AccuSights
PartnersBlogAbout
Book my 30-minute demo

AccuSights Cyber Analytics

Know what attackers are doing. Protect what matters first.

No business can protect everything, everywhere, at all times. The good news: you do not have to. The data below comes from more than 22,000 confirmed breaches across 145 countries, and it points to a short list of things that stop most attacks. You have enough to worry about. Let us help you quantify the right risks and fix them in the right order.

Baseline: Verizon 2026 DBIR · Advisories updated 2026-09-03

The Cyber Expert's five · 17 August to 3 September 2026

What actually mattered this week, and what to do about it

A week where the attackers brought AI to work and the defenders brought alert fatigue. Two red-team reports, one from CISA, showed the same thing our assessments show every month: the way in is a default setting nobody changed, and the way out is a control someone actually runs. Nothing here is new physics. Read the five picks, apply the fixes that match your stack, and get back to running the business.

Act todayVulnerabilities and exploits

Two SharePoint bugs, one public exploit chain, and 8,700 servers still facing the internet

A JWT authentication bypass (CVE-2026-55040, CVSS 9.1) lets an attacker who knows a username act as any SharePoint user, including an admin. Chained with a remote code execution flaw in Business Connectivity Services (CVE-2026-63520), public proof-of-concept code was released in August and honeypots saw probing within days. CISA added the bypass to its Known Exploited Vulnerabilities list on 18 August; Shadowserver counts more than 8,700 exposed on-premises servers.

The Cyber Expert’s read. On-premises SharePoint is the office fax machine of 2026: still there, still plugged in, still trusted. If you run Subscription Edition, 2019 or 2016 and it answers to the internet, the first bug alone hands over the keys. SharePoint Online is not affected. Patch, then check who logged in as your admin last week.

Who this touches: Any business running on-premises SharePoint, especially professional services and manufacturing firms that kept it for document workflows.

Strengthen

  • CIS 7 Continuous Vulnerability Management
  • CIS 4 Secure Configuration
  • CIS 8 Audit Log Management

Do this week

  1. Apply the July and August SharePoint updates today, or take the server off the internet until you do.
  2. Search the IIS and ULS logs for admin sessions from addresses you do not recognize since 14 July.
  3. Put the server behind VPN or an identity-aware proxy; a document server has no business with a public address.

GlobalProfessional servicesManufacturingGovernmentHealthcarePersonal dataSource code and IPMicrosoft SharePoint on-premises

Sources: CISA KEV · Rapid7 analysis · BleepingComputer

Act this weekCritical infrastructure and OT

CISA red team broke into two critical infrastructure organizations. One of them never noticed.

CISA published a joint assessment (AA26-237A) of two consenting organizations, one in government services and one in water and wastewater. Its team reached full domain compromise at both using a default Machine Account Quota, a misconfigured certificate template, default credentials, internal phishing and over-broad cloud permissions. Organization A received the alerts and did not act because thousands of higher-severity false positives had buried them. Organization B isolated hosts within two to twenty minutes.

The Cyber Expert’s read. Same tools, same weaknesses, two different outcomes, and the difference was not budget. It was whether a human looked at the alert and had permission to pull the plug. That is the whole argument for a watched environment over a monitored one. Alert fatigue is a staffing problem wearing a technology costume.

Who this touches: Every organization with Active Directory and a SOC or MDR contract, which is most of you.

Strengthen

  • CIS 5 Account Management
  • CIS 6 Access Control Management
  • CIS 17 Incident Response Management
  • CIS 13 Network Monitoring and Defense

Do this week

  1. Set ms-DS-MachineAccountQuota to 0 unless you have a documented reason not to.
  2. Audit AD CS templates for the ESC1 pattern: enrollee supplies subject, client authentication enabled, low-privilege enroll rights.
  3. Ask your SOC provider one question: who is allowed to isolate a host at 2 a.m. without calling you first?

