Welcome to Ping, a weekly signal for small and mid-sized businesses. Every week we read the security firehose so you don't have to, and boil it down to what a small shop should actually do: what to patch now, what scams are going around, what's aging out, and where AI is quietly changing the risk. One short read, every item sourced, no fear-mongering.

Here's the week.

AI Watch

The newest, least-familiar risk: attacks that target the AI tools your team has quietly started using.

  • Half of US Businesses Now Buy AI Twice. Your Existing Subscriptions Already Include Most of It. AI subscription spend crossed the 50 percent adoption mark at US businesses this year, and much of the growth is department heads buying tools that duplicate features already bundled into Microsoft 365, Google Workspace, Salesforce, and Zoom. An audit of what you already own usually finds two or three redundant seats. (source: Spiceworks: The AI features your subscriptions already include)
  • Running AI on a Server in Your Office: When It Actually Beats a Cloud Subscription. For steady workloads like document classification, meeting transcription, and internal-doc Q&A, a single on-prem GPU box can run the same open models for less than the monthly cloud API bill. The catch is patching, model updates, and who owns the runtime when it breaks at 4 p.m. on a Friday. (source: Spiceworks: The practical IT case for local AI platforms vs cloud AI)
  • One Click on a Copilot Personal Link Can Pull Data From Every App You Connected. Varonis showed that three flaws in Microsoft Copilot Personal, collectively called CoSnitch, let a crafted link silently exfiltrate content from any app the user linked to their assistant, using an undocumented URL parameter Copilot itself surfaced. If your team uses Copilot at home with Gmail, OneDrive, or a personal calendar attached, that is the blast radius. (source: The Hacker News: Microsoft Copilot Personal flaws)
  • The 'Paste This Command' Trick Just Came to Mac: And It Can Watch Your Browser Live. A new macOS info-stealer spread through ClickFix-style 'paste this to fix' prompts includes a module that lets attackers watch and drive the victim's browser in real time. Mac users have long assumed this class of attack was a Windows problem; it isn't anymore. (source: BleepingComputer: New AmnesiaStealer macOS malware hijacks browser sessions)

Patch This Week

Known fixes worth applying now.

  • Microsoft Rated an Entra ID Flaw a Perfect 10.0. If You Use Microsoft 365, Confirm the Patch Is In. Microsoft published fixes for a maximum-severity Entra ID vulnerability that could allow remote code execution in the identity platform that fronts Microsoft 365, Teams, and SharePoint. Since Entra ID is managed by Microsoft, most SMBs assume patching happens automatically, but tenant-level hardening and log review are still on the customer. (source: BleepingComputer: Microsoft warns of max severity Entra ID flaw)
  • Forminator on Your WordPress Site? A Critical Flaw Lets Strangers Upload PHP Files. A vulnerability rated 9.8 out of 10 in the Forminator plugin (installed on more than 600,000 WordPress sites) lets an unauthenticated attacker upload malicious files and run code on the server. If your company site uses Forminator for contact or lead forms, updating the plugin this week is the whole task. (source: The Hacker News: Forminator WordPress Flaw)
  • If Your Office Has Macs, Patch Screen Sharing This Week: Attackers Are Already Using It. A macOS authentication-bypass flaw is being actively exploited to install cryptocurrency miners after public exploit code appeared. Any Mac with Screen Sharing exposed is a target; here's the quick check for small businesses that use Macs. (source: BleepingComputer: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner)
  • Windows 11 24H2 Loses Security Updates on October 13, 2026. Plan the Upgrade Now. The 24H2 build of Windows 11 stops receiving security patches this October. Any PC left on it after that date is unpatched by default, so getting rollout rings and hardware compatibility sorted in September is the sane timeline for most small fleets. (source: Microsoft Windows 11 release information)

Scams & Signals

What's actually landing in inboxes and on networks: the social-engineering and breach news to warn your team about.

