September Retrospective

Monthly Recap: Attackers didn't hack software; they borrowed names you trust, and the serious breaches occurred at your providers, not at your end.

The most common type of attack this month did not exploit any vulnerabilities. An email posing as a well-known domain registrar stated that “your domain is about to expire” and requested credit card information. A phone call imitated the administrator’s voice and demanded an urgent payment—the DNSC reports that 42% of the fraud incidents reported in Romania in the first half of the year were telephone scams. A campaign flagged by DNSC in collaboration with CECCAR sent accounting firms an archive that appeared to come from a colleague or from CECCAR and encrypted the documents using BitLocker, a legitimate Windows tool, which is why traditional antivirus software did not detect anything. Also exploiting no actual vulnerabilities were fake “prove you’re human” pages, which asked visitors to paste a command into PowerShell, andclone download sites, which delivered an installer that disabled Windows Update and weakened Microsoft Defender. The common thread in all of these was the same: trust in a familiar name, coupled with a sense of urgency.

The second theme of the month was that the truly serious security breaches weren't happening in your office. The tool that IT service providers use to remotely manage their clients’ computers received its fourth patch in five weeks for a vulnerability with a maximum severity score of 10 out of 10, which had already been reported as being used in attacks. The web hosting control panel, cPanel, fixed a vulnerability rated 9.4 that allowed a standard hosting account to access the databases of other customers on the same server. None of these are fixed by your company. The only real leverage you have is asking the provider and the speed with which they respond—exactly the kind of supply chain oversight that NIS2 also requires.

The third topic concerns the tools everyone uses every day. Google Chrome fixed a vulnerability that was already being exploited in attacks: a web page crafted by attackers was all it took—no additional clicks required. The fix took five minutes—an update and, of course, a browser restart. At the same time, researchers demonstrated that an AI assistant linked to a work email account can receive commands from the very messages it reads: an instruction hidden in an email was executed silently, with the user’s permissions. The issue has been fixed and no actual data was stolen, but the risk remains for any connector linked to an AI assistant.

What's worth doing next month, in order of importance:

  • Write down the two-channel rule and share it with the team. Any request for money, data, or any unexpected file—even from a familiar name—must be confirmed by returning a call to a number you know in advance, not the one displayed by the caller. It costs nothing and covers most of the attacks mentioned above.
  • Send three written questions to your IT and hosting providers: What remote administration tools do you use? Have you applied the latest critical patches? How long does it typically take you to apply them? Request a written response; a vague answer is an answer in itself.
  • Set aside fifteen minutes for a quick check of the computers: updated and restarted browsers, a backup drive disconnected from the network, and unused AI assistant ports disconnected.

The conclusion of the month is reassuring for a company without an IT specialist: almost everything that happened can be addressed with rules, not expensive products. If you’d like us to implement these rules in your company—from payment verification procedures to supplier relationships—the XDN team can help. You can check for free, in five minutes, whether your company falls under NIS2 and what measures are required of you: xdn-cs.ro/instrument-nis2.html

Sources:

This article was generated with AI assistance.

Request a quote

← All news