Fake emails sent in the name of OpenAI claim that the ChatGPT subscription payment "failed" and ask recipients to update their credit card information in order to steal their account password through a fake login page.
A Google report shows that artificial intelligence is changing the landscape of cybersecurity: it is not secret breaches that pose the main threat to a small business, but rather the speed at which a fix becomes an attack.
A "ChatGPT" that you access through a Google ad may be fake: it sends you to a "fallback domain" where you end up running a command yourself that installs malware.
The DNSC is warning of a phone scam in which attackers pose as financial analysts from the ONPCSB and accuse the victim of being involved in a money-laundering investigation.
Meta has launched “Muse for Small Business,” an AI agent that connects not only to Instagram and Facebook, but also to accounting, e-commerce, and payments—it’s useful, but it matters what it sees and who activates it.
Apple has fixed a security vulnerability in macOS that was already being exploited in attacks and that could give an attacker control over a computer simply by opening a file.
Custom-built applications, forms, and online stores rely on a customer database—which, without the proper access rules, can be viewed by anyone on the internet.
The login credentials for an AI assistant account can be stolen from an infected computer, and along with them go all your conversations and everything you've connected to the assistant.
An AI assistant might give you a scammer's number, claiming it's the "official support" number for your bank or software provider—a campaign is tampering with the sources the AI reads.
Roundcube Webmail, which is included in many hosting control panels, has an actively exploited vulnerability that can expose email account passwords and company messages.
Monthly Recap: Attackers didn't hack software; they just borrowed names you trust, and the serious breaches occurred at your providers, not at your end.
DNSC and CECCAR warn that a ransomware campaign is now targeting accounting firms in Romania — here's how it works and what you can do to avoid becoming the next victim.
A critical vulnerability in cPanel (CVE-2026-58048) allows a standard hosting account to access the databases of other customers on the same server. A fix is already available.
The Windows antivirus can be silently disabled, leaving the computer with protection that is only apparent—a direct risk for companies that rely exclusively on the free protection provided by Windows
A WordPress site can be taken over by an attacker without a password: a critical vulnerability in the WordPress core is already being exploited in real-world attacks, and a fix is available in version 7.1.2.
Microsoft has fixed nearly 1,000 vulnerabilities in a single update package, and two of them are already being exploited in real-world attacks—here's what a small business needs to do.
D-Link DIR-822A routers have a vulnerability rated at the highest severity level, with publicly available exploit code, and the manufacturer has not yet released a fix: an attacker can take control of the router without a password.
The DNSC has renewed its warning about an active scam via text message and WhatsApp carried out in the name of courier companies—here’s how it works and what simple rule keeps your team safe.
WordPress sites built with Elementor Pro can be compromised by attackers through a vulnerability in the form module. The fix is to update the plugin to version 4.2.2.
Zyxel's GS1900 series managed switches have a vulnerability that is actively being exploited in attacks: an attacker on the same network can take control of the device without a password.
MikroTik routers at the network edge are being compromised by attackers remotely and without a password. The "MikroTrick" attack chain is already being used in real-world attacks, and the fix is a simple update.
FortiGate firewalls at the network edge are being compromised by attackers through a vulnerability in FortiOS that does not require a password. The vulnerability is being actively exploited, and the fix is an update.
An email that appears to be from the accounting department or the company’s CEO, using your actual email address, can be sent by attackers without them having to hack into any account—using a feature in Microsoft 365.
A phishing email campaign is circulating in the name of Exim Banca Românească: the message asks recipients to confirm their account under threat of having their card suspended, and the DNSC has issued an alert.
A popular plugin for WooCommerce stores, "Wholesale Lead Capture," has a vulnerability that is actively being exploited: attackers can upload a PHP file and take over the entire site.
An IT company remotely manages your computers using a single tool. When that tool has a serious security breach, the risk extends to your company—here’s what to ask.
Article 30 of the GDPR requires your company to provide a table listing the personal data it holds. It takes about 30 minutes to prepare, and it’s one of the first documents requested during an audit.
The ScreenConnect remote support tool has a vulnerability that has already been exploited in attacks, some of which have spread like a worm: during a session, an attacker can send and run a file on a computer without co
Researchers have demonstrated how a single browser extension can take control of the AI assistant built into Chrome, Edge, Comet, Opera Neon, and the Claude extension in Chrome, causing it to act on your behalf.
The Acronis backup plugin for cPanel & WHM has a vulnerability that has already been exploited in targeted attacks: an account with limited privileges on the server can gain full control on Linux (CVE-2026-87886).
The Issabel PBX system has a critical vulnerability that has already been exploited in attacks (CVE-2026-89026): an attacker can execute commands on the server without a username or password.