  • A Microsoft Teams Message Is Now Delivering a Fake Windows Lock Screen. A new malware family called SynkLoader is showing up in Teams phishing campaigns; the payload paints what looks like a Windows lock screen over the desktop and captures the password the user types to unlock their own PC. Because it arrives via Teams chat, email filters never see it. (source: BleepingComputer: New SynkLoader malware in Teams phishing)
  • Password Spraying Attempts Jumped 155x This Year. The Gaps Attackers Are Exploiting Are in Your MFA Setup. One tracked campaign generated 81 million login attempts in two weeks. The successful ones landed on accounts still reachable through legacy authentication or on login flows that MFA policies quietly excluded, like shared mailboxes, service accounts, and IMAP endpoints. (source: BleepingComputer: Password spraying attacks surge 155x)
  • Over 9,300 Live AWS Keys Are Sitting in Public Code Right Now. Researchers found thousands of Amazon Web Services access keys leaked to public repositories between 2022 and 2026 that still work and still grant full control over corporate cloud accounts. Most were pushed by developers or contractors who never rotated them after the mistake. (source: BleepingComputer: Hundreds of leaked AWS keys give full control)
  • Attackers Are Running Their Command Servers Inside Your Own SharePoint and Teams Tenants. The new TWINLOOT implant framework routes every step of its command-and-control through Microsoft services already in use at the victim: SharePoint files carry tasking, Teams messages carry results. Because the traffic is Microsoft to Microsoft, network filters and DNS blocklists see nothing suspicious. (source: The Hacker News: TWINLOOT abuses SharePoint and Teams)
  • The Fake 'We Hacked Your Ransomware Group' Email Asking Victims for $60,000. A group calling itself Ransom Busters is emailing ransomware victims claiming it already grabbed their stolen data off the attackers' servers, and offering to delete it for $20,000 to $60,000. Researchers say these unsolicited rescue offers are just a second round of extortion wearing a helpful mask. (source: The Hacker News: Ransom Busters Claims It Hacked Ransomware Servers)
  • Retiring a SaaS Tool? Revoke Its OAuth Tokens Before Someone Else Does. A recent breach at a competitive intelligence firm started with a stale legacy credential from a shuttered product that still held OAuth tokens reaching into customers' Salesforce environments. When you decommission a vendor, canceling the invoice is the easy half; pulling the app's connections out of Microsoft 365, Google Workspace, and Salesforce is the half that gets skipped. (source: Spiceworks: Shutting down a cloud service without leaving a mess)
  • Wi-Fi 7 Is Shipping. Here's When an SMB Office Actually Benefits. Enterprise Wi-Fi 7 access points are widely available and client support is growing, but most SMB traffic still fits comfortably inside Wi-Fi 6 headroom. The upgrade pays off when you're already replacing APs, running dense video meetings, or feeding a switch capable of 2.5GbE or more. (source: Spiceworks: Is it worth upgrading to Wi-Fi 7 yet?)

End of the Road

Deadlines that reward planning ahead. A rushed migration is an expensive one.

EOL Runway: support cut-offs for common SMB software

See the runway above for what's coming; nothing new was flagged this week.

Trends & Signals

Because Ping runs every week, we can show the trajectory, not just this week's list. (These track the SMB-relevant items we flag each week: our editorial signal, not a full vulnerability census.)

Patch Load: action-now items per week

The AI Line: AI's share of the SMB security items we track

This week by category

How we help

Most of what's above is routine when someone owns it: patch on a schedule, watch the gear that gets forgotten, plan the upgrades before the deadline, warn the team about the live scams, and keep an eye on the newer AI risks. That's the boring, durable work we do for the businesses we manage, with a 24/7 team so the 3 a.m. items are handled before you wake up. If your patching and planning currently live in someone's head, let's talk about making it a system.

See you next Ping.

Ready to talk it through?

Reach Amoeba Networks whichever way is easiest:


All blog Ping
contact Contact