United StatesGovernmentUtilitiesCritical infrastructurePasswords and credentialsOperational technologyActive DirectoryAD CSMicrosoft 365

Sources: CISA advisory AA26-237A

Act this weekPhishing and social engineering

The "IT Service Desk" that messaged you on Teams was not your IT service desk

Researchers at Expel documented SynkLoader, a modular malware family pushed through Microsoft Teams messages from external or compromised tenants posing as the help desk. Victims are told to install a "PowerShell Cleaner" MSI hosted on Azure Blob Storage. Modules cover credential theft, persistence, reverse proxy, remote shell and screen streaming, plus PhishLocker, a fake Windows 11 lock screen that collects the user’s password.

The Cyber Expert’s read. Nobody clicks links in email anymore, so the bad guy moved to the chat window where the guard is down. The fix is boring and works: your real help desk never sends installers over Teams, and your tenant does not accept chats from strangers by default. Say that out loud to staff this week and turn the setting off.

Who this touches: Any Microsoft 365 shop, with or without an internal IT team, and every MSP that runs Teams for clients.

Strengthen

  • CIS 14 Security Awareness and Skills Training
  • CIS 4 Secure Configuration
  • CIS 2 Inventory and Control of Software Assets

Do this week

  1. In Teams admin, restrict external access to allowed domains only and block unmanaged (Skype and consumer) accounts.
  2. Enforce application control so an MSI from a blob URL cannot run on a standard user’s machine.
  3. Publish a one-line rule internally: IT never asks you to install anything from a chat message.

GlobalEvery businessPasswords and credentialsSessions and tokensMicrosoft TeamsMicrosoft AzureWindows

Sources: BleepingComputer (Expel research)

Act this weekRansomware

A ransomware affiliate used an AI coding assistant to plan attacks on 20 companies in nine countries

CloudSEK found an exposed operator server showing an Aurora ransomware affiliate working through intrusions against more than 20 organizations between April and July 2026, with domain-level access at 17 and four already on the leak site. The operator used Cursor, in Russian, to plan the steps, including a complete certificate-services exploitation path. A separate Gambit Security report saw Cursor Agent used hands-on against ten targets with NetExec, Kerberoasting, NTLM relay and Certipy. Victims span manufacturing, food, professional services and logistics.

The Cyber Expert’s read. The affiliate was not a genius. The AI filled in the parts a mid-skill criminal used to get wrong, which means the attacks got more reliable, not more exotic. Every technique on that list is ten years old and every one has a known fix. Air-gapped, tested backups turn this from an existential event into a bad Tuesday.

Who this touches: Mid-sized firms with Windows domains and a thin IT bench: manufacturers, food producers, logistics, professional services.

Strengthen

  • CIS 11 Data Recovery
  • CIS 5 Account Management
  • CIS 6 Access Control Management
  • CIS 17 Incident Response Management

Do this week

  1. Confirm you hold an offline or immutable backup copy and restore one server from it this month, timed.
  2. Disable NTLM where you can, enforce SMB and LDAP signing, and set service accounts to long random passwords to blunt Kerberoasting.
  3. Review AD CS templates and remove enrollment rights that let ordinary users request authentication certificates.

GlobalUnited StatesUK and EuropeManufacturingFood and agricultureProfessional servicesLogisticsPersonal dataSource code and IPPasswords and credentialsActive DirectoryVMware ESXiWindows

Sources: CloudSEK · Gambit Security

Act this weekPhishing and social engineering

A security company got the help-desk call. One employee approved the MFA push. Device trust held the line.

ReliaQuest confirmed that callers impersonating its own security staff sent employees to a fake single-sign-on page on a lookalike domain. One employee entered credentials and approved an MFA prompt, giving the attacker a single view-only session on the Okta admin dashboard. Device-trust policies blocked access to any application; ReliaQuest reports no data access, persistence or customer impact. ShinyHunters claimed the incident and had been registering company-name domains under the .claims top-level domain a week earlier.

The Cyber Expert’s read. This is what a good day looks like when the phishing works: the attacker gets a screenshot and nothing else. The lesson is not "train harder." It is that a password plus a push is not enough anymore, and the control that saved them was the one that asks "is this a company laptop?" before "is this the right password?"

Who this touches: Any company using Okta, Entra or Google as its identity provider, which is nearly everyone with more than ten staff.

