Welcome to Ping, a weekly signal for small and mid-sized businesses. Every week we read the security firehose so you don't have to, and boil it down to what a small shop should actually do: what to patch now, what scams are going around, what's aging out, and where AI is quietly changing the risk. One short read, every item sourced, no fear-mongering.

Here's the week.

AI Watch

The newest, least-familiar risk: attacks that target the AI tools your team has quietly started using.

  • The 'AI Slop' Package Problem: How Nearly 800 Fake npm Libraries Slipped Into the Ecosystem. Attackers are using AI-generated package names to flood open-source registries with lookalikes that carry remote-access malware. For SMBs, it's a reminder that any developer, contractor, or low-code tool pulling packages is a potential entry point. (source: The Hacker News: nearly 800 malicious npm packages deliver a cross-platform RAT)

Patch This Week

Known fixes worth applying now.

  • The Fake 'Coding Job Interview' That Installs a Real VPN With a Hidden Backdoor. Attackers are posing as recruiters and asking IT professionals to install a 'company VPN client' as part of the interview. It's a trojanized WireGuard build that can run commands on the machine. Worth flagging to any hiring managers and job seekers on your team. (source: The Hacker News: Sandworm-linked UAC-0145 uses fake job interviews to push a VPN that runs commands)
  • When Ransomware Deletes the Backups AND the Disaster Recovery Copies: Why 'Immutable' Is the Word to Ask About. A new joint advisory calls out a ransomware crew that, in at least one case, wiped both the primary backups and the offsite DR copies before demanding payment. If your recovery plan assumes 'we have a backup,' this is the moment to ask a harder question. (source: CISA/FBI joint advisory: Gunra ransomware)
  • Windows Server 2016 Stops Getting Security Updates in January 2027: If You Still Run One, Start Planning Now. Plenty of small businesses still have a Windows Server 2016 file server, print server, or line-of-business app quietly humming in a closet. In a few months it stops getting security patches. The three realistic options are to upgrade, migrate to the cloud, or replace it, and it's worth pricing them before the deadline. (source: endoflife.date: Windows Server support timeline)
  • That 'Draw on My Screen' Button in Zoom? A Flaw Let Any Participant Take Over the Presenter's PC. Zoom's annotation tool, the feature people use to circle things during screen shares, contained a flaw that let one attendee run code on another's machine with no click required. Patch the client, and treat meeting-app features as attack surface. (source: The Hacker News: Zoom annotation flaws could let a meeting participant hijack another attendee's client)
  • If You Sell Online Through Magento or Adobe Commerce, Attackers Are Trying to Take Over Your Customers' Accounts This Week. A critical flaw in Adobe Commerce and Magento is being probed in the wild to hijack shopper accounts. If your webstore runs on either, this is a call-your-developer-today item. If a shopper's card is stolen through your store, the cleanup and the reputation hit land on you. (source: BleepingComputer: hackers exploit critical Adobe Commerce flaw to hijack customer accounts)

Scams & Signals

What's actually landing in inboxes and on networks: the social-engineering and breach news to warn your team about.

