What to look out for today
Today’s main SME lookout is identity and communications platforms being actively targeted, plus the usual follow-on: phishing, account takeovers, and supplier-style scam messages that exploit uncertainty after security news.
- Microsoft Entra ID: Microsoft has warned of a maximum-severity issue that has been exploited in attacks.
- Self-hosted comms: TrueConf Server flaws are being treated as actively exploited (US agencies told to prioritise fixes).
- Third-party software ripple effects: A breach at a large organisation (SickKids) exposed employee/applicant data via third-party software, highlighting how HR-style data can leak even when “core systems” are unaffected.
- Malware delivery tricks: New reporting shows attackers abusing FTP server “banners” to deliver Windows malware (a reminder that older admin services and tooling can be a weak link).
Why this matters to smaller businesses
- Identity is the front door: If an attacker can compromise sign-in/identity controls, they often don’t need to “hack” anything else to get into email, files, finance approvals, and customer data.
- Comms platforms are high-impact: A compromise of conferencing/chat can quickly lead to internal impersonation, stolen meeting links, or surveillance of sensitive conversations.
- Third-party incidents create believable scams: When a well-known organisation reports a breach, criminals commonly send “update your details / re-verify payroll / download a form” messages to staff and applicants.
Warning signs
- Unexpected sign-in prompts, MFA fatigue requests, or “urgent” verification messages for Microsoft 365/Entra-linked accounts.
- New or unknown admin accounts, new MFA methods added, or changes to conditional access/security settings you didn’t request.
- Unusual meeting invites, chat messages, or “support” outreach referencing conferencing tools or comms upgrades.
- Emails/SMS claiming to be from HR/recruitment asking you to re-enter personal details or download “updated application documents”.
- Unexpected outbound traffic from servers that host legacy services (e.g., FTP) or odd behaviour on a server that “never changes”.
How attackers may exploit the situation
- Account takeover to access email, then invoice fraud, payroll diversion, or supplier payment-change scams.
- Abuse of comms platforms to impersonate colleagues/IT support and push links or “security tools”.
- Targeting externally reachable servers (especially self-hosted communications or older admin services) to gain a foothold and deploy remote access tooling.
- Data-breach themed phishing using real brand names and plausible context (“you were affected”, “download your report”, “confirm your details”).
What to do today
- Tell staff what’s happening: a short internal note: “expect fake Microsoft/security and HR-style messages; do not approve unexpected MFA prompts; report anything urgent/odd.”
- Check admin access: confirm who has Entra/M365 admin roles, review recent changes to roles/MFA methods, and remove stale accounts.
- Review sign-in alerts: look for unfamiliar locations/devices, repeated failed logins, and sign-ins outside working patterns—especially for finance and administrators.
- Verify internet-facing services: if you run self-hosted comms (e.g., TrueConf) or legacy services like FTP, confirm they are still required and monitored.
- Reinforce payment controls: insist on call-back verification for any change of bank details, even if it appears to come from a known email thread.
Ask your IT provider
- Are we affected by the reported Entra ID exploited issue, and what mitigations/updates have been applied or verified?
- Do we have any internet-exposed communications servers (including self-hosted conferencing), and are they monitored with alerting?
- What is our process to detect and respond to new admin accounts, new MFA methods, and suspicious mailbox rules?
- Can you provide a weekly report of high-risk sign-ins and privileged role changes?
- Do we still need services like FTP; if yes, how are they logged and protected?
Patch watch - only one short paragraph, and only if relevant
Some of today’s reporting references actively exploited issues in widely used platforms (notably Microsoft Entra ID and a self-hosted communications product). If you rely on these, treat this as an urgent prompt to confirm your provider has applied vendor fixes/mitigations and validated sign-in and admin-change monitoring.
One action today
Send a same-day staff warning: “Do not approve unexpected MFA prompts or ‘account re-verify’ requests; report suspicious Microsoft/HR/security messages immediately.”
Related Actions On Cyber resource
CTA: Use the Actions On Cyber ‘Payment change / invoice fraud call-back checklist’ for finance teams
Sources
- Microsoft warns of max severity Entra ID flaw exploited in attacks (BleepingComputer)
- CISA orders feds to patch actively exploited TrueConf Server flaws (BleepingComputer)
- SickKids data breach exposes employee and job applicant info (BleepingComputer)
- Hackers abuse FTP server banners to deliver new Windows malware (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.