An employee receives a call that appears to be from their boss or the bank, requesting an urgent transfer. Using artificial intelligence, the voice can be cloned from just a few seconds of publicly available audio, and the call
Add-ons that extend AI tools—such as “skills,” plugins, GPTs, and extensions—can mimic well-known names to appear trustworthy, and once installed, they run with your permissions.
An email that impersonates your domain provider and warns you that “your domain is about to expire” may be a scam designed to steal your credit card information.
An emergency update for Google Chrome fixes a vulnerability that has already been exploited in real-world attacks: all it takes is opening a malicious web page.
You have security cameras, but the problem arises exactly when you need them: the footage is of no use. A cheap, poorly chosen, and unmonitored camera only provides a false sense of security, and that
The first day back from vacation is a scammer’s favorite day: a full inbox, a rush to catch up, and a lack of focus—the perfect conditions for a fake payment request. Seven checks made on the first morning of September, before
They had an eight-month-old backup. On the day it mattered, nothing was restored. This is the most costly lesson we see small businesses learn: a backup that’s running doesn’t mean a backup that works
Antivirus software does not make you NIS2-compliant. This is the most common misconception we hear from small business administrators: “We have antivirus software and a firewall, so we’re covered.” Compliance does not
An active campaign uses fake download sites—clones of software manufacturers' websites—to distribute installers that disable Windows Update and weaken Microsoft Defender.
A page that asks you to “confirm that you’re human” by opening PowerShell and pasting a command isn’t a verification—it’s a widespread scam called ClickFix.
Three different attacks this month all ended the same way: someone logged in using a password that didn't belong to them. The basic password policy and two-step authentication fit on a single page and cost almost
The security firm ReliaQuest has documented an ongoing campaign in which attackers take control of Wi-Fi routers and gateways in hotels and conference centers and change their DNS settings to redirect
On July 27, 2026, the U.S. agency CISA added a new vulnerability in FortiOS—the system that runs on FortiGate firewalls, which are used by m—to its list of actively exploited vulnerabilities.
Researchers at Guardio Labs have discovered a vulnerability (called HermeticReader) in the official Adobe Acrobat extension for Chrome—one of the most widely used extensions in the world, with about 300 million
A phishing campaign called SeasonalInvite, documented by the security firm Forescout, reveals a dangerous trend for small businesses: the bait is no longer an “infected” file, but a friendly email
Three different attacks this month could have ended the same way: with the company's files encrypted or deleted. When prevention fails, a tested 3-2-1 backup is what gets the company back on its feet.
Two vulnerabilities in the WordPress core, collectively known as wp2shell (CVE-2026-63030 and CVE-2026-60137), allow a site to be completely taken over with a single request, without a password. This isn’t related to any plugin...
Mozilla has fixed two critical vulnerabilities in Firefox and has openly stated that exploit code for both is already public. On the same day, Google fixed 15 issues in Chrome, two of which
SonicWall confirms that two vulnerabilities in SMA 1000 devices are currently being exploited, and CISA added them to its list of actively exploited vulnerabilities on July 14. For companies that
A wave of ransomware is now hitting small businesses in Europe, starting with an email that appears to be sent by Interpol and claims that the company is under criminal investigation. Bitdefender has documented the campaign, and the pattern
Starting in late August 2026, the Microsoft 365 Copilot app on your phone will gain a recording feature, which will be enabled by default for users with a Copilot license. It can record a conversation
You may have seen headlines in recent days saying that “the August 2 deadline for the AI Act has been postponed.” That’s only half true, and the confusion could be costly. Through the package known as the Digital Omnibus, the European Union
You didn't buy artificial intelligence, but as of August 1, 2026, you already have it in your company: Microsoft has completed the rollout of an improved version of Copilot Chat—included in all eligible accounts—
The Five Eyes intelligence agencies warn: an active campaign is scanning the internet for WordPress sites with vulnerable plugins and installing webshells that give attackers complete control over
A CCTV system looks like it works: LEDs on, image on the screen. But was it recording? A company found out it wasn't — exactly when it needed the footage.
The company had backups. It just hadn't tested them for 8 months — and on the day it mattered, they didn't restore. Why the restore test makes the difference.
An active campaign uses Teams calls from a fake “IT admin” to talk you into installing remote access — then takes over the computer. The simple rule that stops it.
For a company with 15 employees, one day of downtime realistically means 10,000–15,000 lei. Why preventive maintenance is cheaper than a single hour of that day.
How many keys to your office are "somewhere out there"? An access-control system changes the equation: deactivate a card in a minute and see who entered, where and when.
Business Email Compromise: an email that looks perfectly normal, with a single detail changed — the IBAN. A simple procedure stopped a 43,000 lei fraud.
Romania's GEO 155/2024 (NIS2) works on self-identification: the company itself must check whether it is in scope and register with DNSC. What it means and how to check for free.