What to look out for today
- Business phone systems (VoIP/PBX) under active attack – reports of attackers exploiting a severe issue in Sangoma Switchvox to gain access without needing credentials.
- Remote access gateways being actively exploited – SonicWall has warned of active attacks against SMA1000 devices.
- Attackers abusing legitimate IT admin tools – phishing campaigns are using Faronics Deploy (a real endpoint management tool) to push remote-control software (ScreenConnect).
- Potential disruption from email security tooling – Microsoft Defender for Office 365 reportedly flagging legitimate Google Search links as malicious, which can break normal work and trigger “helpdesk” noise.
Why this matters to smaller businesses
SMEs rely heavily on telephony, remote access and outsourced IT tools. If an attacker gets into a phone system or remote access appliance, it can quickly lead to:
- Business disruption (phones down, staff unable to work remotely).
- Account takeover of admin portals and follow-on access to other systems.
- Fraud risk (redirected calls, voicemail access, social engineering using trusted numbers, and potential invoice/payment manipulation).
- Wider compromise if remote-control tools are installed on endpoints.
Warning signs
- Phones/VoIP behaving oddly: unexpected call forwarding, new extensions, voicemail PIN resets, or unusual outbound calling patterns.
- Unexpected remote-control prompts or a new “support” tool appearing (e.g. ScreenConnect) that nobody requested.
- Admin portal logins at unusual times, from unusual locations, or new admin accounts being created.
- Spike in security alerts/tickets about blocked Google Search links (may be false positives, but treat as disruption and verify).
- Staff reporting “IT” emails asking them to click links, run installers, or approve device management changes.
How attackers may exploit the situation
- Internet-exposed voice systems or remote access devices: attackers target them directly to gain an initial foothold.
- Living-off-the-land with legitimate tools: rather than using obvious malware, criminals use real admin/deployment software to push remote access, blending into normal IT activity.
- Phishing to trigger “approved” installs: a convincing email lures a user into enabling a management agent or accepting an update, after which remote-control software is deployed.
- Noise as cover: widespread security false positives can distract IT teams, making it easier for real malicious activity to slip through during the confusion.
What to do today
- Confirm ownership of your business telephony: who supports it, where it’s hosted, and whether it is exposed to the internet.
- Review remote access exposure: identify whether you use SonicWall SMA1000 (or any similar remote access gateway) and who manages it.
- Hunt for unexpected remote-control installs: ask IT to quickly check endpoints for newly installed remote support tools that weren’t requested.
- Set a staff message for today: “Don’t install ‘support’ software or approve device management changes from email. If in doubt, call our known IT contact number.”
- Manage Defender disruption safely: if Google links are being blocked, route staff to use approved bookmarks/known URLs while IT verifies whether alerts are false positives.
Ask your IT provider
- Do we run Sangoma Switchvox anywhere (including at a branch/warehouse), and is it internet-facing?
- Do we use SonicWall SMA1000 (or is it part of our MSP stack)? What extra monitoring is in place for attempted compromise?
- What controls do we have to prevent legitimate admin tools (e.g. deployment platforms) being abused to install remote-control software?
- Can you provide a list of approved remote support tools for our business, and an alerting process for any new/unknown tools appearing?
- If Defender for Office 365 is blocking legitimate links, what’s our verified workaround that doesn’t involve weakening security?
Patch watch - only one short paragraph, and only if relevant
Today’s reporting includes active exploitation warnings for business voice and remote access platforms. Even if you don’t manage patches in-house, ensure your provider can confirm whether you’re affected and what immediate mitigations (including exposure reduction and monitoring) are in place while fixes are applied.
One action today
Send a same-day staff note: “Do not install or approve any ‘IT support’ software from email or chat—call our known IT number instead,” and ask IT to check for any new/unauthorised remote-control tools installed in the last 7 days.
Related Actions On Cyber resource
Actions On Cyber checklist: “Remote access & support tools control (approved tools list + install alerts + staff reporting script)”
Sources
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials (The Hacker News)
- SonicWall warns of actively exploited SMA1000 zero-day flaws (BleepingComputer)
- Hackers abuse Faronics Deploy admin tool to install ScreenConnect (BleepingComputer)
- Microsoft Defender flags legitimate Google search links as malicious (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.