Webwire Pty Ltd - Cybersecurity News This Week: Five Risks Business Leaders Should Act On Now
The latest cybersecurity news explained for business leaders, with practical steps to reduce patching, fraud, supplier and ransomware risk.
Cybersecurity News This Week: Five Risks Business Leaders Should Act On Now
The past seven days have delivered a clear message for Australian businesses and their international counterparts: cyber risk is becoming faster, more automated and more dependent on the security of suppliers, platforms and everyday business processes.
From a record Microsoft security update to AI-assisted fraud campaigns and attacks on IT management tools, the most important developments are not limited to large enterprises. Small and mid-sized organisations are exposed because they often rely on the same cloud services, software platforms and external providers, but have fewer resources to monitor them.
1. Microsoft releases a huge security update with two zero-days
Microsoft’s September 8 security release addressed 974 vulnerabilities across Windows, Azure, Exchange, Office, SQL Server, SharePoint and other products. A major vendor analysis described the release as one of the company’s largest ever, while the Multi-State Information Sharing and Analysis Center rated the overall risk to medium and large businesses as high. At the time of the advisory, there were no reports that the vulnerabilities were being exploited in the wild, but several flaws could enable remote code execution or allow an attacker to gain the privileges of a logged-on user. The MS-ISAC advisory provides the affected product list and recommended actions. citeturn0search0turn0news10
The practical issue for business leaders is not the headline number alone. Many organisations can address hundreds of vulnerabilities through a much smaller number of cumulative updates, but only if patch management is organised, tested and measured. A delay on an internet-facing server, remote access tool or identity system can create an opportunity for attackers before the next maintenance window.
Microsoft also announced that it will publish machine-readable Vulnerability Exploitability eXchange statements for all Microsoft-assigned CVEs. The goal is to help security teams and their tools distinguish between vulnerabilities that affect a particular deployment and those that are present but not exploitable in that environment. This should make prioritisation easier, especially for businesses that do not have a large security operations team. Microsoft’s VEX announcement explains the change. citeturn0search1
Why it matters for businesses
A patching backlog is now a business continuity risk. It can affect customer trust, cyber insurance, contractual obligations and the ability to demonstrate reasonable security practices. The same applies to unsupported versions of Windows Server, Exchange, network appliances and third-party applications.
Practical recommendations
- Confirm which Microsoft products are deployed across laptops, servers, cloud services and line-of-business systems.
- Prioritise internet-facing systems, identity platforms, remote access tools and systems holding sensitive information.
- Use a documented change process so urgent security updates can be deployed quickly without waiting for an informal approval chain.
- Check for signs of compromise after patching, particularly on exposed servers and privileged accounts.
- Ask your managed service provider for written confirmation that the September updates have been assessed and applied where required.
2. AI-assisted attackers target finance teams with convincing invoice fraud
Microsoft reported a campaign that sent more than one million emails between August 3 and August 5. The messages impersonated senior executives and trusted vendors, used fabricated invoices and attempted to persuade accounts payable teams to send payments of nearly US$50,000 through bank transfer. The campaign used lookalike domains and third-party email delivery infrastructure. Microsoft said the legitimate organisations referenced in the messages were not compromised. Microsoft’s research on executive impersonation and invoice fraud describes the attack pattern and mitigations. citeturn1search0
The use of generative AI is not the only concern. The bigger shift is that attackers can produce tailored, polished and internally plausible messages at scale. A small business may receive fewer messages than a global enterprise, but a single successful payment request can have a material impact on cash flow.
This type of fraud also shows why email security cannot be treated as an IT-only issue. The control that stops the final payment is usually a finance policy, a second approval or a phone call to a known number. Technical tools are valuable, but they cannot replace a clear process for unusual payments.
Why it matters for businesses
Attackers are exploiting trust in executives, suppliers and familiar brands. A message can look grammatically correct, use accurate company details and include a realistic invoice, yet still be fraudulent. Australian businesses should also consider the potential consequences under internal fraud controls, privacy obligations, financial reporting requirements and cyber insurance conditions.
Practical recommendations
- Require two-person approval for changes to supplier bank details and for unusual or urgent payments.
- Verify payment requests using a trusted channel, such as a known phone number or an existing supplier portal.
- Configure SPF, DKIM and DMARC for company domains, and review impersonation and external sender protections.
- Train finance staff to inspect reply-to addresses, lookalike domains and requests to bypass normal approval steps.
- Make it acceptable for employees to pause a payment without penalty when a request feels unusual or urgent.
3. PaperCut attacks show how automation can compress the attack timeline
Security researchers at GreyNoise reported an AI-orchestrated campaign against PaperCut MF and NG, print management products used by schools, businesses and other organisations. The researchers said hundreds of AI agents were used to target at least 440 PaperCut instances belonging to 395 identified organisations in 48 countries. The campaign exploited two vulnerabilities for remote code execution and credential harvesting, with many victims concentrated in the education sector. GreyNoise’s campaign analysis describes the scale and speed of the activity. citeturn1search5
The story is important even for organisations that do not use PaperCut. It demonstrates how automation can turn a known vulnerability into a high-volume operational problem. Attackers no longer need to manually repeat every discovery, exploitation and validation step. Once a reliable attack path is available, automated tools can search for exposed systems and move rapidly from initial access to privileged control.
