Phishing attacks using fake Microsoft security scanners are tricking small business employees into uninstalling their antivirus protection, leaving networks exposed to real attacks. Three separate threats emerged this week that target trust and outdated software, requiring immediate action from your team.
Small businesses face three critical threats today. Scammers are deploying fake Microsoft security scanners that trick victims into uninstalling their legitimate antivirus protection, according to Malwarebytes. These fraudulent scans invent security problems and steer users toward removing their real defenses, leaving them vulnerable to actual attacks.
In a stark reminder that no one is immune to social engineering, cybersecurity firm ReliaQuest disclosed that hackers successfully impersonated their own security staff to steal employee credentials. The incident emphasizes the importance of verifying unusual requests through separate communication channels.
WordPress users should act immediately: a critical vulnerability (CVE-2026-19598) in the Everest Forms plugin, with a severity score of 9.8, threatens over 100,000 websites with complete takeover. Attackers can upload malicious files and seize full control of unpatched sites.
These incidents highlight a common pattern: cybercriminals exploit trust and capitalize on delayed security updates. Businesses must maintain current software patches, verify suspicious requests, and train employees to recognize social engineering tactics.
How are phishing attacks targeting your antivirus right now?
Malwarebytes reports scammers deploying fake Microsoft security scans that invent problems and pressure users to remove legitimate antivirus. ReliaQuest disclosed hackers impersonating security staff to steal credentials. WordPress users face a critical vulnerability (CVE-2026-19598, severity 9.8) in Everest Forms affecting 100,000+ sites. The pattern is clear: attackers exploit trust in familiar brands and delay in patching. Your immediate actions: verify all security alerts through a separate phone call or in-person check with your IT team, patch WordPress plugins today, and run unannounced phishing drills with staff to identify who will click suspicious links.
Key takeaways
- Fake Microsoft scans trick users into removing real antivirus protection. Tell staff to call IT directly when security alerts appear unexpected.
- WordPress Everest Forms plugin (CVE-2026-19598) allows complete site takeover. Update immediately if you use this plugin.
- ReliaQuest breach shows hackers impersonate your own security team. Verify unusual requests through a second communication channel.
Frequently asked questions
What should employees do if they see a Microsoft security scan pop-up?
Do not click anything on the pop-up. Close the browser tab, then call your IT team using a phone number you know is correct to verify the alert. Scammers count on speed and fear to bypass thinking.
Do we need to worry about this if we use cloud antivirus?
Yes. These phishing attacks work because they impersonate trusted brands. Even cloud-based tools can be disabled by users who believe the fake scan. Training is your defense.
How do I check if our WordPress site has the Everest Forms plugin?
Log into WordPress admin, go to Plugins, and search for Everest Forms. If installed, update immediately to the latest version. If not using it, consider removing it to reduce your attack surface.
What is CVE-2026-19598 and why does a 9.8 severity score matter?
CVE numbers identify specific known vulnerabilities. A 9.8 score (out of 10) means attackers can take complete control of your site without authentication. This is your highest priority patch.
Sources
- https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus
- https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/
- https://cybersecuritynews.com/wordpress-everest-forms-plugin-flaw/