This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Apple just secretly added Starlink satellite support to iPhones through iOS 18.3.

One of the biggest potential winners? Mode Mobile.

Mode’s EarnPhone already reaches 490M+ users that have earned over $1B, and that’s before global satellite coverage. With SpaceX eliminating "dead zones," Mode's earning technology can now reach billions more in unbanked and rural populations worldwide.

Their global expansion is perfectly timed, and investors like you still have a chance to invest in their pre-IPO offering at $0.52/share.

With their recent 32,481% revenue growth and newly reserved Nasdaq ticker, Mode is one step closer to a potential IPO.

Please read the offering circular and related risks at invest.modemobile.com. This is a paid advertisement for Mode Mobile’s Regulation A+ Offering.

Mode Mobile recently received their ticker reservation with Nasdaq ($MODE), indicating an intent to IPO in the next 24 months. An intent to IPO is no guarantee that an actual IPO will occur.

The Deloitte rankings are based on submitted applications and public company database research, with winners selected based on their fiscal-year revenue growth percentage over a three-year period.

Over the last several days, the threat pattern has clustered around management planes, engineering data platforms, public Wi-Fi gateways, healthcare data stores, browser extensions, and enterprise email systems.

That is not random. These are leverage points.

A firewall management bug can rewrite security policy. A PLM compromise can expose product designs. A hacked hotel Wi-Fi gateway can steal Microsoft 365 access. A browser extension can silently read private chats. A Zimbra exploit can pull mail, passwords, and 2FA tokens.

📈 Risk Forecast – The Week Ahead 📉

Trend (Macro)

Likelihood

Direction

Signal for the Week

Firewall and security management plane exploitation

84%

🔺 Rising

Check Point SmartConsole auth bypass gives attackers admin-level control if management exposure is weak.

Engineering and PLM data theft extortion

82%

🔺 Rising

Clop targeting Windchill and FlexPLM puts design files, product data, and supplier workflows at risk.

Public Wi-Fi credential harvesting

78%

🔺 Rising

Compromised hotel and conference Wi-Fi gateways are being used to steal Microsoft 365 access.

Healthcare-scale data exposure

76%

🔺 Rising

DentaQuest notifications show dental and health data remains high-value fraud and phishing fuel.

Browser extension data exposure

72%

🔺 Rising

Adobe Acrobat’s Chrome extension flaw shows trusted extensions can become silent data readers.

Email platform espionage

74%

🔺 Rising

Laundry Bear’s Zimbra campaign reinforces that email platforms remain state-level collection targets.

🔎 Key Watchlist Items 🔍
  1. Check Point SmartConsole auth bypass exploited in the wild — CVE-2026-16232 lets an unauthenticated attacker obtain a login token and authenticate with full administrative privileges against affected Check Point management systems, making SmartConsole takeover a firewall-management emergency, not a normal change ticket.

  2. Clop targets PTC Windchill and FlexPLM for data theft — Clop affiliates are targeting internet-exposed PLM systems used across manufacturing, automotive, aerospace, and retail, making Windchill extortion a product-design, supplier, and intellectual-property exposure issue.

  3. Hacked public Wi-Fi gateways harvest Microsoft 365 credentials — ReliaQuest reported attackers compromising hotel and conference Wi-Fi gateways, poisoning DNS, and redirecting corporate travelers into Microsoft 365 credential theft flows, making hospitality Wi-Fi a travel-security and executive-account risk.

  4. DentaQuest breach may impact more than 23 million people — SecurityWeek reported that DentaQuest is notifying millions after attackers accessed its network in May and potentially stole personal and dental health information, making dental-health data a long-tail phishing, fraud, and regulatory problem.

  5. Adobe Acrobat Chrome extension exposed WhatsApp Web data — Malwarebytes reported that the HermeticReader flaw in Adobe’s Acrobat Chrome extension could allow a malicious website to silently access WhatsApp Web chats on affected browsers, making extension trust a browser-governance problem with real privacy impact.

  6. Russian Laundry Bear campaign exploited Zimbra for email theft — Reuters reported that U.S. and allied governments accused Russian-backed hackers of using a Zimbra weakness to steal emails without traditional social engineering, making Zimbra mail theft a serious risk for organizations still running vulnerable or poorly monitored webmail.

What is an EOR—and why are companies using it?

Opening entities in every country can be slow, expensive, and hard to scale.

That's why more companies are using EOR to hire globally faster.

See how Oyster helps teams hire, pay, and support talent in 180+ countries while staying compliant along the way.

📊 Emerging Patterns 📊

Management planes are still Tier 0 in disguise. A firewall management compromise can change policy, create blind spots, and make the attacker look like the admin.

Engineering systems are becoming extortion targets. PLM platforms hold product designs, supplier data, and operational timelines. That is not just IT data. That is business leverage.

Travel networks are identity attack surfaces. Hotel and conference Wi-Fi can become a credential trap before the user ever clicks a phishing email.

Healthcare data keeps creating long-tail exposure. Dental and medical records give attackers better identity-fraud material than a random password dump.

Browser extensions deserve enterprise governance. Trusted brand does not equal safe behavior, especially when extensions can read or modify web content.

Email remains a state-level collection target. If attackers can silently read mailboxes, steal 2FA material, and harvest directories, they do not need noisy malware.

⏰ Call to Action ⏰

Check Point management hardening: Apply the SmartConsole hotfixes, restrict management servers to trusted clients, review administrator logins, and validate no unauthorized policy or configuration changes occurred.

PLM exposure review: Identify internet-facing Windchill and FlexPLM instances, restrict access, patch aggressively, and monitor for mass file enumeration, staging, compression, and unusual outbound transfers.

Travel identity controls: Warn executives and frequent travelers about hotel and conference Wi-Fi risk, require VPN before SaaS access where feasible, enforce phishing-resistant MFA, and monitor device-code flow abuse.

Healthcare data response: Prepare phishing guidance for affected populations, validate data-access logging, review third-party healthcare integrations, and confirm breach-notification and legal workflows are ready.

Browser extension governance: Force-update or remove vulnerable Adobe Acrobat Chrome extensions, review enterprise extension allowlists, and restrict extensions with broad content-read permissions.

Zimbra containment: Confirm Zimbra patch status, audit mailbox access patterns, rotate exposed credentials where needed, and hunt for abnormal exports of mail, directories, 2FA tokens, and application passwords.

⚡ Monday Motivation ⚡

The good news: the U.S. announced a new visa restriction policy targeting people responsible for or complicit in cybercrime and cyber-enabled scams, including some immediate family members. That does not magically end cybercrime, but it does make the lifestyle less comfortable. Criminal crews love distance, anonymity, and safe travel. Policy pressure takes those comforts away one paperwork stack at a time.

That matters.

Every arrest, sanction, seizure, visa restriction, and infrastructure disruption raises the cost of doing business for criminals.

Keep going. The bad guys are not invincible. They are just persistent.

This week’s lesson: Attackers are not just stealing access. They are stealing trust: firewall trust, PLM trust, Wi-Fi trust, browser trust, healthcare trust, and email trust. Verify the trust, or prepare the incident statement.

J.W.

(P.S. Forward to your CISO / Add to Board Briefing.)

PRDs by voice. Bug reports by voice. Ship faster.

Dictate acceptance criteria and reproductions inside Cursor or Warp. Wispr Flow auto-tags file names, preserves syntax, and gives you paste-ready text in seconds. 4x faster than typing.

Keep reading