Six attacks from the last 90 days. How many would your stack stop?

All six of these are real, recent, and aimed at businesses exactly the size of your clients. One card each: what happened, what it takes to pass, and how DefensX passes it. Count your own passes. The scorecard is at the bottom.


The last 90 days, in six incidents

The ransomware operator was an AI

01 · JULY

An AI agent ran a full ransomware operation solo: found the way in, fixed its own failed steps in 31 seconds, wrote the ransom note. Attacks now run at machine speed, against everyone.

PASS IF a never-seen page meets something smarter than allow-or-block, automatically.

DEFENSX Unknown sites open in Remote Browser Isolation or Read-Only. The wall is already inside the page.


MFA bypass, $400 a month

02 · JULY

The Forg365 kit rents MFA-relay phishing as a subscription: real-time relay, stolen sessions, clean delivery. Elite tradecraft is now a monthly plan.

PASS IF a user physically cannot submit their company password on a perfect login clone. Not “trained not to.” Cannot.

DEFENSX Credential filters locks passwords to trusted domains. The clone collects nothing.


24 billion passwords, already out

03 · JUNE

One exposed database: 24B stolen records, plaintext passwords included, harvested by infostealers. Some of your clients’ employees are in piles like this right now.

PASS IF you can hand any client a per-user list of their exposed credentials, today.

DEFENSX The credential exposure report: every leaked login, per employee, per tenant, in minutes.


Malware in an AI costume

04 · APRIL

1,100+ malware samples posed as popular AI apps this year (+21%), plus 108 malicious “AI assistant” Chrome extensions stealing accounts at scale.

PASS IF the fake “ChatGPT” ad never loads, the installer never lands, and you can list every extension in the fleet.

DEFENSX Malvertising blocked pre-load, Zero-Trust File controls on downloads, extensions under management.


The breach with no attacker

05 · ALL YEAR

Customer lists, contracts, and code, pasted into unapproved AI tools by people just working faster. No alarm, because nothing was “attacked.”

PASS IF you can say which AI tools a client’s staff used last month, and show a record when the insurer asks.

DEFENSX AI tool governance, paste and upload control, an LLM prompt log, and Auto Pilot coaching the users who earn it.


The target was the MSP

06 · JUNE 29

A CVSS 10.0 flaw in a remote-support tool forged technician sessions: every client endpoint underneath, inherited at once. Identity abuse now defines MSP risk.

PASS IF everything above is also true for your own technicians. Their passwords, sessions, consoles.

DEFENSX The same layer, on your team first: admin domains locked, console behind MFA and IP limits, RBAC.

Sources: Sysdig, The Hacker News, Cybernews, Kaspersky Securelist, ConnectWise 2026 MSP Threat Report. Full links in the online version.


Your score

0-2: you run the standard stack, and these six attacks were built to walk around exactly that. The gap isn’t a missing tool. It’s a place your tools have never been: inside the browser.

3-4: better than most, and your failures cluster in one spot. Everything you failed can only be done from inside the page.

5-6: either you already run security in the browser, or the grading was generous. There’s a clean way to find out.


Turn the score into evidence

DefensX installs through your RMM in minutes, runs beside your current stack without conflict, and starts in watch-only mode: no blocking, no user impact. Thirty days on one tenant, then read what only the browser saw. That report is your real score.

Book a 20-minute demo and we’ll set it up same day, starting with your own technicians, because card six was about you.


Ready to enhance your data security strategy?

Contact DefensX today to learn how AI-powered web DLP can protect your business!

Contact Us