Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB cyber brief: supply‑chain risk, SaaS credential exposure, and ServiceNow exploitation

What small and medium-sized businesses should look out for today.

High Monday 20 July 2026, 11:20 UK time
Today’s look-out: Supplier/SaaS incident scams and credential theft, plus supply‑chain contamination

What to look out for today

  • Software supply‑chain risk for developers: malicious RubyGems packages reported (developers and CI/CD environments most at risk).
  • Supplier/SaaS credential exposure risk: Hugging Face reported a breach affecting internal datasets and some credentials.
  • ServiceNow risk: reporting says a critical ServiceNow issue is now being exploited in attacks (important if you use ServiceNow directly or via an IT provider).

Why this matters to smaller businesses

SMEs often rely on third‑party platforms (SaaS) and outsourced IT. When a supplier is breached or a widely used platform is actively exploited, attackers commonly follow up with phishing, password‑spraying, and “we need you to re‑authorise” style messages. Separately, malicious open‑source packages can compromise developer laptops and build systems, which can then leak credentials and spread into business services.

Warning signs

  • Unexpected password reset or MFA reset prompts for developer tools, AI platforms, or ticketing/workflow systems.
  • Emails or calls claiming to be from a supplier’s “security team” asking you to log in via a new link or share recovery codes.
  • New or unusual API tokens/keys, integrations, or “service accounts” appearing in admin consoles.
  • Developers reporting odd behaviour after installing/updating dependencies (sudden credential prompts, new background processes, unexpected network activity).
  • Service desk/ticketing anomalies: unexpected admin actions, new workflows, or changes you can’t explain.

How attackers may exploit the situation

  • Incident-themed phishing: using news of a supplier breach to trick staff into logging into lookalike portals.
  • Credential reuse/testing: if any credentials are exposed anywhere, attackers will try them across email, Microsoft 365/Google Workspace, and line-of-business tools.
  • Supply-chain foothold: malicious packages installed by developers can be used to steal tokens and credentials, then pivot into cloud services or shared repositories.
  • Platform exploitation: where a platform is reported as actively exploited (e.g., ServiceNow), attackers may target organisations that haven’t applied mitigations or are running vulnerable configurations.

What to do today

  • Send a short internal warning to staff: don’t trust supplier “security alerts” received by email/DM; only use known bookmarks and official channels.
  • Check admin logs for your key SaaS tools (email, file sharing, ticketing/workflow, finance) for new tokens, integrations, or unusual logins.
  • Harden developer accounts: confirm MFA is enabled; review who has access to production secrets and CI/CD credentials.
  • Credential hygiene: if you use Hugging Face (or connected tools), consider rotating relevant tokens/keys and reviewing access.
  • ServiceNow users: ask your provider/vendor what they’ve done in response to reports of active exploitation.

Ask your IT provider

  • Do we use ServiceNow (directly or indirectly), and what actions have you taken given reports of active exploitation?
  • Which of our systems have API tokens/service accounts that could be impacted by supplier credential exposure, and how quickly can we rotate them?
  • What monitoring is in place for new integrations, OAuth grants, mailbox rules, or suspicious admin changes?
  • For developer environments: do we have controls for dependency risk (e.g., approval processes, monitoring, or alerts for unusual package behaviour)?

Patch watch - only one short paragraph, and only if relevant

There is reporting of active exploitation of a critical issue in ServiceNow, and separate reporting of a Windows out-of-band update to address shutdowns on some Dell PCs after July 2026 Windows 11 updates. Treat these as operational priorities: confirm your IT provider has reviewed ServiceNow exposure and that endpoint update rings include a plan for affected Dell devices if you’ve seen unexpected shutdowns.

One action today

Send a same-day staff note: ‘Ignore supplier “security incident” links—use bookmarks/known portals only, and report any MFA reset or login prompt immediately.’

Related Actions On Cyber resource

Actions On Cyber: Supplier incident scam / ‘breach-themed phishing’ checklist (how to verify supplier messages and safely rotate passwords/tokens)

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.