Strengthen

  • CIS 6 Access Control Management
  • CIS 5 Account Management
  • CIS 14 Security Awareness and Skills Training

Do this week

  1. Turn on phishing-resistant MFA (passkeys or FIDO2 keys) for admins first, everyone next.
  2. Require a managed, compliant device for access to your identity admin console and finance systems.
  3. Register a callback rule: anyone claiming to be IT or security on the phone gets a call back on the published number.

United StatesGlobalTechnology and softwareProfessional servicesEvery businessPasswords and credentialsSessions and tokensOktaSingle sign-on

Sources: ReliaQuest · Help Net Security

31%
of breaches now start with an unpatched software flaw
Now the #1 entry point

Exploitation of vulnerabilities has overtaken stolen credentials as the most common way in. Credential abuse fell to 13%.

48%
of all breaches involve ransomware
Up from 44%

Up from 44% the year before. The median ransom paid fell to $139,875, and 69% of victims refused to pay at all.

48%
of breaches involve a third party
Up 60% year over year

A 60% jump in one year. Your vendors, your software suppliers, and your cloud accounts are part of your attack surface whether you manage them or not.

62%
of breaches involve the human element
Up from 60%

Phishing, pretexting, stolen credentials, and simple mistakes. Mobile phishing clicks run 40% higher than email, because attackers moved to your pocket.

How breaches actually happen

Five patterns describe nearly every breach. Watch System Intrusion, the pattern behind most ransomware, climb from 36% to 61% in three years. That is the story of modern cybercrime in one chart.

System Intrusion
61%
Social Engineering
17%
Basic Web Application Attacks
10%
Miscellaneous Errors
8%
Privilege Misuse
3%

The four shifts that matter this year

The rise of vulnerability exploitation

Attackers stopped picking the lock. They walk through the unpatched door.

31%of breaches begin with an exploited vulnerability
26%of known-exploited critical flaws were fully fixed in 2025
43 daysmedian time to fully remediate, up from 32

For years the front door was a stolen password. Not anymore. Exploited software flaws are now the number one way attackers get in, and the defense is losing ground: barely a quarter of critical vulnerabilities on CISA’s Known Exploited Vulnerabilities list were fully fixed last year, and the ones that got fixed took almost two weeks longer than the year before. Meanwhile the typical organization had 50% more critical flaws to patch.

What to do: Know what you run, know what is exposed to the internet, and patch the exploited flaws first. That is a visibility problem before it is a patching problem.

Ransomware and third-party breaches keep growing

Half of breaches are now someone else’s software, or your own held hostage.

48%of breaches involve ransomware
69%of ransomware victims refused to pay
$139,875median ransom paid, and still falling

Ransomware climbed again to 48% of all breaches. The good news hides inside the bad: victims with tested backups increasingly refuse to pay, and the median payment keeps shrinking. Third-party exposure is the quieter half of the story. Breaches involving a vendor or supplier jumped 60% in a single year, and when researchers watched how fast third parties fixed missing MFA on cloud accounts, only 23% ever fully did.

What to do: Backups that someone has actually restored from, MFA on every account you and your vendors touch, and a written answer to the question: which suppliers could take us down with them?

Social engineering went mobile

Your team got good at spotting phishing emails. So the attackers left email.

40%higher click rate on mobile lures vs. email
16%of breaches start with phishing
6%begin with pretexting, a patient, targeted con

The human element sits inside 62% of breaches, and the delivery mechanism moved. Fake texts, scam calls, and voice pretexting now land 40% more often than email phishing, because nobody trained your team on their phones. Pretexting, where an attacker builds trust over days before making the ask, has become a favorite opening move for ransomware crews.

What to do: Train for the text and the phone call, not just the inbox. Then make the payroll and wire-change process survive one convincing phone call, because one is coming.

Generative AI joined the other side

The median attacker now uses AI across 15 different attack techniques.

15attack techniques where the median actor used AI
45%of employees now regularly use AI at work, up from 15%
3.2%of AI data-loss events involved research or technical docs

Attackers use generative AI to pick targets, write malware, and research your weaknesses, with some actors documented across 40 or 50 techniques. Inside your company, the same technology walked in without asking: employee AI use tripled in a year, mostly through personal accounts on work devices, and source code is the single most common thing pasted into it. Shadow AI is now the third most common insider data risk, ahead of most things your policy actually mentions.

