
Managed IT Services for Law Firms in NYC: Keep Matters Moving
NYC law firms need managed IT that protects client confidences, keeps filing systems online, and supports SHIELD-minded safeguards—without a full-time IT department.

Sangoma Switchvox CVE-2026-9586 Just Hit CISA’s Exploited List
CISA added Sangoma Switchvox CVE-2026-9586 to KEV on Sept. 2, 2026. Find leftover NYC phone gear, patch to 8.4.0.2+, and restrict internet exposure.

That SonicWall Box on the Edge Just Hit CISA’s Exploited List
On September 2, 2026, CISA added two SonicWall SMA1000 flaws to the Known Exploited Vulnerabilities catalog. If your Staten Island or outer-borough office still has an internet-facing SMA1000, treat it as an edge problem today—not a federal paperwork problem.

Know a Business That Needs IT? Earn Monthly by Referring Them to MicroSky
MicroSky’s referral partner program is free to join. You make a warm introduction. We close the deal. You earn a monthly commission for as long as that client stays.

That PaperCut Box Next to the Copier Still Answers From the Street
PaperCut confirmed in-the-wild abuse of NG/MF Application Servers. The first emergency patch was not enough — install Release 2, and if the web UI answers from the public internet, restrict it to trusted IPs today. Microsoft 365 did not patch the print box.

That SQL Box Under the Desk Just Hit CISA’s Exploited List
CISA added CVE-2019-1068 to the Known Exploited Vulnerabilities catalog on Aug 26. Federal agencies had until Aug 29. A 15-user NYC firm still running SQL Server 2014–2017 needs to find the instance, not wait for Patch Tuesday.

Your MFA Worked. They Still Stole the Session: Mirage2FA and NYC Microsoft 365 Tenants
ANY.RUN researchers counted 4,561 Microsoft 365 session-cookie thefts from the Mirage2FA kit. The victim finished MFA. The attacker kept the cookie. A password reset does not kick them out.

That Exchange Box in the Closet Still Needs the August 2026 Security Update
Microsoft shipped August 2026 Exchange SUs on Aug 11. Exchange Online is already covered. On-prem 2016/2019 only get the patch if you bought Period 2 ESU — which ends October 2026.

A Callback Beats a Deepfake: How NYC Law and Accounting Firms Stop a BEC Wire
FBI IC3 logged $3.05 billion in BEC losses in 2025. AI can write the email and clone a voice. A 15-user NYC firm still stops the wire with a callback to a number already on file.

NYDFS Named MSPs in an N-central Alert: What NYC Finance Firms Must Ask Their Provider This Week
NYDFS told regulated firms on Aug 11, 2026 to find out if their MSP uses N-able N-central. Here is what a NYC finance SMB should ask, and why SHIELD is not enough.

Microsoft 365 Backup Is Not a Backup: What NYC Law and Accounting Firms Lose in a Tenant-Wide Ransomware Event
A Recycle Bin is not a backup. For NYC law and accounting firms, a tenant-wide encrypt or wipe can take email, matter files, and tax workpapers with it.

Open Source Supply Chain Worms: How npm Packages Are Infecting NYC Businesses in 2026
Self-replicating malware in npm packages and open source repos is infecting businesses worldwide. Learn how NYC SMBs can protect their software supply chain.

Zero-Day Vulnerabilities Are Now Exploited in Under 3 Days: What NYC Businesses Must Do Now
CrowdStrike reported 88 percent of observed public-PoC exploitation in H1 2026 landed within 48 hours. Here’s what NYC businesses should do about patch velocity.

Microsoft 365 Posture Gaps: The Silent Attack Path Hacking NYC Small Businesses in 2026
Huntress’s “45% Problem” is an average Microsoft 365 Secure Score around 45 percent, not a count of tenants with a critical hole. Here’s how NYC businesses close the real gaps.

North Korea IT Worker Scheme: Cyber Threat to NYC Small Businesses
North Korea’s IT worker scheme funnels $2.8M+ into weapons programs and Russia’s war effort. Learn how NYC small businesses can protect themselves.