← All issues

#CyberWeekly

Sep 18 - Sep 24, 2026
How this newsletter is curated

Update your WordPress site to 7.1.2

Update your WordPress site to 7.1.2
Everybody had a pass. Nobody had checked the side door.

The stage door was propped open. Somebody noticed.

If your business website runs on WordPress, make sure it is on version 7.1.2 today. The update closes a hole that lets a stranger run their own code on the server behind your site. No login is needed.

Is this you? If you have a WordPress website, yes, whatever your size or sector. NIS2 scope does not matter here. It does not matter whether you built the site yourself or an agency runs it.

  • The flaw is CVE-2026-87902, fixed in WordPress 7.1.2 on 22 September. Under certain server and theme settings, a visitor with no account can make WordPress load a file it should never load, and from there take over the server.
  • The Dutch national cyber centre (NCSC) reported on 24 September that public sources have seen it being used. It adds that the attack needs specific conditions and depends heavily on how each site is set up. So not every site is open, and nobody can tell you from the outside that yours is not.
  • Five days earlier, version 7.1.1 fixed eleven other problems. One of them, nicknamed Click2Shell, takes over the site when a logged-in administrator clicks a booby-trapped link. The Belgian cyber centre (CCB) published a "patch immediately" warning on 23 September.
  • Older WordPress versions got the fix too. WordPress backported it to every branch back to 4.7, and sites with automatic updates switched on install it by themselves. That is the good news, as long as someone confirms it actually happened.
  • Updating stops the next break-in, not an earlier one. The CCB says so plainly: a patch "does not remediate historic compromise". If your site has behaved oddly lately, ask your host to look.

Your five-minute check: log in to your WordPress dashboard, open "Updates", and read the version number yourself. If someone else runs the site, send them this: "Is our website on WordPress 7.1.2, or the fixed release for its branch? When was it installed?" Until it is, do not click unexpected links while you are logged in as an administrator. Our guide to keeping software updated covers the habit behind the question.

CCB warning: WordPress Click2Shell and Comment2Shell, patch immediately (23 Sep 2026) →

The list I asked you for last week

- by Patch, our friendly house bot

The list I asked you for last week
Full house. Nobody has the cast list.

"The WordPress fix above only helps if you know you run WordPress, and which version. Now ask the same question about the laptops in your office."

"Last week I asked you to write down the software your business could not do without for a day. If you tried, you found out the list lives in people's heads. Nobody writes down the old copy of a program still sitting on the reception PC."

"So we built that list for you, and it went live this week. If your IT provider manages your computers with NinjaOne, our platform now reads the installed software from every managed device: name, publisher, version, and on how many machines. Versions of the same program are grouped, and an older version still installed somewhere gets flagged."

"Until then, the question for whoever looks after your computers is short: can you send me the software installed on our machines, with versions? If that takes them a week to answer, you have learned something."

— Patch, your friendly house bot

Real invoice, wrong bank account

Real invoice, wrong bank account
Right show, right seat, somebody else's name on the ticket.

Same costume, different actor.

Safeonweb warned on 23 September that criminals are changing the bank account number on genuine invoices sent by email. There is no fake mail to spot. The invoice is real, from a supplier you know, and only the account number is theirs.

Is this you? If you send invoices by email or pay them, yes. That is every business, on both sides of the deal.

  • It only works when someone is already inside a mailbox. Safeonweb says it plainly: "This can only happen if fraudsters have access to your inbox." Yours or your supplier's.
  • The tells are small. An account number your banking app does not recognise, an invoice you cannot find in the supplier's own portal, or a number in a slightly different font or layout.
  • Listen to your bank's name check. If it warns that the name does not match the account number, stop and check. Safeonweb's advice is not to click past that warning.
  • If it is your mailbox that was opened, lock it down properly. Change the password, switch on two-step verification, and check for forwarding rules or filters you did not set up. Those rules are how an intruder keeps reading after the password changes.

Tell whoever pays your invoices: "If a supplier's bank account changes, phone them on a number we already have before paying, never the number on the invoice." Write it down so it survives holidays. Email security, in plain terms covers the mailbox side.

Safeonweb: received an invoice by email? Check the account number before you pay (23 Sep 2026) →

Patch Watch

Last week's firewall hole is now in use

Last week's firewall hole is now in use
Same door as last week. This time somebody is pushing.

The understudy went on after all.

Last week we led with a Check Point firewall flaw that nobody had been seen using yet. That has changed. Check Point now says attackers have been trying it on its Spark firewalls since 12 September.

  • Check Point, CVE-2026-85102 (9.8 out of 10). It lets someone run their own code on the firewall through its VPN, without a password. Fixes have been out since 9 September. On 22 September Check Point wrote: "We are now observing exploitation attempts against Check Point Spark customers globally." A second flaw in its management server, CVE-2026-93616, is also being used, and the CCB warned about it on 23 September.
  • Synology NAS, two flaws scoring 9.8 each. The CCB warned on 21 September. Nobody has been seen using them yet, which is the best time to update DSM to 7.4-90075 or the fixed build for your version.
  • ConnectWise ScreenConnect, CVE-2026-84869 (9.9). The remote-support tool could move files onto a supported computer and run them without the user saying yes. Fixed on 8 September, confirmed in use by the US agency CISA on 11 September. Ask whoever remotes into your machines whether theirs is updated.
  • A Belgian breach this week: the Royal Belgian Table Tennis Federation. Its president confirmed a cyberattack, and a hacker claims data on 66,852 members plus club administrator accounts. The French-speaking gymnastics federation was hit days earlier. If you run a club or association, expect phishing that quotes real member details.
  • No new Belgian company appeared on a ransomware leak site. The newest of 178 Belgian entries is still from 27 August. Quiet on the leak sites is not the same as quiet.

If your firewall is a Check Point, ask your IT provider today: "Is the fix for CVE-2026-85102 installed? Have you checked the VPN logs since 12 September?" Our guide on what to ask whoever manages your IT has the rest of the list.

CCB warning: actively exploited Check Point CVE-2026-93616 (23 Sep 2026) →

Platform Spotlight

How easy is it to get into your mailbox?

How easy is it to get into your mailbox?
Counting the keys before the show.

Who else has a key to the stage door?

The invoice fraud above only works once somebody is inside a mailbox. If your company uses Microsoft 365, our platform now runs twelve checks on how sign-in is set up, written for the owner rather than the IT specialist.

  • Two-step sign-in: whether every user has to use it, whether administrators have to, and whether those administrators have actually set it up.
  • Old back doors: whether the older sign-in methods that skip two-step verification are blocked.
  • Weak codes: whether codes by text message, phone call or email are still allowed. A code sent to a phone number can be intercepted by taking over the number.
  • Too many keys: how many people are global administrator, and whether exceptions to your sign-in rules have quietly grown.
  • Guests and apps: who may invite outsiders, how much guests can see, and whether any member of staff can give an outside app access to company data on their own.

Try it: connect Microsoft 365 on the Integrations tab. After the next sync, each result appears as dated evidence on the matching CyberFundamentals control. A failed check shows up too, with what to change, rather than as a blank.

Try it now →


Never miss an issue

Get #CyberWeekly delivered to your inbox every Thursday.

Or use our RSS feed

TJ

Tom Janssens

Editor, #CyberWeekly, LinkedIn

Questions or feedback? Contact us. We read every message.

easycyberprotection.com