What to look out for today
Two themes to keep on your radar this weekend:
- Credential-stealing malware is surging (browser-saved passwords, session tokens and sensitive files). This can lead to email, Microsoft 365 and finance system takeovers without “breaking in” the traditional way.
- Microsoft SharePoint Server exploitation is being treated as actively exploited by US authorities. If you (or your IT provider) run on-prem SharePoint, this is a priority check because it can be a foothold for wider compromise and disruption.
Why this matters to smaller businesses
- Session tokens are as valuable as passwords. If stolen, attackers may access cloud apps even when you have multi-factor authentication, depending on how the session is handled.
- Email compromise drives fraud. Once inside mailboxes, criminals commonly move to invoice interception, supplier payment diversion, and payroll/HR data theft.
- Supplier exposure is real. Even if you don’t run SharePoint yourself, your IT provider, marketing agency, or larger customers might—breaches can lead to convincing “shared document” lures and malicious file links.
Warning signs
- Staff report being unexpectedly signed out of Microsoft 365/Google/CRM, or repeated prompts to re-authenticate.
- New inbox rules (e.g., auto-forwarding, moving messages to RSS/Archive), or “sent items” that staff don’t recognise.
- Unusual login alerts: new locations/devices, “impossible travel”, or logins outside business hours.
- Unexpected requests to “review a SharePoint document” or re-enter credentials to view files.
- AV/EDR alerts mentioning password dumping, browser credential access, or suspicious access to user profile/browser data.
How attackers may exploit the situation
- Steal browser-stored credentials and tokens to take over email and cloud apps, then pivot into finance and admin systems.
- Use hijacked accounts to send believable internal phishing (“new bank details”, “urgent invoice”, “DocuSign/SharePoint link”).
- Target on-prem collaboration platforms (e.g., SharePoint Server) as an entry point, then spread to file shares and backups, increasing ransomware/disruption risk.
What to do today
- Send a short staff note: don’t open unexpected “shared file” links; don’t re-enter passwords from an emailed link; report odd sign-in prompts immediately.
- Check your high-risk accounts: finance mailbox(es), payroll, admin accounts. Look for new forwarding rules, new MFA methods, and recent sign-ins you can’t explain.
- Lock down where you can: ensure MFA is on for email and finance tools; reduce who can approve payments; require call-back verification for any bank detail change.
- Review endpoint hygiene: confirm security software is running and updated on laptops used for banking, payroll, and admin.
Ask your IT provider
- Are we seeing any token/session theft or infostealer indicators across our devices or Microsoft 365 tenant this week?
- Do we have alerting for suspicious inbox rules/auto-forwarding and risky sign-ins on our email platform?
- Do we run on-prem SharePoint Server anywhere (including for a specific department or legacy project)? If yes, what is the current risk assessment and what mitigations/monitoring are in place?
- Which accounts are most privileged (global admin, finance admins) and how are they protected (separate admin accounts, MFA, conditional access)?
Patch watch - only one short paragraph, and only if relevant
If you (or an outsourced IT partner) operate Microsoft SharePoint Server on-prem, treat the current “known exploited” status as a priority operational check. The key question for SMEs isn’t the technical detail—it’s whether you have any exposed/legacy SharePoint servers, whether fixes were applied promptly, and whether logs/alerts are being reviewed for suspicious activity.
One action today
Today, check your finance and admin email accounts for suspicious sign-ins and any new auto-forwarding/inbox rules, and immediately reset credentials/MFA for anything you can’t explain.
Related Actions On Cyber resource
Actions On Cyber checklist: “Payment change & invoice fraud verification process (call-back and approval steps)”
Sources
- Microsoft warns of surge in ACR Stealer attacks on customers (BleepingComputer)
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.