Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Sunday brief: Malvertising ‘builds’ malware in your browser, ClickFix forum scams, and ransomware ops scaling up

What small and medium-sized businesses should look out for today.

High Sunday 26 July 2026, 10:23 UK time
Today’s look-out: Malvertising & “ClickFix” social engineering leading to malware/ransomware

What to look out for today

  • Malvertising lures (adverts) impersonating well-known trading/crypto brands to get staff to download or run something.
  • “ClickFix” style scams on forums/community posts (e.g., gaming/support threads) that claim to fix a problem but actually push a hidden malware install.
  • Ransomware-as-a-service becoming more “professional”, making it easier for criminals to run disruptive attacks on smaller organisations.
  • Supplier/hosted app risk: reports of attackers targeting a popular Java JSON component used in some web apps/services.

Why this matters to smaller businesses

Smaller organisations don’t need to be specifically targeted to be hit. Malvertising and “helpful fix” scams are designed for scale: one click from an admin account, finance user, or a shared office PC can lead to credential theft, remote access being installed, or ransomware. If you rely on a hosted app, web agency, or MSP, their exposure can quickly become your disruption.

Warning signs

  • Staff report seeing ads or search results for “TradingView/Solana/Luno” (or similar) offering downloads, “updated installers”, “pro” tools, or urgent account prompts.
  • A colleague follows steps from a forum post or chat message telling them to copy/paste instructions, run a “fix”, or bypass normal security prompts.
  • Unexpected CPU fan noise / sluggish PCs (possible cryptomining), or browser extensions/toolbars appearing that no one requested.
  • Unusual login prompts or MFA fatigue (repeated push notifications), especially after a download or “fix” attempt.
  • New admin accounts, remote tools, or scheduled tasks appearing without a change request (your IT provider should be able to confirm).

How attackers may exploit the situation

  • Ad-driven infection chains: criminals buy/abuse ad placements to route users through lookalike sites and deliver malware in a way that may evade simple “block the file” controls.
  • Social engineering via “support” content: ClickFix campaigns rely on the victim doing the dangerous step themselves, making it look like legitimate user activity.
  • Follow-on ransomware: initial malware can be used to steal passwords/session cookies and then escalate to a full business disruption event.
  • Third-party exposure: if a supplier runs vulnerable web components, attackers may compromise the supplier and reuse access or stolen data against customers.

What to do today

  • Send a 2-minute staff note: “Don’t follow ‘fix’ steps from forums/ads. If you see an ad for a download or a post telling you to run commands/install a tool, stop and raise it to IT.”
  • Check endpoint coverage: confirm all devices (including shared/front-desk and any home laptops used for work) are enrolled in your security tool and reporting.
  • Lock down who can install software on work PCs—especially on finance/admin machines.
  • Backups quick-check: verify you have a recent backup and that you can restore a small sample (one folder or one machine image) if needed.
  • Advertising & web controls: if you have web filtering, consider tightening categories around “newly registered domains”, “software downloads”, and high-risk ad/tracker networks (balanced against business needs).

Ask your IT provider

  • Can you show me which devices are not currently protected/checked in (and what you’re doing about them)?
  • Do we restrict local admin rights and software installs on user PCs—particularly finance and senior leadership?
  • What alerts are you monitoring for: unusual remote tools, new admin accounts, suspicious browser extensions, credential theft indicators?
  • If ransomware hits, what is our realistic restore time for key systems (files, email, line-of-business apps)? When was the last restore test?
  • For our key suppliers/SaaS (accounts, payroll, CRM), what additional sign-in protections are enforced (MFA, conditional access, device compliance)?

Patch watch - only one short paragraph, and only if relevant

There are reports of active attacks targeting a Java JSON library used in some Spring Boot applications (CVE-2026-16723). This is mainly a risk for organisations that run their own Java web apps or rely on suppliers who do. If you outsource your website/app hosting, ask your provider to confirm whether any customer-facing services use Fastjson 1.x and what mitigations they have in place while vendor patching is unclear.

One action today

Send a short internal message today telling staff not to follow “fix” instructions from forums/ads or install “urgent updates” from adverts—report it to IT instead.

Related Actions On Cyber resource

Actions On Cyber checklist: “Phishing & scam reporting – the 60-second staff playbook”

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.