SMB cybersecurity
44 stories on SMB cybersecurity, newest first, from 44 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting.
- AI Agents Are Multiplying Faster Than Businesses Can Track Them
- AI Agents Escaping Their Sandboxes? Old Access Failures Are To Blame
- Fake HR Desktop Apps Trick Staff Into Handing Over Remote Access
- Hackers Are Poisoning AI Chatbot Answers to Spread Phishing Links
- Why Small Businesses Should Think of Their Network as a Security Tool, Not Just Plumbing
- New 'Exvicy' ClickFix Toolkit Spreads Malware Through Hacked WordPress Sites
- Why Knowing Who Has Access Is the New Frontline of Cyber Defence
- New Android Malware 'RatHat' Uses AI and Debug Tools to Keep Control After Uninstall
- Attackers Exploit New Flaws in Days, Businesses Take Weeks to Patch: Why Pentesting Needs to Change
- Cheap Malware-as-a-Service Kit Puts Windows Businesses at Risk
- AI Rollouts Outpacing Basic Permission Checks, Study Finds
- New Android Malware 'MantaxOtax' Locks Phones While Stealing Personal Data
- Shadow AI: The Hidden Risk Lurking in Your Business Tools
- Why Fixing Vulnerabilities in Code Beats Patching in Production
- Why AI 'Rules' Aren't Enough: Lessons from a Real-World Agent Attack
- AI Agents Need Guardrails: Lessons from the Hugging Face Access Incident
- Ransomware Gang Weaponises Popular AI Coding Tool in Fresh Attacks
- White-Label Routers Made in China Found With Built-In Backdoors
- AI Is Speeding Up Cyberattacks — Is Your Security Ready to Keep Pace?
- Car Infotainment Systems Targeted by Android Malware Botnet
- CISA Report: Most Cyberattacks Exploit Basic, Known Software Flaws
- MFA Isn't a Silver Bullet: Why Multi-Factor Authentication Can Still Let Attackers In
- Critical Login Bypass Flaws Found in Popular WordPress SSO Plugin
- The Hidden Danger of AI 'Super-Users' in Your Business
- Hackers Are Now Targeting the Tools Behind Your Software, Not Just the Code
- CISA Flags Two Actively Exploited TrueConf Server Vulnerabilities
- 'Shady AI' Emerges as a Major Governance Risk for Businesses
- Researchers Warn AI Coding Agents Can Catch and Spread 'Mind Viruses'
- New Linux Botnet 'Evooo1Bot' Turns Hacked Devices Into Attacker Toolkits
- Weekly Threat Recap: Old Bugs, Exposed Services and Browser Hijacks Keep Costing Businesses
- How AI Is Learning to Think Like a Security Analyst
- Supply Chain Attack on LiteLLM Hits Over 2,500 Organizations
- Ivanti Patches Remotely Exploitable Flaws in Endpoint Manager
- Malicious Chrome Extension Sneaks Back Into Web Store After Ban
- AI Coding Assistants Tricked Into Leaking Secrets via 'Split Instruction' Attacks
- 'Ghostjacking': How Hackers Trick AI Security Tools by Poisoning Their Own Logs
- CrowdStrike Uncovers Hackers Hiding Malicious Commands on VMware ESX Servers
- Critical Flaw in Paperclip Software Could Have Let Attackers Seize Admin Control
- Fake 'ClickFix' Sites Now Screen Visitors Before Delivering Mac Malware
- New Phishing Kit 'Kali365' Tricks Users Into Approving Attacker Logins on Real Microsoft Pages
- Why Traditional Security Tools Aren't Enough to Manage AI Risk
- AI Email Assistants Could Become Tools for Hackers, Researchers Warn
- Anthropic: AI Security Incidents Traced to Access Controls, Not Faulty Models
- Cheap Streaming Boxes Could Be Turning Your Business Wi-Fi Into a Fraud Machine