ability to manually mark an assignment complete for a user.
  • Show count of AttackPhish emails a user has reported.
  • Simulations: show optional HootPhish walkthrough link.
  • Launch HootPhish training from the AttackPhish failure landing page.
  • Add CSV export for AttackPhish report results.
  • Export a phishing campaign’s results and assigned training results to CSV.
  • Ingest and show AttackPhish relay delivery status in Email Logs.
  • HaloPSA integration: sync clients and end users into CyberHoot for training.
  • Autotask PSA integration: partner UI for connecting, mapping companies, and syncing. Sync companies and contacts into CyberHoot for training.
  • ConnectWise PSA integration: partner UI for connecting, mapping companies, and syncing. Sync companies and contacts into CyberHoot for training.
  • Hudu integration: publish per-tenant training status into partner documentation. Partner UI for publishing tenant training status.
  • IT Glue integration: publish per-tenant training status into partner documentation. Partner UI for publishing tenant training status.

Dark Web Monitoring

Dark Web Monitoring is the continuous process of scanning hidden online marketplaces, forums, data dumps, and criminal websites for stolen information related to an organization, such as email addresses, passwords, customer data, financial information, or intellectual property.

The goal is to detect exposed credentials or sensitive information early so organizations can respond before cybercriminals exploit it.

Unlike actively searching the dark web yourself, dark web monitoring services automatically monitor known sources where cybercriminals buy, sell, and share stolen data and alert organizations when their information appears.

Click here to read more!



Enroll in CyberHoot’s Referral Program today and start earning a 20% share of all revenue generated for one year by those who register through your exclusive referral link. As a referral partner, not only will you receive financial rewards, but you’ll also experience the satisfaction of aiding others in becoming more security-conscious, safeguarding them against cyber threats. Don’t hesitate, sign up now at https://cyberhoot.com/referral-program/.

Referral through Autopilot’s Dashboard:

Join CyberHoot in our mission to create a more aware and better secured world! Recommend CyberHoot Autopilot to a friend, and they will enjoy a complimentary first month. For every new sign up who uses your referral link, you will receive a free month added to your account. This offer is exclusively for first-time CyberHoot registrants.


Know someone who had a close call recently with a cyber attack, phishing email, or social engineering phone call?  Recommend CyberHoot’s free cybersecurity training.  They’ll receive six (6) videos (each video is 3-4min.) and one of our positive reinforcement, hyper-realistic, phishing simulations. All for free.

Registration: https://cyberhoot.com/individuals


Looking for additional resources?

CyberHoot Case-Studies

CyberHoot White Paper Download – How HootPhish Improves upon AttackPhish

All New: 2025 Infographics on Cybersecurity Statistics


Secure your business with CyberHoot Today!!!

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

When “Apple Support” Calls You Back, Hang Up

When “Apple Support” Calls You Back, Hang Up

Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: This week's blog has a...

Read more
Meet Manic: The Android Malware With a Sneaky Backup Plan

Meet Manic: The Android Malware With a Sneaky Backup Plan

Every so often a piece of malware comes along with a trick clever enough to make security researchers pause and...

Read more
SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

Author: Craig Taylor I cannot visit a coffee shop, go for a round of golf, have a friendly conversation with...

Read more