| How a cybersecurity company discovered an AiTM attack by accident. |
Presented By |  |
|
CYBERSECURITY Digital kombat  Getty Images | Researchers at cybersecurity company NCC Group discovered a cutting-edge adversary-in-the-middle (AiTM) attack—and they did so by complete accident. Dubbed “Kitana,” this AiTM platform draws in victims to a fraudulent website using standard-issue URL squatting domains and malicious advertising, then tricks them into inputting sensitive information, including passwords and payment details, according to NCC Group’s Cyber Threat Intelligence report. Unlike more traditional attacks that often involve compromising a legitimate website to steal consumer info, though, Kitana leverages malicious domains that mimic actual hospitality and commerce websites. The attackers can then monitor victims’ activities on these fake sites in real time, stealing whatever’s inputted. Good catch.—CN |
|
|
Sponsored By Salesforce Moving IT teams forward  | The biggest technology shift in a generation is happening right now. Dive into strategies, case studies, and hands-on training built for IT teams at Dreamforce from Sept. 15–17 in San Francisco. Whether you’re reining in solution sprawl or deploying secure AI architecture, you’ll spend three days in sessions built to prepare you for the future of IT. Here’s a sneak peek at the new sessions dropping weekly: - Build Better on Salesforce: App and Agent Dev Workshop
- Scale Agents, not Complexity, with Multi-Agent Orchestration
- Agentforce Deployment Best Practices: From Setup to Success
- Security Keynote: Trust Across Agents, Data, and Platforms
Give your team access to the skills, practical training, and connections that drive results at Dreamforce. Can’t make it to SF? Dreamforce streams live on Salesforce+ for free. Save over $3.9k when you register three or more people. |
|
|
SOFTWARE Open season  Ben Kothe | It’s always open (source) season at Bloomberg these days. That wasn’t always the case, said Phil Vachon, head of infrastructure at Bloomberg’s CTO office. When he started at the financial-services company in 2010, open source was viewed with suspicion, and tech teams focused more on building their own technology solutions. But over the past decade, Vachon added, there’s been a growing realization that open source could allow engineers to accelerate delivery of higher-quality projects. “We’ve gone through great lengths, going from a culture that was very difficult to contribute to open source 15 years ago, to today, where the barriers are actually extremely low,” he said. “We almost virtually give people carte blanche to contribute to open-source projects.” Open the door.—CN |
|
|
CYBERSECURITY Dropping the veil  Illustration: Morning Brew Design, Photos: Adobe Stock | While some cyberattackers are relying on AI and cutting-edge tools to get through organizations’ increasingly powerful defenses, others are launching stealthy attacks that leverage trust in existing platforms—and they’re succeeding, at least against companies without much budget for cyber defense. One such attack, known as VEIL#DROP, is a multi-stage malware campaign where attackers steal credentials, passwords, crypto wallet information, and more. According to Aaron Beardslee, manager of security research at Securonix, whose team uncovered the threat, VEIL#DROP exploits Google’s Blogger and Blogspot, which are used by independent creators and small businesses for low-lift publishing. It starts off with the attacker socially engineering a victim into opening a fake PDF document that actually contains a malicious JavaScript file. And then the click.—CN |
|
|
Sponsored By Auvik Networks  | Where’s your network switch? No judgment if it’s on a dusty shelf in a closet. But you might wanna check out Auvik’s cheat sheet. It outlines how to set up a switch in a cleaner environment. It also has tools to help cut upstream costs, optimize routing table space, and stop network loops. Grab your free copy. |
|
|
Thursday Quiz What do you know?  Amelia Kinsinger | The week’s biggest IT stories—now in quiz form. Test yourself on the latest cybersecurity headlines, software news, and tech breakthroughs in a quick, competitive challenge built for IT pros. Challenge your coworkers and see how your score stacks up! Ace the quiz |
|
|
patch notes  Francis Scialabba | Today’s top IT reads. Stat: 17%. That’s how much Meta’s stock price has declined in the past year. (the Wall Street Journal) Quote: “I think we’re all going to be much busier than we thought we were supposed to be in a post-superintelligence world.”—Sam Altman, OpenAI CEO, on how AI may not substantially change the workweek after all (Futurism) Read: The New York Times continues its fight with AI, even as it uses AI to support its reporting. (Wired) Agentic innovation: Dreamforce 2026 is coming to San Francisco from Sept. 15–17. Every session is designed to provide the practical skills needed to put your agentic strategy to work the minute you’re back in the office.* *A message from our sponsor. |
|
|
Jobs  | CollabWORK connects you to the hidden job market through IT Brew and other trusted channels. Browse roles curated specifically for this community by clicking through to the job board. |
|
|
Written by Caroline Nihill Was this email forwarded to you? Sign up here. Get smarter in just 5 minutes Take The Brew to work Interested in podcasts? | ADVERTISE//CAREERS//SHOP//FAQ
Update your email preferences or unsubscribe here. View our privacy policy here.
Copyright © 2026 Morning Brew Inc. All rights reserved. 22 W 19th St, 4th Floor, New York, NY 10011 |
|
|