What to do: Give people a sanctioned AI tool so they stop using unsanctioned ones, and put your source code and client data behind a data-loss policy that watches AI destinations.

Your industry, your numbers

Attack surfaces are not created equal. Pick your industry and see what actually hits businesses like yours, in plain language.

Small & Medium Business

NAICS All sectors
7,152confirmed breaches analyzed
100%external attackers
100%financially motivated
55%involve a third party

How they get in

Exploited vulnerabilities
26%
Credential abuse
13%
Phishing
9%

System Intrusion, Basic Web Application Attacks and Social Engineering: 100%

Every attacker external. Every motive financial. Nothing personal, purely math: small businesses hold the same valuable data as large ones with a fraction of the defenses. Internal data was taken in 97% of SMB breaches, credentials in 31%.

Where to start: You cannot protect everything, and you do not have to. MFA, tested backups, patched edge devices, and someone watching. That combination breaks almost every attack pattern on this page.

The view by region

Northern America

8,426 breaches30% start with an exploited flaw3% espionage motive

The largest regional dataset in the report. Financially motivated crime dominates at 98%, with credential abuse a stronger second vector than anywhere else.

Europe, Middle East & Africa

2,855 breaches42% start with an exploited flaw36% espionage motive

Espionage motivates 36% of EMEA breaches, ten times the North American rate. Third-party involvement (69%) and the human element (71%) both run above the global baseline.

Asia Pacific

6,060 breaches47% start with an exploited flaw27% espionage motive

The highest vulnerability-exploitation rate of any region at 47%, and the highest phishing entry rate at 28%.

Current advisories worth your attention

Chosen from the CISA Known Exploited Vulnerabilities Catalog and verified breach reporting. Not everything, on purpose. Just what a business owner should act on.

CRITICALCISA Known Exploited Vulnerabilities Catalog, and SonicWall product notice SNWLID-2026-0016

SonicWall SMA1000 remote access appliances are being broken into through two zero-days (CVE-2026-83548 and CVE-2026-83549)

Who should care: Businesses whose people log in from home or the road through a SonicWall SMA 1000 box, and the IT firm that put it there. Affected models are the 6210, the 7210 and the 8200v virtual appliance. The first flaw lets a stranger reach internal functions without logging in, the second runs commands on the appliance itself, and chained together they hand over the very device that guards your remote access. SonicWall confirmed both were already being used in real attacks when it published the notice on 1 September. Your firewall's own SSL-VPN and the smaller SMA 100 series are not affected, so check the model before you panic.

Do this: Upgrade to 12.4.3-03526 or 12.5.0-02952 from MySonicWall today. Then ask SonicWall support to review the appliance for signs someone already got in, because a patch removes the hole and not the intruder. SonicWall's own instruction if anything turns up is blunt: rebuild the appliance, change every user and administrator password, and reset the one-time-code tokens.

CRITICALCISA Known Exploited Vulnerabilities Catalog

Attackers are taking over Sangoma Switchvox phone systems through the page that sets up desk phones (CVE-2026-9586)

Who should care: Businesses running a Sangoma Switchvox phone system. It was sold as the SMB Edition and it sits in a lot of small offices, clinics and contractor back rooms, usually installed once by a phone vendor and never thought about again. The page your desk phones use to collect their settings never asks who is calling, and it passes whatever it receives straight to the database behind it. Honeypots began catching live exploitation on 30 August, and what attackers leave behind is a reverse shell, which is a foothold on the same network as your files and your accounting.

Do this: Upgrade to Switchvox 8.4.0.2 or later. That release came out on 14 July, so an unpatched system has been sitting open for weeks. Take the Switchvox web interface off the public internet at the same time, because nobody outside your offices needs to reach it. If it was internet-facing before you patched, assume someone found it and have your phone vendor look for unfamiliar processes and new accounts.

