Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB Cyber Brief: remote access and SaaS supplier risk, plus “fake code” malware traps

What small and medium-sized businesses should look out for today.

High Tuesday 21 July 2026, 10:38 UK time
Today’s look-out: Supplier & remote-access compromise leading to business disruption and follow-on scams

What to look out for today

  • Remote access/VPN appliances being targeted (SonicWall SMA1000) with zero-day exploitation reported.
  • Business SaaS/platform risk: reported in-the-wild exploitation affecting ServiceNow’s AI Platform.
  • HR/ERP breach ripple effects: a major firm disclosed a breach tied to an Oracle E‑Business Suite HR use case—expect “HR/payroll” themed scams that borrow credibility from big-name incidents.
  • “Fake code” and developer-tool malware: thousands of malicious GitHub repositories posing as legitimate projects (including AI/MCP-related repos) to deliver malware.
  • Ransomware themes expanding: ransomware activity reported targeting AI-related data stores (relevant if you run AI tooling or store model/data assets internally).

Why this matters to smaller businesses

SMEs often depend on a small number of critical systems: remote access for staff/IT support, a handful of SaaS platforms (IT tickets, HR, finance), and external code/tools used by developers or IT. When attackers compromise any of these, the impact can be immediate: account takeovers, unauthorised access, ransomware disruption, and convincing follow-on phishing aimed at finance and HR teams.

Warning signs

  • Unexpected MFA prompts or users reporting “approval requests” they didn’t initiate (especially for admin/IT accounts).
  • New or unusual logins to SaaS admin portals (odd times, unfamiliar locations, new devices).
  • Remote access behaving oddly: unexplained VPN drops, new admin users, config changes, or support accounts you don’t recognise.
  • HR/payroll themed emails referencing a “supplier breach”, “employee data verification”, “updated payroll details”, or “urgent compliance checks”.
  • Developer/IT staff downloading “helpful tools” or “AI/MCP servers” from new GitHub repos, especially if delivered as ZIPs or forks with very new/low-activity profiles.

How attackers may exploit the situation

  • Edge device compromise: targeting remote access appliances to gain a foothold, then moving into email and file systems for data theft or ransomware.
  • SaaS platform exploitation: using a supplier/platform weakness to run code or access data, then abusing trusted integrations, API tokens, or automated workflows.
  • “Credibility piggybacking” scams: using news of a big-brand breach to pressure your team into clicking links, sharing employee data, or changing payroll/bank details.
  • Code supply-chain traps: pushing malware via convincing open-source repos and lookalike developer profiles, targeting IT/admin machines where credentials and access are richest.

What to do today

  • Confirm your remote access inventory: list who has VPN/admin access, which appliance/model you use, and who supports it (internal vs MSP).
  • Review admin access to key SaaS (ITSM, HR, finance): remove old accounts, enforce MFA, and reduce the number of admins.
  • Set a “payment/payroll change” control: no bank detail changes via email alone; require a call-back to a known number (from your records, not the email).
  • Send a 2-minute staff note to finance/HR/office staff: “expect breach-themed emails; don’t click; verify via known channels.”
  • For dev/IT teams: only use approved repositories/tools; be cautious with new repos, ZIP downloads, and “AI tooling” projects with thin history.

Ask your IT provider

  • Do we use SonicWall SMA1000 anywhere (including for legacy/backup remote access)? If yes, what’s our current exposure and mitigation plan?
  • Are we a ServiceNow customer, and do we use any AI Platform features? What monitoring is in place for unusual admin activity?
  • What alerting do we have for: new admin users, new OAuth/app integrations, mailbox forwarding rules, and suspicious sign-ins?
  • What is our rapid isolation plan if a remote access device or SaaS admin account is suspected compromised (who does what in the first hour)?
  • Do we have an approved software/repo policy for IT and developers (and a way to block or review unapproved downloads)?

Patch watch - only one short paragraph, and only if relevant

If you (or your MSP) manage edge devices and core business platforms, today is a good day to confirm you have an urgent patch-and-mitigation process for internet-facing systems (notably remote access appliances and major SaaS platforms) when in-the-wild exploitation is reported. Ask for confirmation of actions taken and any compensating controls if patching isn’t immediate.

One action today

Message finance and HR staff today: “No payroll or supplier bank detail changes via email—always verify using a call-back to a known number from our records.”

Related Actions On Cyber resource

Actions On Cyber checklist: Payment change & invoice fraud call-back procedure (finance/ops quick controls)

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.