  • 1.6 Million Accounts Exposed at a Major Business Phone Vendor: What SMBs Should Do When Their VoIP Provider Gets Breached. Cloud communications provider RingCentral disclosed that names, emails, and account details from 1.6 million business accounts were stolen in a July extortion-group intrusion. If your team uses a hosted phone or contact-center service, reset any exposed credentials and warn staff to expect targeted phishing that name-drops the breach. (source: BleepingComputer: RingCentral data breach exposed info of 1.6 million accounts)
  • More Than 730 Fake 'VPN' Extensions in the Chrome Store: How to Audit Browser Extensions on Company Laptops. Researchers found more than 730 malicious Chrome extensions posing as VPNs, many still live, quietly routing employees' web traffic through attacker-controlled proxies. Most of your team can install a browser extension without asking IT, so a quick audit of what's on company laptops is worth the fifteen minutes. (source: Socket: 737 Chrome VPN extensions linked to brand impersonation and traffic redirection)
  • When the Insider Is a Contractor: A Data Analyst Just Got Two Years for a $2.5M Extortion Scheme. A short-term contractor with access to production data quietly copied it, then tried to extort the employer. Tight access controls, prompt offboarding, and download monitoring are what stop this exact case. (source: BleepingComputer: data analyst sent to prison for stealing data, extorting employer)
  • When Your Shipping and Fulfillment Provider Gets Hacked: A Hardware Wallet Maker Just Learned the Hard Way. Hardware-wallet maker Trezor had roughly 14,000 customer records exposed when its fulfillment vendor was breached. If you ship physical product, your fulfillment partner holds names, addresses, phone numbers, and order histories, so it's worth inventorying which vendors keep your customers' data. (source: BleepingComputer: Trezor discloses data breach affecting nearly 14,000 customers)
  • Ransomware Now Reboots Your PC Into Safe Mode to Turn Off Your Antivirus. A recent Akira ransomware attack failed to encrypt files but still stole data by restarting the target machine into Safe Mode with Networking, where most endpoint protection doesn't run. 'We have EDR' isn't the whole story, so ask your provider which settings would block a forced Safe Mode reboot. (source: BleepingComputer: Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt)
  • When 'Anonymous Guest' Can See More Than You Think: Data Theft From Salesforce and ServiceNow Portals. An active campaign is walking off with data from public-facing customer portals by requesting it as an anonymous guest and getting an answer. If your business runs a portal on either platform, check what an unauthenticated guest can actually reach. (source: BleepingComputer: 'City-Forum' data-theft attacks target Salesforce, ServiceNow portals)
  • You Interviewed Them, You Onboarded Them, You Shipped Them a Laptop. They Weren't Who They Said They Were. Security researchers set up a fake startup and hired three people they believe were operating under fabricated identities, down to a driver's license and a bank account. The gap between hiring, device shipping, and account provisioning is the part SMBs can actually tighten. (source: The Hacker News: researchers built a fake crypto startup and hired three suspected North Korean IT workers)
  • Thinking of Moving Off the Cloud? Price a Server First, Because RAM Alone Might Change Your Mind. 'Cloud repatriation' is a fashionable idea, but a modest business tower now runs several thousand dollars and a single 32GB memory stick can cost nearly $4,000. A fair on-prem-versus-cloud comparison for a small office in 2026 has to include the hardware costs owners tend to forget. (source: Consumer Reports: AI data centers are scooping up RAM and could spike prices in 2026)
  • Got an 'Apple Threat Notification' on Your iPhone? Here's What It Actually Means and What to Do. Apple just sent a fresh round of threat alerts warning specific users that mercenary spyware targeted their iPhone. These alerts are real and rare, and they usually mean someone paid a lot of money to break into your device. If one ever lands on a company phone, don't dismiss it as spam; Apple's own guidance covers the steps to take. (source: BleepingComputer: Apple sends new threat notification alerts over mercenary spyware attacks)
  • Turning on BitLocker Isn't Enough: Why Your Laptops Need a Startup PIN Too. BitLocker is a solid baseline for laptop encryption, but without a startup PIN, several published attacks can pull the key straight off a stolen device. A PIN closes that gap with a few minutes of setup per machine. (source: NCSC: how BitLocker PINs help protect your data and devices)
  • When a Video Conferencing Vendor Gets Hacked: Why the 'Installer' You Downloaded Last Month Might Be Malware. Attackers breached video-conferencing vendor TrueConf and quietly swapped the client installer with a trojanized, backdoored version. If you rolled it out recently, verify the build you deployed and ask vendors how they sign and check installer integrity. (source: BleepingComputer: hackers breach TrueConf to trojanize client installers with backdoors)
  • When Social Engineering Beats Three Employees at Once: What a Big-Brand Data Theft Tells SMBs About Human-Layer Defense. Levi Strauss disclosed that attackers social-engineered three employees to reach corporate data on their machines. The lesson is to build layered defenses that assume a human will eventually be fooled. (source: BleepingComputer: Levi Strauss & Co. says hackers stole corporate data in cyberattack)

End of the Road

Deadlines that reward planning ahead. A rushed migration is an expensive one.

EOL Runway: support cut-offs for common SMB software

  • Office 2021 Stops Getting Security Updates in October: Here's the Migration Decision for SMBs. If your team is still on perpetual-license Office 2021, security updates end October 13, 2026. It's worth a plain comparison of staying on-prem versus moving to Microsoft 365 versus alternatives, without the hype. (source: endoflife.date: Microsoft Office support timeline)

Trends & Signals

Because Ping runs every week, we can show the trajectory, not just this week's list. (These track the SMB-relevant items we flag each week: our editorial signal, not a full vulnerability census.)

Patch Load: action-now items per week

The AI Line: AI's share of the SMB security items we track

This week by category

How we help

Most of what's above is routine when someone owns it: patch on a schedule, watch the gear that gets forgotten, plan the upgrades before the deadline, warn the team about the live scams, and keep an eye on the newer AI risks. That's the boring, durable work we do for the businesses we manage, with a 24/7 team so the 3 a.m. items are handled before you wake up. If your patching and planning currently live in someone's head, let's talk about making it a system.

See you next Ping.

Ready to talk it through?

Reach Amoeba Networks whichever way is easiest:


All blog Ping
contact Contact