Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

SMB Cyber Intelligence Brief: donation sites, printing systems and file-sharing platforms in the firing line

What small and medium-sized businesses should look out for today.

High Friday 28 August 2026, 20:26 UK time
Today’s look-out: Web plugin and business-platform compromise leading to ransomware, data theft and follow-on phishing

What to look out for today

Today’s theme is common business tools being used as the entry point: website plugins (especially donations), file-sharing platforms, and print management systems. There’s also a fresh reminder that browser extensions can quietly steal credentials and funds.

  • WordPress donation sites: a reported maximum-severity flaw in the GiveWP donation plugin could allow attackers to run commands on the hosting server.
  • File-sharing platforms: an ownCloud issue has been added to CISA’s known-exploited list after being used in a real-world attack.
  • Print management (schools, charities, offices): PaperCut NG/MF is being actively targeted, with attackers chaining issues to execute code without authentication.
  • Business platforms: ServiceNow has warned of three maximum-severity vulnerabilities (relevant if you rely on ServiceNow for IT/workflows).
  • Browser extensions: multiple Chrome/Edge extensions were found with wallet-stealing / crypto-draining code (also a warning about extensions in general and credential theft).
  • Breach ripple effects: Hasbro disclosed an employee data breach — expect follow-on phishing using stolen personal/financial data themes.

Why this matters to smaller businesses

SMEs often depend on a small number of tools to run the business (website, donations, printing, service desk/workflows, shared files). When attackers get in via one of these, it can quickly become:

  • Ransomware/disruption (systems locked, printing and operations halted).
  • Data theft (donor details, employee data, customer files, invoices, HR documents).
  • Follow-on scams (invoice fraud, payroll diversion, “we’ve changed bank details”, fake IT support calls).
  • Supplier/SaaS knock-on impact if you outsource web hosting, print management, or platform administration.

Warning signs

  • Website donation pages behaving oddly: unexpected redirects, new admin users, unexplained plugin changes, sudden performance issues.
  • Print system issues: printers spooling jobs incorrectly, PaperCut server errors, new/unknown admin accounts, unusual outbound network traffic.
  • File-sharing anomalies: unexpected password resets, sharing links created without approval, access logs showing unusual locations.
  • ServiceNow (or similar workflow tools): unusual new integrations, changes to permissions/roles, unexpected data exports.
  • Browser symptoms: staff report new toolbars/extensions, persistent pop-ups, browser sessions logging out, unexplained account lockouts.
  • Phishing spikes mentioning HR/benefits, payslips, tax, or urgent employee verification (common after employee-data theft stories).

How attackers may exploit the situation

  • Compromise a public-facing plugin (e.g., donation plugin) and use the web server as a foothold to steal data, place skimmers, or pivot internally.
  • Break into file-sharing to access sensitive documents, then extort or use information for targeted fraud.
  • Take over print management to gain a trusted internal position, then deploy tools that lead to wider compromise and potential ransomware.
  • Exploit business platforms to tamper with workflows, approvals and data access (impacting procurement, IT, HR processes).
  • Use malicious extensions to steal credentials, session tokens or financial information — then reuse access in email, banking or SaaS services.

What to do today

  • Confirm ownership: identify who is responsible for WordPress (and key plugins), PaperCut, ownCloud/file-sharing, and ServiceNow administration (in-house or supplier).
  • Quick exposure check: are any of these systems internet-accessible? If yes, treat as urgent to review configuration and logging.
  • Review admin accounts: look for new/unused admin users in WordPress, PaperCut and file-sharing platforms; remove anything unrecognised.
  • Enable/verify MFA on admin portals and hosting panels; ensure recovery emails and phone numbers are correct.
  • Browser extension hygiene: ask staff to remove unused extensions; block unapproved extensions where possible (especially on finance/admin machines).
  • Reinforce phishing controls: remind staff that donation/IT/HR-related emails can be lures; confirm bank detail changes by phone using a known number.
  • Backups check: confirm you have recent, restorable backups for website and key servers (and that restore has been tested).

Ask your IT provider

  • Do we run GiveWP, PaperCut NG/MF, ownCloud, or ServiceNow anywhere (including for a single department or legacy server)? Who administers them?
  • Which of these are internet-facing, and what monitoring/alerting is in place for suspicious logins and privilege changes?
  • Can you show us a last 7-day admin change log review (new users, role changes, plugin changes, new integrations)?
  • What’s our ransomware containment plan if the website host / print server / file share is compromised (isolation steps, restoration order, communications)?
  • Do we have browser extension controls for staff devices, particularly finance and administrators?

Patch watch - only one short paragraph, and only if relevant

Several of today’s items relate to high-severity security issues in commonly used platforms (including GiveWP for WordPress, PaperCut, ownCloud and ServiceNow). Rather than treating this as a generic “patch everything” message, ask your IT support to confirm whether you use these products and, if you do, whether the relevant vendor fixes/hardening guidance have been applied and verified.

One action today

Ask your IT support (or web host) today to confirm whether your organisation uses GiveWP, PaperCut, ownCloud or ServiceNow and to provide written confirmation of the current mitigation/patch status plus evidence of recent admin/log review.

Related Actions On Cyber resource

CTA: Actions On Cyber – “Supplier & SaaS Risk Check” (quick questions to ask your IT provider/web host and what evidence to request)

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.