Welcome to Ping, a weekly signal for small and mid-sized businesses. Every week we read the security firehose so you don't have to, and boil it down to what a small shop should actually do: what to patch now, what scams are going around, what's aging out, and where AI is quietly changing the risk. One short read, every item sourced, no fear-mongering.
Here's the week.
AI Watch
The newest, least-familiar risk: attacks that target the AI tools your team has quietly started using.
- Your Team's AI Coding Assistant Can Be Tricked Into Installing a Different Plugin Than the One You Approved. A flaw called Plugin4Shell lets whoever controls a plugin's repository swap the code an AI coding agent installs, even when the agent pinned it to a specific reviewed version. Anthropic patched it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0; teams using either should update and re-check any pinned plugins. (source: The Hacker News: Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code)
Patch This Week
Known fixes worth applying now.
- Check Point Firewall Admins: A Zero-Day in the Management Server Is Being Used in Targeted Attacks. CVE-2026-93616 lets an attacker who can reach the Security Management Server's web interface run scripts without logging in. Check Point shipped a hotfix on September 22, and management servers should never be exposed to the internet in the first place. (source: BleepingComputer: Check Point warns of Management Server zero-day)
- SonicWall Gen 6 Firewalls Lose All Support on October 1. After October 1, 2026, the last Gen 6 SonicWalls stop getting patches of any kind, including for critical flaws. Plenty of them are still humming quietly in office closets from the late 2010s. (source: Spiceworks: What SonicWall Gen 6 end of support means for the firewall in your closet)
- WordPress Just Patched Click2Shell. One Link to a Logged-In Admin Silently Installs a Theme. WordPress core's September update fixes a flaw where a crafted link, opened by an authenticated admin, installs any theme from the WordPress.org directory with no Install click. On its own it forces the install; chained with a vulnerable theme it becomes code execution on the site. (source: The Hacker News: New WordPress Click2Shell Flaw)
- A Vendor Asked Every Customer to Shut Servers Down for Nine Hours Last Weekend. Kiteworks received credible federal threat intel about an imminent attack and told customers worldwide to power their systems off on Saturday. Every SMB needs a named out-of-hours contact who can act on a same-day vendor advisory like this. (source: BleepingComputer)
- The Window Between Disclosure and Attack Is Now Five Days. Emergency Patching Needs a Real Playbook. Rapid7 finds a newly disclosed flaw now hits CISA's Known Exploited Vulnerabilities catalog in a median of five days after publication, down from 8.5. SMBs need a written process for who decides, who patches, and how they roll back if a patch breaks something. (source: Spiceworks: Emergency patching for small IT teams)
- D-Link Says the DIR-822A Router Has a Max-Severity Bug and No Patch Is Coming. A public proof-of-concept exists for CVE-2026-86296 in D-Link's legacy DIR-822A Wi-Fi routers, and the vendor has confirmed there will be no fix. Any office still running one needs a replacement plan this quarter. (source: BleepingComputer: D-Link warns of max severity zero-day)
Scams & Signals
What's actually landing in inboxes and on networks: the social-engineering and breach news to warn your team about.
- A Ransomware Crew Logged Into a Firewall's Admin Console Because It Was Exposed to the Internet. Cisco Talos documented an intruder walking into a Secure Firewall Management Center over the public web with a password baked into the software, then mapping the network and deploying Qilin ransomware. Any admin login page that faces the internet is a candidate for the same treatment. (source: Spiceworks: Admin pages don't belong on the open internet)
- 5,700 Microsoft 365 Accounts Attacked, and the Seven That Fell Were Still Using Default Passwords. Proofpoint tracked a TeamFiltration campaign that hit 28 tenants from 1,487 AWS IPs. Only the accounts still carrying their original onboarding passwords got taken over. Any account older than your current password policy should be rotated now. (source: The Hacker News)
- third-party.com Is a Placeholder in Countless Code Samples. It Now Serves a Fake Cloudflare Page That Runs PowerShell. The domain most developers treat as an example is a real address that someone owns, and it's currently hosting a ClickFix page that walks Windows users through pasting a malicious PowerShell command. Any internal doc, script, or README that used it as a placeholder is a live link. (source: BleepingComputer: Placeholder domain used in dev docs now serves ClickFix attacks)
- A Fake LastPass Installer Is Using a Microsoft-Signed Driver to Kill Antivirus Before Stealing Passwords. A password-stealer bundle circulating on GitHub ships a kernel driver that Microsoft's own signing program approved, and it disables antivirus and EDR before running. Signed does not mean safe, and app allowlisting matters more than trusting the publisher. (source: The Hacker News: Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver)
- A BigCommerce Breach Through a Third-Party App Injected Malicious Scripts Into Merchant Storefronts. Attackers stole credentials for a set of Ribon apps and used them to push skimming scripts into live BigCommerce stores. If you run an online store, every app that can edit your theme is a supply-chain risk. (source: BleepingComputer: BigCommerce alerts merchants of data breach linked to Ribon apps)
- A Standard Windows 11 Reset Can Leave Deleted Files Recoverable. There's Now a Secure Wipe Option. The out-of-box reset in Windows 11 clears the file table but leaves the underlying data recoverable with off-the-shelf tools. Microsoft's new Cloud Rebuild flow adds a genuine sanitize step that matters before a laptop leaves the building. (source: Windows Latest: Windows 11 leaves deleted files recoverable after reset)
- Microsoft Paused a Microsoft 365 Update That Was Deactivating Perpetual Office 2016 and 2019 Installs. Update KB5002907 removed the activation on some perpetual-license Office installs before Microsoft pulled it. If Office suddenly demands reactivation on an older PC, this is the cause. Confirm your team can locate the original product keys. (source: BleepingComputer)
End of the Road
Deadlines that reward planning ahead. A rushed migration is an expensive one.
See the runway above for what's coming; nothing new was flagged this week.
Trends & Signals
Because Ping runs every week, we can show the trajectory, not just this week's list. (These track the SMB-relevant items we flag each week: our editorial signal, not a full vulnerability census.)
How we help
Most of what's above is routine when someone owns it: patch on a schedule, watch the gear that gets forgotten, plan the upgrades before the deadline, warn the team about the live scams, and keep an eye on the newer AI risks. That's the boring, durable work we do for the businesses we manage, with a 24/7 team so the 3 a.m. items are handled before you wake up. If your patching and planning currently live in someone's head, let's talk about making it a system.
See you next Ping.
Ready to talk it through?
Reach Amoeba Networks whichever way is easiest:
- Call (212) 444-9780
- Email info@amoebanetworks.com
- Use the contact form
- Or just click on Mike — the floating Contact button with his face in the corner of any page — to grab a time on his calendar.