Webwire Pty Ltd - Four Cyber Risks Small Businesses Need to Act On This Week

The latest cybersecurity news reveals four practical risks for SMEs, from fake IT support and phishing evasion to malware downloads and zero-day remote access flaws.

 · 7 min read

Four Cyber Risks Small Businesses Need to Act On This Week

Cybersecurity news this week has a clear message for small and mid-sized organisations: attackers are not waiting for a major technical weakness. They are looking for trusted tools, rushed decisions and gaps in everyday business processes.

From fake IT support contacts in Microsoft Teams to zero-day flaws in remote access appliances, the latest incidents show why governance, patching and business continuity belong in the same conversation. The good news is that practical improvements can make a measurable difference without requiring a large security team.

1. Fake IT support contacts are turning collaboration tools into attack paths

According to recent Microsoft threat intelligence research, attackers are using external Microsoft Teams conversations to impersonate IT or helpdesk staff. The victim is persuaded to approve a remote support session, often through a legitimate tool such as Quick Assist or another remote management application.

Once access is granted, the attacker can use PowerShell, Windows Installer and other trusted tools to place malware on the device. The observed activity then moved into reconnaissance, screenshot capture and lateral movement through Windows administrative protocols. In practical terms, a convincing conversation can become a pathway to high-value systems such as identity infrastructure and file servers.

This matters to smaller businesses because external collaboration is now part of normal operations. Employees may receive Teams messages from customers, suppliers, contractors and technology providers every day. A small organisation may also rely on one or two people who perform several IT roles, making it easier for an attacker to sound credible.

The incident is a reminder that identity security is not only about passwords. It is also about verifying who is asking for access, why they need it and whether the request fits an approved process.

Practical actions:

  • Create a simple helpdesk verification phrase or ticket number that staff must request before granting remote access.
  • Train employees never to approve remote control, run PowerShell commands or install software because of an unsolicited chat or phone call.
  • Review external access settings in Microsoft Teams and limit contact from untrusted domains where business needs allow.
  • Require multifactor authentication and managed-device checks for administrative access.
  • Alert on remote support tools followed by PowerShell, MSI installation, command prompt activity or unusual WinRM connections.

Read the Microsoft analysis of the Teams support impersonation campaign for technical detail and detection guidance.

2. Invisible characters are helping phishing messages evade filters

A recent Microsoft research report highlighted a high-volume phishing campaign that used invisible Unicode characters to split important words inside email messages. The messages looked normal to recipients, but the hidden characters could interfere with simple keyword matching and some text-processing systems.

The campaign used financial lures involving business funding, loans and credit lines. That makes the activity especially relevant to small businesses, which are often targeted with urgent offers for working capital, invoice funding or account services. The messages were also delivered through legitimate email marketing infrastructure, demonstrating why sender reputation alone is not enough to establish trust.

The broader trend is important. Attackers are adapting techniques associated with AI security and applying them to traditional phishing. As more organisations use automated filters, language models and workflow tools to process email, attackers will continue looking for differences between what a human sees and what a security system reads.

For business leaders, this is not a reason to distrust every automated security control. It is a reason to use layered controls and avoid relying on one signal, such as a suspicious keyword or sender domain.

Practical actions:

  • Keep email security, anti-phishing and attachment protection enabled and up to date.
  • Ensure staff verify financial requests through a known phone number or established business contact.
  • Use payment approval processes that require a second person for changes to bank details, supplier accounts or urgent transfers.
  • Teach employees to inspect the full message context, including sender domain, links, urgency and unusual requests.
  • Ask your email security provider whether it normalises invisible characters and look-alike text during inspection.

For additional context, see the Microsoft research on ASCII smuggling and phishing evasion.

3. Fake software downloads are still a serious business continuity risk

Microsoft also reported an active malware campaign built around counterfeit software download websites. The sites imitate trusted brands and offer installers or archives that appear legitimate. Once executed, the malware attempts to establish persistence, weaken security protections and communicate with attacker-controlled infrastructure.

