Business Security

Current Cyber Threats

Active ransomware campaigns, phishing trends, and critical vulnerabilities affecting small businesses right now. Reviewed and refreshed weekly, in plain language — no jargon required.

Last reviewed: September 9, 2026

Ransomware / Phishing

Fake Interpol "Investigation" Emails

A ransomware campaign is emailing businesses fake notices claiming to be from Interpol, saying the company is under investigation with "evidence" attached. Opening the attachment installs ransomware. It has hit pharmaceutical, food, agriculture, tech, media, and legal businesses across the US, Europe, Asia, and the Middle East.

  • Unexpected email claiming a law-enforcement investigation, with an urgent attachment
  • Pressure to open a file immediately "to see the evidence"

What to do: Don't open the attachment. Real law enforcement doesn't notify businesses of investigations this way. Verify independently and forward suspicious emails to your IT provider before opening anything.

Source: Security Boulevard, July 2026

Phishing

Fake Meta "Verification Badge" Offer

Small business owners and marketing teams running Facebook Pages are getting phishing messages offering a verification badge, with a fake 24-hour deadline to "activate" it. Clicking through leads to a credential-stealing page.

  • Unsolicited offer of a "verification badge" for your business page
  • Artificial urgency ("activate within 24 hours")

What to do: Don't click. Manage your Page's verification status only through Meta Business Suite, typed in directly, never through a link in a message.

Source: Hornetsecurity Monthly Threat Report, July 2026

Ransomware Trend

"Double Extortion" Is Now the Norm

Most ransomware groups now steal your data before encrypting anything, then threaten to publish customer records, financials, or internal files publicly if you don't pay — even if you can restore from backup.

  • Backups alone no longer fully protect you from a ransomware payout demand
  • A breach can mean stolen data is leaked regardless of what you pay

What to do: Backups are still essential, but pair them with real access controls and monitoring so attackers can't quietly sit in your network stealing data for weeks first.

Source: Hornetsecurity Monthly Threat Report

Critical Vulnerability

Zyxel & DrayTek VPN/Firewall Boxes Under Active Attack

Hackers are actively exploiting a flaw in Zyxel and DrayTek VPN/firewall appliances — common budget-friendly boxes many small businesses use for remote access — to gain direct network access. No patch is available yet.

  • You use a Zyxel or DrayTek VPN/firewall appliance for remote access
  • No fix currently exists, so exposure continues until one ships

What to do: Check if this affects your equipment. Until a patch ships, consider restricting remote access or moving to a different solution temporarily.

Source: CISA advisory coverage, August 2026

Critical Vulnerability

Windows VPN Flaw Lets Attackers Run Code Remotely

CVE-2026-33824 is a confirmed-exploited flaw in Windows' VPN/IKE service that can let an attacker run code remotely — a real risk for any business using Windows-based VPN or site-to-site encrypted tunnels.

  • Affects Windows systems handling VPN/IKE connections
  • Already on CISA's actively-exploited list, not just theoretical

What to do: Make sure Windows updates are current on any machine handling VPN connections. If you're not sure, that's exactly what a patch review catches.

Source: CISA Known Exploited Vulnerabilities Catalog, August 2026

Critical Vulnerability

Microsoft SharePoint Login Bypass

CVE-2026-55040 lets attackers slip past authentication on Microsoft SharePoint, a system many small businesses use to store internal documents and files. Attackers are actively exploiting it to reach sensitive business records.

  • Affects businesses using SharePoint for internal document storage
  • Actively exploited, not just a theoretical risk

What to do: If you use SharePoint, confirm it's fully patched. This is a good candidate to bring up in a security check.

Source: CISA Known Exploited Vulnerabilities Catalog, August 2026

Patch Timing

The Window to Patch Has Shrunk to Days

CISA says the gap between a vendor releasing a fix and criminals actively exploiting it has dropped to as little as five days. Waiting weeks or months to apply updates is no longer a safe habit.

  • "We'll get to updates eventually" is now a real exposure window

What to do: Keep systems on a regular patch schedule rather than an ad-hoc one. This is exactly what our patch & update service is for.

