The Cyber Brief, Issue 1, September 2026.
Yes, a malvertising attack can come from an account you already trust, and this month HBO Max proved it. Their own verified Reddit account was hijacked and used to run fake ads loaded with malware, and nobody at HBO Max had to click anything wrong to make it happen. For a small or midsized business, the real lesson isn’t about HBO Max at all. It’s about what a single stolen login can do to your business while nobody is looking.
Can a malvertising attack really come from a trusted brand’s ad?
This month’s answer is yes. HBO Max’s own verified Reddit account was hijacked and used to run ads loaded with malware. The account was verified, the source looked clean, and the usual advice, check who sent it, gave nobody’s team anything to go on.
Doing nothing here doesn’t cost you a virus. It costs you a login. One employee clicks a familiar looking ad, a password stealer grabs saved credentials and open browser sessions, and someone is inside your email or your bank as you, with no alarm telling you it happened. The malware rode in through an ad, not a link in an email, so the filters most small businesses rely on never saw it coming.
For a firm this size, the takeaway is blunt. The habit your team already has, checking the source, doesn’t cover this. You need a second layer that catches the theft after the click, not just before it.
What does the WooCommerce plugin bug mean for small business websites?
Security researchers found hackers exploiting a bug in a WooCommerce plugin to take over WordPress sites without ever needing a login. If you sell anything through WordPress, an out of date plugin can hand your storefront to a stranger with no password required.
For a firm this size, the fix isn’t a bigger firewall. It’s patch management. A storefront plugin that hasn’t been updated in months is an open door with a welcome mat out front.
Why should a port shutdown or a crypto heist matter to a business with neither ships nor wallets?
Three stories this month say the same thing from different angles. US prosecutors moved forward with charges against suspected leaders of the Black Axe gang, the group tied to a lot of the fraud emails landing in small business inboxes, a reminder that the scams keep improving because organized groups run them like businesses. Separately, a single unreviewed line of code let a hacker drain $7.8 million from a crypto wallet, and most small firms never review their code at all. And the Port of Tanjung Pelepas went dark for days after a cyberattack before resuming operations. If your supply chain touches ports or logistics, that delay was yours too, even though the attack never touched your systems.
One more worth watching: Microsoft published an AI code of conduct setting boundaries and a chain of command for its AI tools, worth a look if your team is starting to use AI at work, since the rules for what those tools are allowed to do are still being written.
For a firm this size, exposure doesn’t require you to be the target. It just requires you to depend on someone who is.
What’s the one thing that actually matters this month?
Nobody gets asked whether they’re hackable. Everyone already is. The questions that actually land are how long you’re down, what you owe your clients while you are, and whether you can show you did the reasonable thing. That changes what’s worth buying. A control that shortens the outage and leaves a record beats one that only promises to keep people out.
The incidents that hit firms your size are rarely exotic. It’s the backup nobody ever restored from and the admin login three people still share. Our cybersecurity data breach risk page walks through what that looks like for a business your size.
What should you do about it this week?
No vendor required for any of this:
- Turn on a password manager with saved session alerts, so a stolen cookie gets flagged, not just a stolen password.
- Ask your team to open ads and offers in a private or incognito window, never the one where they’re logged into work accounts.
- Find the one login everyone shares, there’s always one, and give it its own account this week.
Nobody gets asked whether they’re hackable. Everyone already is. TC³ can help you shorten the outage and leave a record that you did the reasonable thing, though no tool we sell stops a person from clicking a bad ad. Curious how your team would hold up? Try the Two-Week Test. Catch up on past issues in The Cyber Brief archive, browse more on our cybersecurity news hub, and subscribe to get the next issue in your inbox.