What to look out for today
Three practical SME watch-outs are getting attention today:
- Exchange 2016/2019 update deadline: Microsoft has reiterated security updates stop in October for Exchange 2016/2019 via the ESU programme. If you run your own email server, this is a planning and risk moment.
- WhatsApp Web privacy exposure via a browser add-on: A reported flaw in the Adobe Acrobat Chrome extension could allow websites to access private data rendered in WhatsApp Web.
- AI-assisted development risk: A reported issue in Microsoft’s Azure DevOps MCP server could allow hidden pull request comments to manipulate AI review agents, potentially causing data leakage across projects.
Why this matters to smaller businesses
- Email is a single point of failure: If you host Exchange on-prem, end-of-updates can quickly become a board-level business risk (ransomware entry, account takeover, data theft, and downtime).
- Browser extensions are “shadow IT”: Many teams install PDF and productivity add-ons without security review. If staff use WhatsApp Web for customer conversations, sensitive data could be exposed.
- AI features can amplify mistakes: If developers (or suppliers) use AI agents to review code or pull requests, prompt/agent manipulation can turn a small workflow weakness into a broad information leak.
Warning signs
- Unexpected prompts to “re-authenticate” to email, Microsoft 365, or WhatsApp, especially after an alleged “security update”.
- Staff reporting odd browser behaviour: new tabs opening, unexpected pop-ups, or WhatsApp Web acting strangely after visiting a website.
- Development teams noticing AI review tools posting unusual suggestions, requesting access to unrelated repos/projects, or summarising content that shouldn’t be visible to that tool.
- Any sudden rush message from a supplier/IT provider saying you must “pay today” for an Exchange extension, emergency migration, or “licence renewal”.
How attackers may exploit the situation
- Deadline-driven social engineering: Criminals often piggyback on real vendor announcements (like Exchange deadlines) to send convincing phishing emails posing as Microsoft/your IT provider.
- Data harvesting through common tools: If a browser extension can expose WhatsApp Web content, attackers may try to lure staff onto a webpage that triggers the issue, then reuse any gleaned info for follow-on fraud.
- Supply-chain style leakage via AI agents: If an AI review agent can be influenced by hidden text, a malicious contributor could try to coax it into revealing information from other projects or internal documents it can access.
What to do today
- Confirm whether you run Exchange 2016/2019 anywhere (including at a hosted provider). If yes, set a dated plan for October: migrate, retire, or ensure you understand your support path.
- Reduce browser extension risk: Ask staff to remove unnecessary Chrome extensions. If your business uses WhatsApp Web, be extra strict about which extensions are allowed in work browsers.
- Set rules for AI in development: If you use AI review/coding agents, restrict their permissions to the minimum repos/projects required, and treat any “invisible” or unusual PR content as suspicious.
- Run a quick phishing reminder to finance/admin teams: no payment or bank detail changes based on email alone—always confirm via a known phone number.
Ask your IT provider
- Do we have any Exchange 2016/2019 servers (or dependencies like hybrid connectors)? What is the exact migration/retirement plan and timeline?
- What is our browser extension policy on managed devices, and can you produce a list of installed extensions on work endpoints?
- Do any teams use Azure DevOps with AI agents/automation? What guardrails exist (least-privilege access, logging, approvals) to prevent data leakage across projects?
- How quickly would we detect and respond to email account takeover (alerts, sign-in anomaly monitoring, MFA enforcement)?
Patch watch - only one short paragraph, and only if relevant
If your organisation uses the Adobe Acrobat Chrome extension or relies on on-prem Exchange 2016/2019, treat today as a prompt to check your update and lifecycle status with your IT support. The key SME risk isn’t technical detail—it’s leaving widely used tools unreviewed or running email infrastructure close to (or past) its support deadlines.
One action today
Today, confirm whether you have any Exchange 2016/2019 in use (including with a hosted provider) and set a dated plan to migrate/retire before October.
Related Actions On Cyber resource
Actions On Cyber: Phishing & invoice fraud call-back checklist (bank detail change verification)
Sources
- Microsoft to stop Exchange 2016 / 2019 security updates in October (BleepingComputer)
- Adobe Chrome extension flaw let sites access private WhatsApp chats (BleepingComputer)
- Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.