Capstone Technologies Group LLC Capstone Technologies Group LLC
  • Home
  • Services
    • Managed IT Solutions
    • Cybersecurity Services
    • Data Protection & Recovery
    • VoIP Solutions
    • Website Solutions
  • Industry Solutions
    • Legal IT Solutions
    • Medical IT Solutions
    • Financial IT Solutions
    • SMB IT Solutions
    • Non Profit IT Solutions
  • Resources
    • Blog
    • White Papers
    • Threat Intelligence Center
  • About Us
    • Who We Are
    • Client Testimonials
    • Case Studies
  • Threat Intelligence Center
  • Pricing

Expert Solutions at Your Fingertips: Call (937)319-1211

Facebook
LinkedIn
Mastodon
Bluesky
Capstone Technologies Group LLC Capstone Technologies Group LLC
  • Home
  • Services
    • Managed IT Solutions
    • Cybersecurity Services
    • Data Protection & Recovery
    • VoIP Solutions
    • Website Solutions
  • Industry Solutions
    • Legal IT Solutions
    • Medical IT Solutions
    • Financial IT Solutions
    • SMB IT Solutions
    • Non Profit IT Solutions
  • Resources
    • Blog
    • White Papers
    • Threat Intelligence Center
  • About Us
    • Who We Are
    • Client Testimonials
    • Case Studies
  • Threat Intelligence Center
  • Pricing

Contact Us

When Your Own Microsoft 365 Becomes the Attacker's Channel

A malware family called TWINLOOT routes its command-and-control through Microsoft's own cloud — SharePoint, Teams, and the Graph API — so the domain blocklists and web filters built to catch an intrusion never see it, and it leaves no trace in your Microsoft 365 sign-in logs. Here's what that means for a professional-services firm, and the one question worth putting to your IT team.

Read more: When Your Own Microsoft 365 Becomes the Attacker's Channel

Adlumin SOC dashboard for Capstone's managed environment showing zero at-risk systems and a network health score of 82

Half of 2025's Attacks Never Touched the Endpoint

Adlumin SOC dashboard for Capstone's managed environment showing zero at-risk systems and a network health score of 82

Blog • August 11, 2026

N-able's 2026 State of the SOC Report, built on data from the Adlumin SOC platform, lands on one finding every firm running endpoint protection should stop and consider: 50% of the attacks observed in 2025 bypassed endpoint controls entirely.

If your security strategy starts and ends with antivirus or EDR, that number means half of last year's attacks would have been invisible to you.

Key Insight

Half of 2025's attacks bypassed endpoint controls entirely — they moved through the network, perimeter, and identity layers that endpoint tools don't watch. — N-able 2026 State of the SOC Report

Here's why. Endpoint tools watch the endpoint — malware execution, suspicious processes, credential theft from memory. They're good at it. But a large share of modern attacks never runs anything on an endpoint until the very end. Network reconnaissance, lateral movement between systems, firewall and VPN exploitation, offline password cracking, identity attacks in the cloud — none of it generates an endpoint alert. By the time something does, the attacker has usually been inside for hours.

The Adlumin data puts numbers on it. Across 2025, the network and perimeter layers caught 137,187 threats that endpoint-only monitoring would have missed. Many weren't minor — they were the opening stages of attacks that would have become full breaches without visibility at those layers.

The same report explains why response speed matters as much as visibility. When a VPN login from an unusual location, internal SMB scanning, and a PowerShell execution show up separately, each looks ambiguous on its own. Correlated across layers, they read as an active compromise.

We watched a version of this play out in one of our own managed environments last Thanksgiving. A client traveled out of state for the holiday, logged in to get some work done, and was immediately flagged for signing in outside their normal area. SentinelOne on the laptop saw nothing wrong — because nothing on the laptop was wrong. The signal only existed in the layers around it. Adlumin correlated the sign-in with what our managed SonicWall appliance was seeing, and the SOAR weighed the context: a company laptop, a clean authentication, the VPN's two-factor prompt answered correctly. No aggravating circumstances, so it stopped at notifying me. Other cases have gone the other way — clients who left the country without telling us were automatically isolated from the network, applications, and resources until we confirmed it was really them. Same detection either way; the response matched the risk.

This is what the Capstone Threat Intelligence Center tracks: daily analysis of active threats — credential campaigns, perimeter exploits, the techniques showing up most often in professional services — and what each one means for the firms we manage.

Brian Sammons, Founder of Capstone Technologies Group

Brian Sammons has managed IT environments for Ohio professional service firms since 2002. Capstone Technologies Group provides managed security services including firewall management, endpoint protection, backup, and 24/7 threat monitoring for medical practices, law firms, and accounting firms across the Dayton, Columbus, Cincinnati, and Springfield markets.

