What to look out for today
Three themes to brief staff and IT on today:
- Ransomware groups publicly claiming data theft and using leak sites to pressure victims into paying.
- Network edge / router compromise being used for spying and credential theft (especially where routers are managed by an MSP/telecoms provider).
- Malware disguised as legitimate tools that relies on users being convinced to add it to antivirus exclusions or “allow lists”.
Why this matters to smaller businesses
- Ransomware is rarely just encryption now—data theft and extortion can create legal, reputational and customer-notification issues even if operations keep running.
- Routers and network access systems are a single point of failure. If compromised, attackers may intercept traffic, steal credentials, and undermine security monitoring—often without obvious signs to end users.
- “Just add an exception” is a common turning point in real incidents. Once a user weakens security controls, attackers gain persistence and can move toward email compromise, invoice fraud, or ransomware.
Warning signs
- Unexpected or urgent requests to disable antivirus, add exclusions, or run “signed/legitimate” software to fix a problem.
- Unplanned network changes: new remote access paths, unexplained configuration updates, or connectivity behaving oddly (intermittent access, sudden routing/VPN changes).
- Extortion indicators: unusual emails claiming stolen data, threats to publish files, or references to a “leak site”.
- Security tooling seems “quiet”: fewer alerts than normal, missing logs, or monitoring gaps reported by your IT provider.
How attackers may exploit the situation
- Ransomware operators may break in, steal data, then apply pressure via public claims and direct extortion messages—aiming to force rapid payment decisions.
- Router and authentication infrastructure compromise can be used to capture admin credentials, watch traffic, and reduce your ability to detect what’s happening.
- Signed or “trust-looking” apps (e.g., utilities/adware bundled as helpful tools) are used to persuade staff to override controls—making endpoint protection less effective.
What to do today
- Reinforce a simple rule: staff must not add antivirus exclusions, disable protection, or install “fix tools” based on an email/call/chat message—route all such requests through IT.
- Confirm your backups and recovery plan (what you can restore, how quickly, and who approves a restore). Ensure at least one backup copy is protected from tampering.
- Check who manages your router/firewall (in-house, MSP, telecoms). Make sure device admin accounts are controlled, monitored and not shared broadly.
- Prepare for extortion messaging: decide who triages suspicious claims (IT + leadership + legal/insurer as appropriate) so staff don’t engage ad hoc.
Ask your IT provider
- Which routers/firewalls do you manage for us, and how do you monitor for unusual tunnels/remote access and configuration changes?
- Do we have central logging for network devices and admin activity, and how quickly would we notice if logging went missing?
- What controls stop users (or attackers) from adding antivirus exclusions or disabling protections without approval?
- If we received an extortion email today, what is our first-hour response (isolation steps, evidence preservation, and who contacts the insurer)?
Patch watch - only one short paragraph, and only if relevant
Separately, Microsoft has acknowledged a Windows 11 update issue that can reset mouse settings. It’s not a security alert, but if your IT team uses the August preview updates, be prepared for user support tickets and consider whether preview updates are appropriate on business devices.
One action today
Send a same-day staff note: “Do not disable antivirus or add exclusions/install ‘fix tools’ from emails or calls—forward to IT/helpdesk immediately.”
Related Actions On Cyber resource
Actions On Cyber checklist: Ransomware readiness (backups, first-hour response, and extortion triage)
Sources
- Berlin confirms data theft after Rhysida ransomware attack claims (BleepingComputer)
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs (The Hacker News)
- Chinese Fire Ant hackers turn Cisco routers into spying platforms (BleepingComputer)
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions (The Hacker News)
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets (The Hacker News)
- Microsoft says Windows 11 KB5120998 update resets mouse settings (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.