Welcome to Ping, a weekly signal for small and mid-sized businesses. Every week we read the security firehose so you don't have to, and boil it down to what a small shop should actually do: what to patch now, what scams are going around, what's aging out, and where AI is quietly changing the risk. One short read, every item sourced, no fear-mongering.
Here's the week.
AI Watch
The newest, least-familiar risk: attacks that target the AI tools your team has quietly started using.
- Adversary-in-the-Middle Phishing Kits Are Hitting Thousands of Microsoft 365 Tenants, and Standard MFA Isn't Stopping Them. Two commercial phishing platforms, Mirage2FA and NovaCookies, proxy the real Microsoft 365 login page and quietly steal the authenticated session cookie. About 4,500 US and EU companies have been hit. SMS codes and app-approval prompts pass right through; phishing-resistant sign-ins (passkeys, FIDO2, number-matching with device binding) shut it down. (source: The Hacker News: Mirage2FA Surge Hits 4,500 US and EU Companies; The Hacker News: NovaCookies Campaigns Abuse Genuine Docusign Notifications)
Patch This Week
Known fixes worth applying now.
- Print Servers Are Under Active Attack. If You Run PaperCut NG or MF, Patch Immediately. PaperCut is warning that a vulnerability across all versions of NG and MF is being exploited as a zero-day. Print management servers sit deep in the office network with domain access, which makes them a high-value pivot point for attackers. (source: BleepingComputer: PaperCut warns of NG, MF flaw exploited in zero-day attacks)
- Three Max-Severity Ubiquiti Vulnerabilities Just Landed. If You Run UniFi Gear, Update Firmware This Week. Ubiquiti has released patches for three CVSS 10.0 flaws that a remote attacker can exploit without any credentials. UniFi is common in small-office networking closets, and the fix is a firmware bump most controllers can push tonight. (source: BleepingComputer: Ubiquiti patches three max severity security vulnerabilities)
- Avada, One of the Most Popular Paid WordPress Themes, Has a Zero-Click Code Execution Flaw. A critical vulnerability chain in the Avada theme lets an unauthenticated visitor run PHP on the server, no login or user interaction required. Avada has been sold hundreds of thousands of times, so the odds your marketing site (or a client's) is affected are real. (source: BleepingComputer: Critical Avada WordPress theme flaw enables zero-click RCE)
- GiveWP Donation Plugin Has a Max-Severity Flaw. Sites Are Being Scanned for It Now. GiveWP powers donation forms on around 100,000 WordPress sites. A newly disclosed vulnerability lets an unauthenticated attacker run commands on the hosting server, which is total site takeover unless the plugin is updated. (source: BleepingComputer: GiveWP WordPress donation plugin flaw)
- Actively Exploited: A miniOrange SAML Plugin Flaw Lets Attackers Log In as WordPress Admins. Two critical authentication bypass bugs in the miniOrange SAML 2.0 Single Sign On plugin let attackers forge SAML responses and take over admin accounts. If your WordPress site uses this plugin, the plugin must be updated (or removed) now, and every admin account should be checked for suspicious logins. (source: Hackers target WordPress sites in miniOrange auth bypass attacks (BleepingComputer))
- Attackers Are Repurposing Microsoft Defender's Own Boot-Time Driver to Wipe Other Security Software. Researchers showed BTR.sys, a Microsoft-signed remediation driver, can be pointed at rival endpoint software and remove it before Windows finishes starting. No vulnerability is being exploited; the driver is doing exactly what it was built to do, aimed at the wrong files. (source: The Hacker News: Microsoft Defender's Own Driver Can Be Weaponized)
- Federal Agencies Must Now Patch by Risk Score, Not Calendar. Your Business Can Borrow the Same Playbook. CISA's new Binding Operational Directive 26-04 tells federal agencies to prioritize security updates by measurable risk rather than fixed monthly windows. The scoring model is public, straightforward, and maps cleanly onto how a small IT team already triages patches. (source: CISA: BOD 26-04 Implementation Guidance)
- CISA Just Added an ownCloud Flaw to Its Exploited List. If You Run It On-Prem, Check Your Version This Week. A 9.8-rated ownCloud vulnerability (CVE-2023-49105) is now in the Known Exploited Vulnerabilities catalog after a Chinese-speaking group used it to steal nuclear research data. Any SMB running self-hosted ownCloud for file sharing should confirm the fix is in and audit for signs of access. (source: The Hacker News)
- Over 8,300 Self-Hosted Gitea Servers Are Still Unpatched Against an Actively Exploited Code Execution Flaw. Shadowserver counts more than 8,300 internet-exposed Gitea instances that have not applied the patch for a critical RCE, and attackers are already using it. Small dev teams often stand these up quietly and forget about them. (source: BleepingComputer)
- Two Critical Next.js Flaws Allow Unauthenticated Remote Code Execution. Any Site Built on It Needs an Update This Weekend. Vercel patched two critical Next.js vulnerabilities: one triggered by a malicious AVIF image, the other a Windows path traversal. Both let an unauthenticated attacker run code on the server hosting the site. (source: The Hacker News)
Scams & Signals
What's actually landing in inboxes and on networks: the social-engineering and breach news to warn your team about.