PaperCut issued an urgent security bulletin in late August covering the relevant vulnerabilities and patching guidance. Organisations that applied the updates still need to consider whether an attacker gained access before the fix was installed. PaperCut’s security bulletin sets out the affected products and emergency patch information. citeturn1search8
Why it matters for businesses
The risk is not limited to high-value applications. Attackers often enter through overlooked systems such as printers, remote management software, VPNs, cameras and building management platforms. These systems may have access to internal networks even when they do not store sensitive data themselves.
Practical recommendations
- Maintain an accurate inventory of every internet-facing application and appliance, including systems managed by external providers.
- Patch systems that are exposed to the internet before lower-risk internal applications.
- Review logs for unexpected administrator activity, new accounts, unusual downloads and connections to unfamiliar addresses.
- Segment printers, guest devices and operational technology from core servers and identity systems.
- Treat a late patch as a possible incident trigger and increase monitoring until the system has been checked.
4. A critical N-able flaw puts managed service environments in the spotlight
N-able released a hotfix for CVE-2026-86218, a critical pre-authentication remote code execution vulnerability affecting its N-central remote monitoring and management platform. The vendor urged customers to upgrade immediately. N-central is widely used by managed service providers, which means a weakness in the platform can create risk beyond one organisation and potentially expose multiple customer environments. N-able’s security update describes the vulnerability and the required hotfix. citeturn2search0
The incident is a reminder that businesses need to understand how their IT provider accesses systems. Remote management platforms are powerful by design. They can deploy software, run scripts, manage endpoints and make changes across many devices. If the platform or its administrator accounts are compromised, the attacker may inherit a broad set of capabilities.
This does not mean businesses should avoid managed service providers. It means the relationship needs the same level of scrutiny applied to internal privileged access. Organisations should know what tools are installed, who can use them, how access is protected and how quickly the provider will respond to a critical vulnerability.
Why it matters for businesses
Many small and mid-sized businesses rely on an MSP but do not have visibility of the tools used behind the scenes. A security incident at the provider can become a customer incident, particularly when remote access is persistent, shared or insufficiently monitored.
Practical recommendations
- Ask your MSP which remote monitoring and management platforms are connected to your environment.
- Confirm that critical hotfixes are applied to both hosted and on-premises management servers.
- Require MFA, named administrator accounts and least-privilege permissions for remote management access.
- Review provider access regularly and remove dormant accounts, unused integrations and unnecessary permissions.
- Include notification timeframes, evidence requirements and incident cooperation in your managed services agreement.
5. Vendor compromise continues to expose sensitive data
Healthcare technology company Veradigm disclosed that credentials stolen from a third-party vendor were used to access a limited company API and download patient information associated with some customers. Reports said the information may have included personally identifiable data, including Social Security numbers, while the investigation continued. The incident was reported in the United States, but the underlying lesson applies to organisations everywhere: data exposure can occur through a supplier that has legitimate access rather than through a direct attack on the main company. Healthcare IT News coverage outlines the reported access path and customer impact. citeturn2search1turn2search4
Third-party risk is especially relevant in Australia, where businesses often share information with payroll providers, accountants, marketing platforms, cloud applications, health service providers and outsourced IT teams. A supplier may not appear in the organisation’s own network diagrams, but it can still hold sensitive data or possess an identity that can reach important systems.
The lesson is not to complete a questionnaire once and file it away. Vendor risk changes when a provider adds a new integration, changes its hosting model, uses subcontractors or expands the data it stores. Contracts also need to cover incident notification, cooperation, retention, deletion and evidence of security controls.
Why it matters for businesses
A business may be held accountable for protecting information even when the incident occurs in a supplier’s environment. Customers usually care about whose data was exposed, not which company owned the server. Poor visibility can also delay notification, investigation and containment.
Practical recommendations
- Create a list of suppliers that store, process or can access business and customer data.
- Classify vendors by the sensitivity of the information and the level of system access they receive.
- Use MFA, separate service accounts and least privilege for integrations and supplier access.
- Ask critical suppliers how they detect stolen credentials, monitor API activity and investigate unusual downloads.
- Test your supplier incident process, including who must contact whom and how quickly access can be suspended.
What This Means For Your Business
The common thread across this week’s stories is speed. Vulnerabilities are being automated, scam messages are being produced at scale, remote management systems can extend an incident across multiple customers, and legitimate supplier access can provide a quiet route to sensitive information.
Business leaders do not need to build a large security operations centre to respond well. They do need a short list of priorities: know what is exposed, patch the systems that matter most, protect privileged access, require independent payment verification and understand which suppliers can reach business data.
Start with a practical 30-day review. Ask your IT team or provider to confirm the status of the latest Microsoft updates, identify internet-facing systems, review remote administration tools and check whether MFA is enabled for every privileged account. Ask your finance team to test its payment verification process using a realistic but harmless scenario.
Cybersecurity is not a one-off technology purchase. It is a set of business habits that reduce the chance of a serious incident and improve the organisation’s ability to recover when something goes wrong. Small, consistent improvements can make a significant difference when attackers are moving faster than ever.
Call Webwire on 08 9386 0053 or contact us at enquiries@webwire.com.au.