Welcome to The Senroc Download! This is your weekly briefing from the team at Senroc Technologies letting you know what we're seeing, what we're thinking, and tips you can use right now.

CYBERSECURITY
Phone scams using AI voice to not sound like robots

Most people have learned to recognize robocalls. They sound flat, awkward, and have no ability to interact. A new category of phone scam has changed that. Attackers are now using AI voice tools to make calls that sound like real people — natural conversation, pauses, responses to what you say. Security researchers have documented a platform called ATHR that runs these calls automatically at scale, walking individuals through credential theft the same way a human scammer would.

The calls typically start with an email that creates urgency — a fake security alert, a billing issue, an account problem — and then direct the recipient to call a phone number. That number connects to an AI agent that sounds like a support rep and collects login information in real time. The back-and-forth interaction bypasses the "this sounds fake" instinct most people have developed.

Takeaway: Train your team on one rule: your real IT provider, bank, or software vendor will never call you unexpectedly and ask you to verify your password or log into something over the phone. Hang up and call back on a number you already have on file.

Source: Bleeping Computer, July 2026

IT TIP
Check your email settings for auto-forwarding

When attackers get into a business email account, one of the first tactics they can use is to set up an auto-forwarding rule. Every email you receive starts going to the attacker silently — you never see it, your inbox looks normal, but they're reading your conversations, watching for wire transfer confirmations, vendor invoices, and financial discussions. It can run for weeks or months before ever noticing.

In email, go to your email settings and look for forwarding rules or inbox rules. There should be nothing forwarding your email to an address you don't recognize. If there is, it’s a serious problem that needs immediate attention. Checking takes less than a minute!

Takeaway: Check your email forwarding settings today and ask your team to do the same. If your business uses Microsoft 365, your IT provider should be disallowing external forwarding on all accounts by default. They can also run a report that shows all forwarding rules across every account at once — worth requesting periodically.

CYBERSECURITY
If your employees travel, hotel Wi-Fi is now a real credential risk

With summer travel in full swing, there's a specific attack pattern everyone should know about. Security researchers documented a campaign where attackers compromised hotel Wi-Fi and changed the DNS settings, so that anyone trying to log into Microsoft 365 was silently redirected to a fake Microsoft login page. Employees saw what looked like a normal login screen, but their credentials went straight to the attackers. The attack even bypassed MFA by requesting the authentication token in real-time from the employee allowing the attackers right through.

The campaign hit employees in financial services, legal, healthcare, and professional services across multiple U.S. cities. The common thread was travel: connecting to hotel Wi-Fi with a work device. Using your phone's personal hotspot or having a built-in cellular connection instead eliminates most of the risk at little to no cost.

Takeaway: When you or your team travel, use your phone's hotspot or built-in cellular connection for anything work-related. Hotel Wi-Fi is a shared, untrusted network and should be treated as such. Never install software or approve unexpected prompts while using hotel Wi-Fi and always check the URL when visiting sensitive websites.

Source: Bleeping Computer, July 2026

If any of this made you think about your own setup, feel free to reach out. Happy to take a look at where things stand with our free evaluation.

Until next week,
Senroc Technologies