Two threat trends are reshaping the risk landscape for small and midsize businesses this year: AI-generated phishing at industrial scale, and attackers slipping malicious code into the open-source software your IT systems quietly depend on. Neither requires a sophisticated nation-state budget to pull off anymore - and both are already hitting organizations far smaller than the household names making headlines.
Security researchers tracking live phishing activity have reported that roughly 90% of phishing kits circulating today were built with the help of AI tools, and that criminal groups are now running dozens of "device code phishing" kits - tooling that didn't meaningfully exist a year ago. These kits are built to steal login sessions and authentication tokens directly, letting attackers bypass passwords and, in some cases, multifactor authentication prompts entirely.
A related technique called "ClickFix" has become one of the most common ways victims land on these fake pages: users are lured in through booby-trapped search engine results - researchers estimate roughly 4 out of 5 ClickFix attacks start with a simple web search - then tricked into copying and pasting a malicious command themselves, often under the guise of "fixing" a browser error or verifying they are human. Because the victim types the command, many antivirus and email filtering tools never get a chance to flag it. Adding to the pressure, these phishing domains are now rotated out after an average of just two days online, making traditional blocklists far less effective than they used to be.
The second trend is quieter but arguably more dangerous: attacks on the software supply chain itself. Over the past year, a loosely organized cybercrime community has run one of the largest and longest-running software supply-chain campaigns on record, built around a self-propagating worm nicknamed "Shai-Hulud." The group's method: compromise the credentials of developers who maintain popular open-source packages on platforms like npm and GitHub, then quietly insert malicious code into those packages. Because thousands of other applications and tools automatically pull in that code as a dependency, the infection spreads outward on its own - from one popular library into the next project that uses it, and the next.
The scale has been significant. Security researchers have linked this campaign to the compromise of thousands of code repositories and the theft of cloud credentials and other secrets from thousands of organizations, including widely used AI infrastructure tools. For a small business, the uncomfortable takeaway is this: you don't have to be the target to be a victim. If any vendor, web developer, or internal tool you rely on pulled in a tainted open-source package, the compromise can arrive through a routine software update - no phishing email required.
It's tempting to assume these stories are "big company problems." They aren't. Smaller organizations typically have thinner security staffing, fewer monitoring tools, and less visibility into what their software vendors and web platforms are built on - which makes them easier, not harder, targets. A single stolen session token from an AI-crafted phishing page, or one compromised dependency buried in a website plugin or line-of-business app, can give an attacker the foothold they need to reach email, financial systems, or customer data.
Move beyond basic MFA. Session-token theft is specifically designed to work around one-time codes. Where possible, use phishing-resistant authentication (such as hardware security keys or passkeys) for email, banking, and admin accounts.
Train your team on ClickFix-style lures. The single most important habit to teach: never copy and paste a command into a terminal or "Run" dialog because a website told you to, even if it claims to be fixing an error or verifying you're human.
Ask your vendors the hard question. Ask your website developer, software vendors, and IT partner how they track and patch the open-source components inside the tools you use, and how quickly they respond when a popular package is found to be compromised.
Keep rapid patching and monitoring in place. Because malicious updates and phishing domains both move fast - some phishing pages exist for only a couple of days - detection and response speed matters as much as prevention.
Maintain tested, offline backups. Whether the entry point is a phishing page or a tainted software update, a verified backup remains the most reliable way to recover without paying a ransom.
Lumos Technology Services helps small and midsize businesses stay ahead of these fast-moving threats. Our team provides proactive monitoring, phishing-resistant authentication rollouts, vendor and software risk reviews, and 24/7 threat detection so you don't find out about a compromise the hard way. If you're not sure how exposed your business is to AI-driven phishing or a compromised software dependency, reach out - a quick risk assessment is the fastest way to find out.
Note: The incident and statistics referenced above are drawn from public reporting by security researchers (including Push Security and KrebsOnSecurity) and are accurate as of this post's publish date; we encourage readers to follow primary sources for the latest updates as these campaigns continue to evolve.
Banner photo: U.S. Army National Guard photo by Staff Sgt. Renee Seruntine, via the National Guard's Flickr stream / Wikimedia Commons, licensed under CC BY 2.0. No endorsement by the U.S. National Guard is implied.