A critical WD My Cloud flaw enables remote system command execution. SMBs must update firmware immediately to avoid data breaches and downtime. #CyberSecurity #NAS #SMBRisk

https://www.bleepingcomputer.com/news/security/critical-wd-my-cloud-bug-allows-remote-command-injection/

Critical WD My Cloud bug allows remote command injection

Western Digital has released firmware updates for multiple My Cloud NAS models to patch a critical-severity vulnerability that could be exploited remotely to execute arbitrary system commands.

BleepingComputer

CISA reports Ivanti EPMM flaws exploited with malware kits, urging immediate patching and network monitoring to prevent SMB breaches. #CyberSecurity #SMBRisk #PatchNow

https://www.bleepingcomputer.com/news/security/cisa-exposes-malware-kits-deployed-in-ivanti-epmm-attacks/

CISA exposes malware kits deployed in Ivanti EPMM attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published an analysis of the malware deployed in attacks exploiting vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM).

BleepingComputer

SonicWall urges SMBs to reset MySonicWall credentials due to exposed backups. Act fast to prevent firewall compromise. #cybersecurity #databreach #SMBrisk

https://www.bleepingcomputer.com/news/security/sonicwall-warns-customers-to-reset-credentials-after-MySonicWall-breach/

SonicWall warns customers to reset credentials after breach

SonicWall warned customers today to reset credentials after their firewall configuration backup files were exposed in a security breach that impacted MySonicWall accounts.

BleepingComputer

APT36 uses Linux .desktop files to load malware. SMBs should disable .desktop execution, train staff, and implement simple Linux file checks. #LinuxSecurity #SMBRisk

https://www.bleepingcomputer.com/news/security/apt36-hackers-abuse-linux-desktop-files-to-install-malware/

APT36 hackers abuse Linux .desktop files to install malware

The Pakistani APT36 cyberspies are using Linux .desktop files to load malware in new attacks against government and defense entities in India.

BleepingComputer

SMBs must address AI-driven legal risks—privacy breaches, bias, IP infringement—through governance policies, vendor contracts, and employee training. #AICompliance #SMBRisk

https://www.techradar.com/pro/ai-in-the-workplace-the-legal-risks-businesses-cant-afford-to-ignore

AI in the workplace: the legal risks businesses can’t afford to ignore

Copyright, data protection, and regulatory compliance

TechRadar
‘I can imagine a future where a lot of people really trust ChatGPT’s advice for their most important decisions’: Sam Altman is ‘uneasy’ about the future of AI as an emotional support

OpenAI's CEO feels "uneasy"

TechRadar