Questions about what your current tools can and can't see? Schedule 15 minutes and I'll walk you through it.

See What We're Tracking
Capstone Technologies Group logo

Capstone Launches Threat Intelligence Center

Announcement • June 01, 2026

Brian here. We've started publishing daily threat intelligence analysis at the Capstone Threat Intelligence Center.

The Threat Intelligence Center tracks active threats targeting the types of environments we manage — credential theft campaigns against Microsoft 365, malware delivery methods, phishing techniques, vulnerability disclosures, and the attack patterns that show up most often in professional services firms.

We monitor threat feeds throughout the day, score articles by relevance and severity, and publish analysis with context on what each threat means for managed environments. When a credential theft campaign targets Office 365 users — like the Storm-2755 attack we tracked last week that manipulates search results to redirect employee paychecks — the analysis publishes the same day.

Articles post to the Threat Intelligence Center daily and distribute across our social channels. The highest-priority threats get featured on LinkedIn each morning.

Starting this week, I'm also publishing a weekly summary on the blog — the two or three threats from the prior week that matter most for Ohio professional service firms, with context on what we're seeing and what it means for your environment. The first one is up now: SonicWall's 2026 Report Confirms What We See Every Week.

See What We're Tracking
Business computer displaying Windows 10 and Windows 11 upgrade options as October 14 deadline approaches

Windows 10 End of Life: Your Free Security Bridge Explained

Windows 10 support ends October 14, 2025—just two weeks away. Microsoft recently announced extended security updates offering free and affordable options for the first time. With over 400 million Windows 10 PCs still in use and millions unable to upgrade due to strict hardware requirements, understanding your options is critical. Here's everything you need to know to protect your business systems and make informed decisions before the deadline.

Read more: Windows 10 End of Life: Your Free Security Bridge Explained

AI-Driven BEC Attacks: A New Cybersecurity Challenge

AI-enhanced Business Email Compromise (BEC) attacks are bypassing traditional security measures, posing immediate threats to organizations. Swift action is essential to prevent financial and reputational damage.

Read more: AI-Driven BEC Attacks: A New Cybersecurity Challenge

More Articles …

  1. Fast Flux DNS Threats: Why Capstone Clients Were Protected Before NSA Warnings
  2. Compare Passkeys, Passwords, MFA, SSO, Windows Hello, and NIST Guidelines
  3. Capstone Technologies Group Joins Forces with SonicWall as SecureFirst MSSP Partners
  4. How We Helped Secure Ohio's 2018 Election Infrastructure

Subcategories

Weekly Briefing

  • 1
  • 2
  • 3

Page 1 of 3

Intro Image
Threat Intelligence Center

19 Malicious Chrome and Edge Extensions Steal Wallet Data and Drain Crypto

Researchers identified 19 Chrome and Edge extensions containing wallet-stealing and...
28 Aug, 2026
Intro Image
Threat Intelligence Center

AI-Driven Fraud Erodes Identity Verification and Makes Deception Harder to Spot

AI has shifted fraud from a detection problem to an identity problem. Synthetic voice, video, and...
20 Aug, 2026
Intro Image
Threat Intelligence Center

AI-Enabled Device Code Phishing Campaign Abuses Device Code Sign-In Flow

Device code authentication was built for input-constrained devices, and attackers have learned to...
15 Aug, 2026
Intro Image
Threat Intelligence Center

Akira Ransomware Reboots Windows Into Safe Mode to Knock EDR Offline

The Akira ransomware group is abusing a legitimate Windows feature to neutralize endpoint...
14 Aug, 2026
Intro Image
Threat Intelligence Center

Apollo Discloses Data Breach as Attack Wave Hits Financial Sector Firms

Apollo has disclosed a data breach stemming from an ongoing wave of attacks directed at the...
22 Aug, 2026
Intro Image
Threat Intelligence Center

Attackers Abuse AnyDesk and ScreenConnect RMM Tools for Remote Access

Remote monitoring and management software is trusted by design, and that trust is what attackers...
28 Aug, 2026
Facebook
LinkedIn
Mastodon
Bluesky
Schedule Your Assessment!

About Us

  • Privacy Policy
  • Code of Ethics
  • Sitemap
Mastodon

Areas We Serve

  • Managed IT Services Springfield, Ohio
  • Managed IT Services Dayton, Ohio
  • Managed IT Services Columbus, Ohio
Address: 2071 N Bechtle Ave, Box 143, Springfield, OH 45504-1583
Phone: (937) 319-1211
Email: [email protected]
SUBSCRIBE To Our Newsletter

Get the latest news!

Copyright © 2026 Capstone Technologies Group. All Rights Reserved.
Customized & Hosted by Capstone Technologies Group Great Hosting