Webwire Pty Ltd - This Week in Cybersecurity: What SMBs Need to Know – July 20, 2026
From printer vulnerabilities to a record-breaking Microsoft patch update—here’s what every SMB must act on this week in cybersecurity.
Cybersecurity Alerts This Week No SMB Should Ignore
Every business, regardless of size, is under threat. This week’s cybersecurity headlines highlight how attackers exploit everyday systems, push boundaries further, and the urgent steps organisations should take to stay resilient.
Introduction
In the past week, new vulnerabilities and exploits have emerged that small and mid-sized businesses must not overlook. From overlooked devices like printers to record-breaking patch updates from Microsoft, the expanding threat landscape demands attention.
Whether it’s new zero-days being actively exploited or supply chain risks creeping into trusted systems, the stakes are high. But with the right steps—smart patching, awareness, and best-practice policies—teams can navigate the risks with confidence.
1. Printers Pose Real Security Risks in SMB Offices
Printers are often forgotten in security conversations—but they’re now emerging as a gateway for data breaches. According to a respected industry publication, attackers can compromise printers just as easily as laptops or servers, and such breaches can lead to significant financial, regulatory and reputational damage. Features like document storage, network connectivity and default credentials make printers surprisingly vulnerable. SMBs must treat them as critical endpoints.
Why it matters to your business: - Many SMBs overlook printer security when hardening their environments. - A compromised printer may expose confidential documents or enable lateral movement across networks. - Regulatory requirements often extend to document handling systems—including printers.
Practical recommendations: - Apply firmware updates and change default credentials promptly. - Segment printers on a separate VLAN or network zone. - Monitor printer logs and network traffic for anomalies. - Disable unnecessary services (e.g. remote printing protocols). - Include printers in your regular security audits.
2. Microsoft Ships Record-Breaking Patch Release: 600+ Fixes
This July’s Patch Tuesday shattered records, with Microsoft releasing over 600 security fixes—far more than typical. This includes two actively exploited zero-days in Active Directory Federation Services and SharePoint Server, and a BitLocker bypass flaw. Microsoft credits AI-powered detection for uncovering the surge in vulnerabilities.
Why it matters to your business: - Zero-day flaws already under exploitation demand immediate attention. - High volume of patches increases the risk of missing or delaying critical updates. - Legacy configurations—like RC4-based Kerberos—can break when patches are applied without audits.
Practical recommendations: - Prioritise patches for actively exploited issues (e.g. AD FS and SharePoint flaws). - Audit identity systems and service accounts before patching. - Rotate credentials and move away from legacy encryption like RC4. - Patch promptly, but test in staging environments first. - Monitor for post-patch issues and resume testing quickly.
3. CISA Confirms Dozen Critical Exploited Vulnerabilities in the Wild
CISA’s Known Exploited Vulnerabilities (KEV) catalog added 12 new entries in the past week. These are confirmed to be exploited and represent the highest priority for remediation. Key vendors impacted include Microsoft, Fortinet, SonicWall, Ubiquiti, and others. Active exploits can turn any uncontrolled vulnerability into a breach overnight.
Why it matters: - KEV-listed flaws signal active attacks, not hypothetical risks. - Products from vendors like Fortinet and SonicWall are common in SMB networks. - Each week’s additions shrink the window for safe remediation.
Practical recommendations: - Monitor CISA KEV and similar trusted feeds for additions affecting your stack. - Patch or mitigate KEV-listed issues first—before other scheduled updates. - Apply compensating controls if immediate patching isn’t possible. - Use network segmentation and restrict access to high-risk assets. - Automate patch tracking and deployment wherever possible.
4. SMBs: Beware the Rising Risk from Supply Chain Credential Attacks
Recent incidents show hackers targeting integration firms and middleware to access multiple businesses at once. A notable breach by Icarus at Klue, a market intelligence firm, exposed customer data drawn from cloud integrations. The attackers used compromised legacy credentials to siphon data from Salesforce clouds across many organisations.
Why it matters: - One breached integration point can expose multiple businesses’ data. - Legacy or poorly managed credentials are a frequent entering point. - Packaged vendors may serve many SMBs, increasing blast radius.
Practical recommendations: - Limit use of third-party integrations and audit credentials regularly. - Enforce least privilege on service accounts and integration credentials. - Monitor for suspicious data transfers from vendor systems. - Require MFA and short credential rotation cycles for integrations. - Have a rapid response plan for vendor-related incidents.
What This Means For Your Business
Across these warnings lies a common thread: attackers are efficiently exploiting overlooked systems, automated discovery is revealing more vulnerabilities than ever, and supply chains are an expanding battlefield.
For SMBs, the key isn’t to become overwhelmed—it’s to act with intent. Start by patching what’s actively being exploited—AD FS, SharePoint, known KEVs. Then step back and look at your weak points: printers, third-party integrations, network segmentation, legacy configs.
Focusing on fundamentals—strong hygiene, monitoring, fast response—makes your business a harder target. And when new threats like AI-enhanced attacks or supply chain compromises emerge, you’ll be better positioned to respond.
Call Webwire on 08 9386 0053 or contact us at enquiries@webwire.com.au.