This Week in Security: September 1, 2026

ArisGate Security Team

•
September 1, 2026
ARISGATE SECURITY BRIEF · PHISHING & SOCIAL ENGINEERING
The new phishing attacks don't need your password at all.
ClickFix, fake browser windows, and rogue app permissions are replacing the login page as the way in.

New research describes three phishing techniques now in active use that skip the password entirely:

  • ClickFix, which tricks users into running malicious commands themselves.
  • Fake browser login windows that mimic a real sign-in prompt.
  • OAuth consent phishing, where a user simply approves permissions for a malicious app.

Why this matters for your firm

These techniques target the exact moment of trust staff rely on every day. A single approved consent prompt can hand an attacker standing access to email, calendar, and files, without a password ever changing hands, and without triggering the password monitoring most firms rely on.

Florida Bar Rule 4-1.6 and Recommendation 25-1

Rule 4-1.6 requires reasonable efforts to prevent unauthorized access to client information, and a training gap that lets one of these techniques through is difficult to defend as reasonable after the fact. Recommendation 25-1's documented assessment expectation reinforces the same point.

What to do this week

  1. Train staff to slow down on any unexpected sign-in or permission prompt.
  2. Audit which third party apps currently have access to your firm's email and files.
  3. Revoke anything unfamiliar.

How ArisGate helps

ArisGate helps solo and small Florida law firms close this exact gap. Schedule a free security audit today.

Schedule a Call