Source: CrowdStrike Patch Tuesday Analysis, August 2026

Critical Vulnerability

Citrix NetScaler Flaw Now Lets Attackers Take Full Control

CVE-2026-8452 affects Citrix NetScaler ADC and Gateway, appliances many businesses use for secure remote access and VPN connections. Originally thought to only crash the device, researchers found it can actually let an attacker gain full remote control as root. It's already being used in the wild to plant backdoors on unpatched systems.

  • Affects businesses using NetScaler for VPN, SSL VPN, or remote access
  • Upgraded from "annoying outage" to "full takeover" risk

What to do: If you or your IT provider run a NetScaler appliance, confirm it's on a patched version immediately. This is a good one to bring up in a security check.

Source: Help Net Security, August 2026

Ransomware Campaign

Cl0p Group Hits Manufacturing Software Supply Chain

The Cl0p ransomware group has listed over 40 organizations, including major manufacturers, as victims of a campaign targeting PTC's Windchill and FlexPLM software, tools used to manage product design and manufacturing data. Attackers chained a flaw with CVE-2026-12569 to break in, even after a patch was available.

  • Affects businesses using Windchill or FlexPLM for product data management
  • Victims include large manufacturers, but any user of the affected software is at risk

What to do: If your business or a vendor uses PTC Windchill/FlexPLM, confirm the June patch has actually been applied, not just scheduled.

Source: SecurityWeek, August 2026

Extortion Tactic

Fake "Recovery Firms" Are the New Ransomware Angle

A new twist on ransomware extortion: instead of another demand from the original attackers, some businesses are contacted by a supposed data-recovery company, calling itself "Ransom Busters," offering to retrieve stolen files, destroy the criminals' copies, and hand over decryption keys, for a fee of $20,000 to $60,000. Researchers believe it's actually the same ransomware group in disguise, running a second extortion attempt on the same victims.

  • An unsolicited "recovery firm" contacts you about a breach you haven't announced publicly
  • Pressure to pay a third party quickly to make the problem go away

What to do: Don't engage or pay before verifying independently. If you've had an incident, work through a trusted IT/security provider, not an unsolicited offer that shows up out of nowhere.

Source: GuidePoint Security, August 2026

Critical Vulnerability

SonicWall Appliances Under Active Attack

SonicWall confirmed active exploitation of two flaws in its SMA 1000 series appliances, hardware many small businesses rely on for secure remote access. One flaw (CVSS 10.0, the maximum score) lets an attacker in with no credentials at all; the second lets an already-logged-in attacker run commands on the device. CISA gave federal agencies until September 5, 2026 to patch, a signal of how urgent this one is.

  • Running a SonicWall SMA 1000 series appliance for remote access or VPN
  • Firmware not updated since the fix became available
  • No monitoring in place to catch unusual admin activity on the device

What to do: Patch SonicWall SMA 1000 devices immediately if you haven't already. If patching isn't possible right away, isolate the appliance from the internet until it is.

Source: The Hacker News / CISA KEV Catalog, September 2026

Critical Vulnerability

N-able N-central (RMM Software) Under Active Attack

N-able N-central, remote monitoring and management software many IT providers use to manage client computers, has a maximum-severity flaw (CVSS 10.0) that lets an attacker run code on the server with no login at all, no phished password or stolen session needed, just network access to the server. It's the fourth zero-day patched in N-central in five weeks, and CISA confirmed active exploitation, giving federal agencies until September 11, 2026 to patch.

  • Running N-able N-central on-premises to manage or monitor client computers
  • Any N-central build older than 2026.3.1.14 (2026.3 Hotfix 4)
  • N-central server reachable from the open internet rather than behind a VPN

What to do: If you or your IT provider run N-central, confirm it's updated to 2026.3.1.14 or later right away. Because this hits the tool used to manage other computers, a compromise here can spread to every device it monitors.

Source: The Hacker News / CISA KEV Catalog, September 2026

Not Sure Where You Stand?

Get a real answer, not a guess.

Not sure if any of this affects your business, or if something you received is part of one of these campaigns? Send it our way on the Scam Alerts page, or request a vulnerability assessment below.

Request a Quote