- Berlin Refused to Pay Its Extortionists. The Preparation That Makes 'No' a Real Option for SMBs. A city government publicly declined ransom after attackers stole data from its network. Saying no in real time requires separated and tested backups, breach counsel already on retainer, and a communications draft on the shelf. Any small business can put those pieces in place before the incident. (source: The Hacker News: Berlin Refuses to Pay Hackers)
- Two Critical Infrastructure Orgs, Same Attack Playbook, One Saw Nothing: CISA's Latest Red Team Report. CISA's red team fully compromised both organizations to the domain level using similar tradecraft, but one team detected and responded while the other missed the entire operation. The difference was tuned alerting and someone actually watching the console. (source: CISA: Cybersecurity Advisory AA26-237A)
- That Guest Wi-Fi Sign-Up Form Is a Customer Database. Treat It Like One. An airport group just disclosed that hackers stole traveler data including guest Wi-Fi sign-ups. Any business that captures a name and email at the front desk or lobby Wi-Fi is running a mini CRM that lives outside its main security controls. (source: BleepingComputer: Manchester Airports Group says hackers stole travelers' data)
- Microsoft Teams Can Now Auto-Block External Bots From Meetings. Turn This On. A new Teams meeting policy lets tenant admins automatically kick out any identified external bot that tries to join a meeting, cutting off a real path used to lurk on calls and vacuum up transcripts. It's an admin-side toggle, not something end users have to remember. (source: Microsoft Teams now lets admins block external bots from meetings (BleepingComputer))
- ToxicPanda Now Silences Google Play Protect Using Android's Own VPN Permission. The latest ToxicPanda build asks for a VPN permission and then quietly routes Google Play Protect's traffic into a dead end, so the built-in scanner never sees the malware sitting next to it. Any BYOD Android phone that grants VPN access to a random 'security' app inherits that blind spot. (source: BleepingComputer: ToxicPanda uses VPN permissions to block Google Play)
End of the Road
Deadlines that reward planning ahead. A rushed migration is an expensive one.
See the runway above for what's coming; nothing new was flagged this week.
Trends & Signals
Because Ping runs every week, we can show the trajectory, not just this week's list. (These track the SMB-relevant items we flag each week: our editorial signal, not a full vulnerability census.)
How we help
Most of what's above is routine when someone owns it: patch on a schedule, watch the gear that gets forgotten, plan the upgrades before the deadline, warn the team about the live scams, and keep an eye on the newer AI risks. That's the boring, durable work we do for the businesses we manage, with a 24/7 team so the 3 a.m. items are handled before you wake up. If your patching and planning currently live in someone's head, let's talk about making it a system.
See you next Ping.
Ready to talk it through?
Reach Amoeba Networks whichever way is easiest:
- Call (212) 444-9780
- Email info@amoebanetworks.com
- Use the contact form
- Or just click on Mike — the floating Contact button with his face in the corner of any page — to grab a time on his calendar.