CRITICALCISA Known Exploited Vulnerabilities Catalog

PaperCut print server flaws chained for full takeover (CVE-2026-81578 and CVE-2026-82078)

Who should care: Businesses running PaperCut NG or MF to track and charge for printing. That means a lot of schools, law firms, clinics, universities and the IT providers who installed it years ago and have not touched it since. Two flaws chain together: the first skips the login on the web management screen, the second runs code on the server. Huntress confirmed attackers used the chain in two customer environments before a patch existed.

Do this: Install Emergency Patch Release 2 today, even if you already applied the first emergency patch, because researchers found several ways around that one. Versions 24, 25 and 26 have the fix and anything on version 23 or earlier needs a full upgrade. Close the PaperCut web interface to the open internet as well, so only your office addresses can reach it.

CRITICALThe HIPAA Journal

McKesson confirms an intrusion after ShinyHunters claims a terabyte of patient data, and the way in was a phone call

Who should care: Every practice, clinic and healthcare vendor, less for the size of it than for how it started. The group says it called employees, talked them into giving up access to their Okta single sign-on accounts, then used that access to reach McKesson's Salesforce and Snowflake data. About a terabyte left between August 21 and August 25. The 284 million figure being advertised counts rows of data, not people, and McKesson says the investigation is early.

Do this: Tell your staff this week that nobody from IT will ever phone and ask them to approve a login prompt or read out a code, and that the right answer is to hang up and call back on a number they already have. After that, pull the list of who at your practice can export records in bulk from your EHR or billing system. It is almost always longer than the owner expects.

CRITICALCISA Known Exploited Vulnerabilities Catalog

ownCloud authentication bypass (CVE-2023-49105) added to CISA's exploited list after a real theft

Who should care: Any business running its own ownCloud file server. Someone set it up years ago so documents would stay in house, and it has probably been running untouched ever since. An attacker who knows one username can read, change or delete files without ever logging in, which is exactly how a research body in the Philippines lost records this month.

Do this: Find out today whether you run ownCloud and what version. Anything from 10.6.0 through 10.13.0 is vulnerable, and 10.13.1 is the fix. If nobody can answer, pull it off the public internet until someone can.

CRITICALCISA Known Exploited Vulnerabilities Catalog

Citrix NetScaler flaw under active attack (CVE-2026-8452), among six added to CISA's exploited list

Who should care: Any business using Citrix NetScaler ADC or Gateway for remote access. If a vendor hosts your remote desktop, ask them.

Do this: Patch now or take the appliance offline. CISA added this because attackers are exploiting it in the wild today, not theoretically.

HIGHCISA Known Exploited Vulnerabilities Catalog

Seven-year-old Microsoft SQL Server flaw (CVE-2019-1068) exploited; CISA gave agencies three days

Who should care: Businesses whose accounting, scheduling, practice management or job costing software sits on a Microsoft SQL Server. That covers most of you. Almost nobody thinks about the database humming away behind the application they actually use.

Do this: Ask your software vendor or IT provider two things: which SQL Server version runs our main application, and does it have the 2019 fix. CISA also told agencies to look for evidence of a break-in, not simply to patch and move on.

CRITICALCISA Known Exploited Vulnerabilities Catalog

Zimbra mail server flaw (CVE-2026-73570) is being used to take over servers, and 267 have already fallen

Who should care: Businesses running their own Zimbra mail server instead of Microsoft 365 or Google Workspace, and the IT firms that host Zimbra for them. The setting attackers abuse, SNMP notifications, is turned on by default in vulnerable versions, so you did not have to misconfigure anything to be exposed. The Shadowserver Foundation counted 267 compromised servers by August 24.

Do this: Upgrade to Zimbra 10.1.20 or later, which shipped July 20. If you are already past the patch date and only fixing it now, assume someone got in first and have your provider check for new accounts, forwarding rules and scheduled jobs.

About the data

Baseline data: Verizon 2026 Data Breach Investigations Report, the 19th edition of the most comprehensive study of real-world breaches in the industry. More than 31,000 security incidents and 22,000 confirmed breaches across 145 countries, contributed by almost one hundred organizations, from incident response firms to law enforcement to cyber insurers.

Do not let the bad guys take what you built.

Tell us your industry and we will send a complimentary threat and risk report for businesses like yours, then a Cyber Success Engineer will walk you through it.

Or skip the form and directly.