Welcome to The Senroc Download! This is your weekly briefing from the team at Senroc Technologies letting you know what we're seeing, what we're thinking, and tips you can use right now.
Microsoft's security team recently tracked a business email compromise attack from start to finish. An attacker gained access to an employee's email account, found an ongoing conversation with a business partner about a pending payment, sent a fake wire transfer request impersonating the employee, and deleted the sent message to cover their tracks. The entire sequence took 127 minutes.
This is why callback procedures matter before any payment goes out. By the time someone notices the email was fake, the money is usually already gone. The FBI reports that business email compromise has cost companies more than $26 billion in documented losses — and it works because it exploits existing trust, not technical vulnerabilities.
Takeaway: Any request to send money, change payment details, or wire funds should be confirmed by phone before it's acted on — using a number you already have, not one in the email. If it’s not already a written policy in your organization, it should be!
Source: Bleeping Computer, July 2026 / Microsoft Security Intelligence
Between July 21 and 22, at least 29 organizations were hit by a malvertising campaign that used a legitimate Claude.ai artifact to redirect users to a fake "Claude Desktop" download. The file looked like a real installer for the AI tool. It was actually SectopRAT, a remote access trojan that gives attackers full control of the infected machine. The attackers hosted the redirect on Claude.ai's own domain, which meant the URL users saw was genuine. Security researchers at Huntress named the campaign FakeAgent. Anthropic removed the malicious artifact once it was flagged on July 22.
The attack is a clear example of a pattern that's becoming more common: using legitimate, trusted platforms (AI tools, cloud services, app stores) as a delivery mechanism for malware. The domain looks right. The page looks right. The installer looks right. The problem is what's inside it.
Takeaway: For software your team installs, the rule is simple: navigate directly to the vendor's official website and download from there. Never install from a link in an ad, a search result, or a file shared informally. If an employee wants to add a new tool, it should go through whoever manages your IT before it gets installed.
Source: The Hacker News, July 2026
With fake installers becoming harder to spot, here's a quick checklist you can use before installing anything new. First: did you navigate to the download page yourself, or did you follow a link from somewhere else? If you followed a link, stop. Go directly to the vendor's website by typing the address into your browser. Second: does the URL match exactly what you'd expect? Attackers register domains like "claudedesktop-app.com" that look close but aren't official. Third: when in doubt, check with IT before installing. The few minutes it takes to ask is worth it.
Takeaway: Treat any unexpected prompt to install software as suspicious by default. Legitimate software updates don't come through pop-ups or links in emails. If someone or something is pushing you to install something right now, that's your indicator to slow down before moving forward.
If any of this made you think about your own setup, feel free to reach out. Happy to take a look at where things stand with our free evaluation.
Until next week,
Senroc Technologies



