Chicago IT Support & Cyber Security | Forward Technologies

Chicago-based Forward Technologies delivers IT support and cyber security to businesses in the Chicago area and nationwide.

  • Home
  • Services
    • Outsourced IT Support
    • DMARC Email Security
    • Development
      • Web Development & Facelifts
      • CustomView: Plugin for WordPress
    • Data Recovery Service
    • PPC Marketing Services
    • SEO Services
  • Email Security
    • SPF Basics
    • DKIM Basics
    • DMARC Basics
    • Email Security Consulting
  • Data Recovery Service
  • Blog
  • Contact Us

Hackers Are Now Using Microsoft Teams to Break Into Corporate Networks

May 14, 2026 by Edward Silha

Microsoft Teams Phishing Attacks Target Corporate NetworksFor years, companies drilled one thing into employees’ heads: don’t trust weird emails. Problem is, attackers adapted. Instead of fighting against people’s skepticism around email, they moved to platforms employees already trust without thinking twice about it. One of the biggest targets right now is Microsoft Teams

A threat group called KongTuke has been using Teams chats to get inside corporate networks, and honestly, it’s working disturbingly well. Instead of blasting out phishing emails, they pose as internal IT staff and message employees directly through Teams. Sometimes they’re operating from already-compromised Microsoft 365 accounts. Other times they create fake accounts designed to look close enough to pass a quick glance. Either way, the attack can go from first contact to compromised system in just a few minutes. [Read more…]

Filed Under: Cybersecurity, Tech In General Tagged With: corporate cybersecurity, cybersecurity, enterprise security, initial access brokers, KongTuke, malware, Microsoft 365, Microsoft 365 security, Microsoft Teams, ModeloRAT, phishing, PowerShell attacks, ransomware, social engineering, Teams phishing, Windows security

Malicious CAPTCHA Redirects Turn WordPress Sites into Malware Launchpads

August 28, 2025 by Edward Silha

A sinister campaign known as ShadowCaptcha is using over 100 compromised WordPress sites as unwitting hosts, redirecting visitors to fake CAPTCHA pages. These deceptive pages trigger malware delivery ranging from credential stealers to ransomware and cryptocurrency miners.

Researchers from Israel’s National Digital Agency revealed that ShadowCaptcha merges social engineering with living-off-the-land tactics. Attackers aim to steal credentials, exfiltrate browser information, deploy cryptomining software, or trigger ransomware—depending on the route the victim takes. [Read more…]

Filed Under: Blog, Cybersecurity, WebDev Tagged With: browser exploit, ClickFix attack, compromised WordPress plugins, crypto miners, cybersecurity, cybersecurity news, fake CAPTCHA, Help TDS, HTA payload, info stealers, infostealer, JavaScript injection, malware campaigns, mshta.exe, phishing redirect, ransomware, ShadowCaptcha, web application firewall, WinRing0x64.sys, WooCommerce plugin threat, WooCommerce_inputs, WordPress security, XMRig

Hackers Pose as IT Support to Breach Salesforce, Steal Corporate Data, and Demand Ransom

June 4, 2025 by Edward Silha

Illustration of hacker posing as IT support to access Salesforce dataHackers posing as IT support are targeting employees at large companies to sneak into their Salesforce systems and steal data. They start with a phone call, pretending to help with a routine issue. The real goal? To get the employee to connect to a fake version of Salesforce’s Data Loader tool. Once that happens, the attackers can quietly grab sensitive company data.

Google’s Threat Intelligence Group has been tracking the group behind this, known as UNC6040. Their method depends on trust—posing as helpful support staff and guiding employees through what feels like a normal setup process. Because the tool is something many employees already use, it doesn’t seem suspicious. [Read more…]

Filed Under: Blog, Cybersecurity Tagged With: CRM security, cybersecurity, data breach, data extortion, Google Threat Intelligence Group, Microsoft 365, Mullvad, Okta, phishing, ransomware, Salesforce, ShinyHunters, UNC6040, voice phishing, Workplace

Social Media

  • Facebook
  • GitHub
  • LinkedIn
  • Periscope
  • Twitter

Forward Technologies
747 N LaSalle
STE 500B
Chicago, IL 60654
(312) 715-7806

Copyright © 2026 — Forward Technologies • All rights reserved. • Privacy Policy •