News & announcements

Practical tips, field stories and announcements about cybersecurity, NIS2 compliance and security systems.

openai-fake-invoice

Fake emails sent in the name of OpenAI claim that the ChatGPT subscription payment "failed" and ask recipients to update their credit card information in order to steal their account password through a fake login page.

Read the article →

accelerate-exploitation

A Google report shows that artificial intelligence is changing the landscape of cybersecurity: it is not secret breaches that pose the main threat to a small business, but rather the speed at which a fix becomes an attack.

Read the article →

fake-ChatGPT-from-ads

A "ChatGPT" that you access through a Google ad may be fake: it sends you to a "fallback domain" where you end up running a command yourself that installs malware.

Read the article →

fake-call-money-laundering

The DNSC is warning of a phone scam in which attackers pose as financial analysts from the ONPCSB and accuse the victim of being involved in a money-laundering investigation.

Read the article →

what-does-the-agent-see

Meta has launched “Muse for Small Business,” an AI agent that connects not only to Instagram and Facebook, but also to accounting, e-commerce, and payments—it’s useful, but it matters what it sees and who activates it.

Read the article →

apple-bresa-exploited

Apple has fixed a security vulnerability in macOS that was already being exploited in attacks and that could give an attacker control over a computer simply by opening a file.

Read the article →

open-database

Custom-built applications, forms, and online stores rely on a customer database—which, without the proper access rules, can be viewed by anyone on the internet.

Read the article →

the-account-you-stole

The login credentials for an AI assistant account can be stolen from an infected computer, and along with them go all your conversations and everything you've connected to the assistant.

Read the article →

false-support-by-ai

An AI assistant might give you a scammer's number, claiming it's the "official support" number for your bank or software provider—a campaign is tampering with the sources the AI reads.

Read the article →

roundcube-webmail-attack

Roundcube Webmail, which is included in many hosting control panels, has an actively exploited vulnerability that can expose email account passwords and company messages.

Read the article →

September Retrospective

Monthly Recap: Attackers didn't hack software; they just borrowed names you trust, and the serious breaches occurred at your providers, not at your end.

Read the article →

ransomware-accountants

DNSC and CECCAR warn that a ransomware campaign is now targeting accounting firms in Romania — here's how it works and what you can do to avoid becoming the next victim.

Read the article →

cpanel-databases

A critical vulnerability in cPanel (CVE-2026-58048) allows a standard hosting account to access the databases of other customers on the same server. A fix is already available.

Read the article →

antivirus-blocked-defender

The Windows antivirus can be silently disabled, leaving the computer with protection that is only apparent—a direct risk for companies that rely exclusively on the free protection provided by Windows

Read the article →

wordpress-core-rce

A WordPress site can be taken over by an attacker without a password: a critical vulnerability in the WordPress core is already being exploited in real-world attacks, and a fix is available in version 7.1.2.

Read the article →

Patch Tuesday - September

Microsoft has fixed nearly 1,000 vulnerabilities in a single update package, and two of them are already being exploited in real-world attacks—here's what a small business needs to do.

Read the article →

dlink router

D-Link DIR-822A routers have a vulnerability rated at the highest severity level, with publicly available exploit code, and the manufacturer has not yet released a fix: an attacker can take control of the router without a password.

Read the article →

package-fraud-text-messages

The DNSC has renewed its warning about an active scam via text message and WhatsApp carried out in the name of courier companies—here’s how it works and what simple rule keeps your team safe.

Read the article →

the-browser-assistant

The browser gets an AI assistant that browses for you—and runs with all your accounts open. A command hidden on a page can instruct it.

Read the article →

wordpress-elementor

WordPress sites built with Elementor Pro can be compromised by attackers through a vulnerability in the form module. The fix is to update the plugin to version 4.2.2.

Read the article →

zyxel-network-switch

Zyxel's GS1900 series managed switches have a vulnerability that is actively being exploited in attacks: an attacker on the same network can take control of the device without a password.

Read the article →

MikroTik router

MikroTik routers at the network edge are being compromised by attackers remotely and without a password. The "MikroTrick" attack chain is already being used in real-world attacks, and the fix is a simple update.

Read the article →

fortinet-fortios-pivotc2

FortiGate firewalls at the network edge are being compromised by attackers through a vulnerability in FortiOS that does not require a password. The vulnerability is being actively exploited, and the fix is an update.

Read the article →

m365-direct-send

An email that appears to be from the accounting department or the company’s CEO, using your actual email address, can be sent by attackers without them having to hack into any account—using a feature in Microsoft 365.

Read the article →

bank-email-fraud

A phishing email campaign is circulating in the name of Exim Banca Românească: the message asks recipients to confirm their account under threat of having their card suspended, and the DNSC has issued an alert.

Read the article →

woocommerce-store

A popular plugin for WooCommerce stores, "Wholesale Lead Capture," has a vulnerability that is actively being exploited: attackers can upload a PHP file and take over the entire site.

Read the article →

your-it-provider

An IT company remotely manages your computers using a single tool. When that tool has a serious security breach, the risk extends to your company—here’s what to ask.

Read the article →

compliance-processing-register

Article 30 of the GDPR requires your company to provide a table listing the personal data it holds. It takes about 30 minutes to prepare, and it’s one of the first documents requested during an audit.

Read the article →

screenconnect-remote-support

The ScreenConnect remote support tool has a vulnerability that has already been exploited in attacks, some of which have spread like a worm: during a session, an attacker can send and run a file on a computer without co

Read the article →

browser-extension-ai

Researchers have demonstrated how a single browser extension can take control of the AI assistant built into Chrome, Edge, Comet, Opera Neon, and the Claude extension in Chrome, causing it to act on your behalf.

Read the article →

acronis-backup-cpanel

The Acronis backup plugin for cPanel & WHM has a vulnerability that has already been exploited in targeted attacks: an account with limited privileges on the server can gain full control on Linux (CVE-2026-87886).

Read the article →

issabel-call-center

The Issabel PBX system has a critical vulnerability that has already been exploited in attacks (CVE-2026-89026): an attacker can execute commands on the server without a username or password.

Read the article →

vishing-cloned-voice

An employee receives a call that appears to be from their boss or the bank, requesting an urgent transfer. Using artificial intelligence, the voice can be cloned from just a few seconds of publicly available audio, and the call

Read the article →

ai-addons-impersonation

Add-ons that extend AI tools—such as “skills,” plugins, GPTs, and extensions—can mimic well-known names to appear trustworthy, and once installed, they run with your permissions.

Read the article →

phishing-domain-expiration

An email that impersonates your domain provider and warns you that “your domain is about to expire” may be a scam designed to steal your credit card information.

Read the article →

chrome-zero-day

An emergency update for Google Chrome fixes a vulnerability that has already been exploited in real-world attacks: all it takes is opening a malicious web page.

Read the article →

Checklist: The First Day Back from Vacation

The first day back from vacation is a scammer’s favorite day: a full inbox, a rush to catch up, and a lack of focus—the perfect conditions for a fake payment request. Seven checks made on the first morning of September, before

Read the article →

t1

Antivirus software does not make you NIS2-compliant. Not by a long shot.

Read the article →