Skip to main content
Plenty of phish in the sea
To:Brew Readers
IT Brew // Morning Brew // Update
Hyphen havoc!

Hey, Tuesday! AI regulations might not look both ways before crossing after this year’s Paris AI summit, where the Trump administration pushed for speedier development rather than safety.

In today’s edition:

Dot con

DOGE or bust

Heroic hosting

—Billy Hurley, Eoin Higgins, Brianna Monsanto, Patrick Lucas Austin

CYBERSECURITY

Phishing hook going through a mouse pointer arrow

Francis Scialabba

To a phisher, one tiny hyphen can make a big mark.

SANS Technology Institute Dean of Research Johannes Ullrich alerted users to a “clever” phishing tactic that uses a URL containing a “com-” domain prefix. With that tiny, easy-to-miss hyphen, threat actors can disguise a malicious destination.

Ullrich noted on the SANS site that the phishing tactic was placed into fraudulent messages alerting a user of unpaid tolls. (The FBI warned the public of toll trolls in April 2024, when there were over 2,000 complaints of attacks using fake text messages.)

How the “.com-” tactic works. A legitimate site involving Florida’s toll system (SunPass) would involve a forward slash and look something like: “sunpass.com/tolls.”

In instances discovered by Ullrich and shared on the SANS site, the phisher registers for and receives a domain that begins with “com-,” followed by seemingly random letters, then ending with a top-level domain, like .info, .top, .xyz, and even .com.

To a reader, the phishy URL appears as something like: “sunpass.com-[random letters].top”—a tricky difference to notice when you’re quickly looking on a tiny phone screen and it appears that you owe toll money.

Read the rest here.BH

Presented By ThreatLocker

CYBERSECURITY

photo of devices showing the DOGE X account and Elon Musk's X account

Nurphoto/Getty Images

So insecure, much danger.

Elon Musk’s government reform efforts may be having a deleterious effect on national security as the billionaire’s Department of Government Efficiency is leading to anger among federal rank and file and opening systems up to attack.

For Musk’s White House-appointed organization, known by its acronym DOGE, the federal government offers a rich and juicy target for the kind of slash-and-burn tactics that Silicon Valley is known for. Musk, whose purchase of Twitter in 2022 was followed by massive job cuts and exhortations to remaining staff to be “hardcore,” appears to be taking a similar tack across the US government.

Crisis management. Rex Booth, SailPoint CISO, told IT Brew that the public should view DOGE carefully, but rationally. A former White House advisor who helped develop the Office of the National Cyber Director, Booth is no stranger to the ups and downs of the federal government.

“There are things to be concerned about, and there are things that are less dire than they may appear to be,” Booth said. “If everything’s a crisis, nothing’s a crisis.”

Read more here.EH

CLOUD

A three-dimensional image of a cloud overlaid on computer chips.

Olemedia/Getty Images

The Internet Infrastructure Coalition (i2Coalition), an organization known for uniting the unsung heroes that support the backbone of the internet, is circling in on its advocacy for one specific part of the industry it thinks needs a little more TLC: the hosting industry.

Earlier this month, i2Coalition debuted its Secure Hosting Alliance (SHA), an initiative that is on the hunt to create a more “ethical” web-hosting industry. David Snead, director of the newly formed alliance and co-founder of i2Coalition, told IT Brew that the impetus for the formation of the group came after the coalition observed a direct need to address abuse and trust issues specific to the hosting industry.

“The hosting industry is a bit different than a lot of other internet infrastructure participants because there are so many different players and the range of participants is so great that…it’s kind of a good opportunity to have a group that focuses on particular issues,” Snead said.

On the agenda. The SHA currently comprises 23 founding members, including Cloudflare, DreamHost, and GoDaddy. Together, the members will work to address abuse—which Snead defines as “actionable criminal activity” such as fraud—on their platforms and create proper “mechanisms” for entities to report suspected misconduct.

Keep reading here.BM

PATCH NOTES

Picture of data with "Clean Me" written on it + bottle of cleaner in front of it, Patch Notes

Francis Scialabba

Today’s top IT reads.

Stat: 101.7 million. That’s the number of Reddit’s daily active unique visitors during Q4 2024. (CNET)

Quote: “The acceleration of global electricity demand highlights the significant changes taking place in energy systems around the world and the approach of a new Age of Electricity.”—Keisuke Sadamori, International Energy Agency director of energy markets and security, on the increasing demand for energy for data centers (The Verge)

Read: OpenAI is working to stop Elon Musk from taking over the company. (Ars Technica)

Safe and sound: ThreatLocker created this e-book to share a comprehensive roadmap for strengthening your Microsoft 365 cloud environment. Learn how to combat threats to cloud services and online accounts 24/7/365.*

*A message from our sponsor.

JOBS

Ready to move your career forward without endless scrolling? CollabWORK connects you with jobs in the communities you’re already part of—like IT Brew. Experience community-powered hiring and discover the opportunities that suit you best. Click this link to browse jobs hand-selected for IT Brew!

SHARE THE BREW

Share IT Brew with your coworkers, acquire free Brew swag, and then make new friends as a result of your fresh Brew swag.

We’re saying we’ll give you free stuff and more friends if you share a link. One link.

Your referral count: 2

Click to Share

Or copy & paste your referral link to others:
itbrew.com/r/?kid=9ec4d467

         
ADVERTISE // CAREERS // SHOP // FAQ

Update your email preferences or unsubscribe here.
View our privacy policy here.

Copyright © 2025 Morning Brew Inc. All rights reserved.
22 W 19th St, 4th Floor, New York, NY 10011

Top insights for IT pros

From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.

A mobile phone scrolling a newsletter issue of IT Brew