The campaign has been observed across healthcare, manufacturing, technology, logistics, government and education. Although much of the reported activity involved Chinese-speaking users and China-based operations, the delivery method is global. Any employee searching for a popular application, utility or browser extension can be directed to a look-alike download page.

This is more than an endpoint security issue. A compromised workstation can become the starting point for stolen credentials, disrupted operations, unauthorised access to shared files and costly incident response. If the attacker disables security tools or removes recovery information, the event can quickly become a business continuity problem.

Smaller organisations should pay particular attention to informal software installation. Employees may download tools to solve an immediate business problem, while managers may not know which applications are installed across the environment. That creates an unmanaged supply chain inside the business.

Practical actions:

  • Maintain an approved software list and make it easy for staff to request legitimate applications.
  • Restrict local administrator rights wherever possible.
  • Enable endpoint protection features such as web filtering, tamper protection and protection against potentially unwanted applications.
  • Block or quarantine executable files downloaded from untrusted websites and cloud storage locations.
  • Review endpoint alerts for security exclusions, suspicious scheduled tasks, unusual installers and unexpected command-line activity.
  • Include software downloads in staff security training, not just email phishing exercises.

The Microsoft investigation into counterfeit installers includes useful examples of the attack chain and mitigation priorities.

4. Remote access appliances remain a high-priority patching issue

On September 2, SecurityWeek reported that SonicWall had warned customers about two zero-day vulnerabilities affecting certain SMA1000 secure remote access appliances. The flaws were being exploited in the wild and could be chained to enable unauthorised remote code execution. The affected models included the 6210, 7210 and 8200v, while other SonicWall products were not affected according to the report.

The key lesson is not limited to SonicWall customers. Remote access gateways, firewalls, virtual private network appliances and other internet-facing systems are attractive targets because they sit at the edge of the business. A compromise can provide an attacker with a direct route into internal systems, often before endpoint controls have an opportunity to respond.

For a small business, the challenge is visibility. The device may be managed by an external IT provider, installed years ago or treated as part of the network rather than as a critical business system. Patch decisions can also be delayed because administrators fear service interruption.

That approach creates a larger risk. A planned maintenance window is usually easier to manage than an emergency response after an internet-facing device has been compromised.

Practical actions:

  • Maintain an accurate inventory of firewalls, VPNs, remote access gateways and other internet-facing devices.
  • Subscribe to vendor security advisories and define an urgent patching process for actively exploited flaws.
  • Confirm which party is responsible for patching managed network equipment and how quickly they must act.
  • Restrict management interfaces to approved networks, administrators and strong authentication methods.
  • Review logs for unusual administrator access, configuration changes, new accounts and unexpected outbound connections.
  • Keep an offline or otherwise isolated configuration backup so a compromised appliance can be rebuilt quickly.

SecurityWeek’s report on the SonicWall SMA1000 zero-days provides the affected product details and patch information.

What this means for your business

The common thread across this week’s news is that cyber risk now sits inside ordinary business activity. A Teams message can become a remote access incident. A finance email can bypass a simple filter. A software download can create persistence on a workstation. An unpatched gateway can expose the whole network.

That means governance does not need to be complicated to be useful. Start by identifying the systems that would stop the business if they were unavailable, compromised or locked. For many organisations, that list includes identity and email, accounting platforms, customer databases, file storage, internet connectivity and remote access services.

Then assign clear owners and define the minimum controls for each area. Those controls should include multifactor authentication, tested backups, timely patching, restricted administrator access, supplier responsibilities and a practical incident response plan. Your plan should state who makes decisions, who contacts customers, who speaks to insurers and who coordinates with IT specialists or law enforcement.

Finally, test the plan. Ask staff what they would do if an external person claimed to be from IT, if a supplier requested a bank account change or if the main network gateway had to be taken offline. Short exercises often reveal gaps that a policy document will not.

Businesses do not need to predict every attack. They need enough visibility, discipline and recovery capability to make common attacks harder and incidents less disruptive.

Call Webwire on 08 9386 0053 or contact us at enquiries@webwire.com.au.