What to look out for today
- Remote access/VPN appliances being targeted (SonicWall SMA1000) with zero-day exploitation reported.
- Business SaaS/platform risk: reported in-the-wild exploitation affecting ServiceNow’s AI Platform.
- HR/ERP breach ripple effects: a major firm disclosed a breach tied to an Oracle E‑Business Suite HR use case—expect “HR/payroll” themed scams that borrow credibility from big-name incidents.
- “Fake code” and developer-tool malware: thousands of malicious GitHub repositories posing as legitimate projects (including AI/MCP-related repos) to deliver malware.
- Ransomware themes expanding: ransomware activity reported targeting AI-related data stores (relevant if you run AI tooling or store model/data assets internally).
Why this matters to smaller businesses
SMEs often depend on a small number of critical systems: remote access for staff/IT support, a handful of SaaS platforms (IT tickets, HR, finance), and external code/tools used by developers or IT. When attackers compromise any of these, the impact can be immediate: account takeovers, unauthorised access, ransomware disruption, and convincing follow-on phishing aimed at finance and HR teams.
Warning signs
- Unexpected MFA prompts or users reporting “approval requests” they didn’t initiate (especially for admin/IT accounts).
- New or unusual logins to SaaS admin portals (odd times, unfamiliar locations, new devices).
- Remote access behaving oddly: unexplained VPN drops, new admin users, config changes, or support accounts you don’t recognise.
- HR/payroll themed emails referencing a “supplier breach”, “employee data verification”, “updated payroll details”, or “urgent compliance checks”.
- Developer/IT staff downloading “helpful tools” or “AI/MCP servers” from new GitHub repos, especially if delivered as ZIPs or forks with very new/low-activity profiles.
How attackers may exploit the situation
- Edge device compromise: targeting remote access appliances to gain a foothold, then moving into email and file systems for data theft or ransomware.
- SaaS platform exploitation: using a supplier/platform weakness to run code or access data, then abusing trusted integrations, API tokens, or automated workflows.
- “Credibility piggybacking” scams: using news of a big-brand breach to pressure your team into clicking links, sharing employee data, or changing payroll/bank details.
- Code supply-chain traps: pushing malware via convincing open-source repos and lookalike developer profiles, targeting IT/admin machines where credentials and access are richest.
What to do today
- Confirm your remote access inventory: list who has VPN/admin access, which appliance/model you use, and who supports it (internal vs MSP).
- Review admin access to key SaaS (ITSM, HR, finance): remove old accounts, enforce MFA, and reduce the number of admins.
- Set a “payment/payroll change” control: no bank detail changes via email alone; require a call-back to a known number (from your records, not the email).
- Send a 2-minute staff note to finance/HR/office staff: “expect breach-themed emails; don’t click; verify via known channels.”
- For dev/IT teams: only use approved repositories/tools; be cautious with new repos, ZIP downloads, and “AI tooling” projects with thin history.
Ask your IT provider
- Do we use SonicWall SMA1000 anywhere (including for legacy/backup remote access)? If yes, what’s our current exposure and mitigation plan?
- Are we a ServiceNow customer, and do we use any AI Platform features? What monitoring is in place for unusual admin activity?
- What alerting do we have for: new admin users, new OAuth/app integrations, mailbox forwarding rules, and suspicious sign-ins?
- What is our rapid isolation plan if a remote access device or SaaS admin account is suspected compromised (who does what in the first hour)?
- Do we have an approved software/repo policy for IT and developers (and a way to block or review unapproved downloads)?
Patch watch - only one short paragraph, and only if relevant
If you (or your MSP) manage edge devices and core business platforms, today is a good day to confirm you have an urgent patch-and-mitigation process for internet-facing systems (notably remote access appliances and major SaaS platforms) when in-the-wild exploitation is reported. Ask for confirmation of actions taken and any compensating controls if patching isn’t immediate.
One action today
Message finance and HR staff today: “No payroll or supplier bank detail changes via email—always verify using a call-back to a known number from our records.”
Related Actions On Cyber resource
Actions On Cyber checklist: Payment change & invoice fraud call-back procedure (finance/ops quick controls)
Sources
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware (BleepingComputer)
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution (The Hacker News)
- Estée Lauder discloses data breach via Oracle E-Business flaw (BleepingComputer)
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware (The Hacker News)
- JadePuffer agentic attacks now target AI model data with ransomware (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.