Google Phishing, ScreenConnect Flaws, and Shadow AI Risks

by The Creator | Sep 7, 2026

Phishing training is your first line of defense against hackers exploiting Google's trusted services to steal employee credentials. In this week's threat update, attackers are routing campaigns through legitimate Google domains using familiar scenarios like document reviews and package deliveries, making verification procedures critical for your team.

In today's cybersecurity update for September 7th, 2026, small business owners face several critical threats requiring immediate attention.

Hackers are exploiting trusted Google services to launch sophisticated phishing campaigns that steal corporate credentials. These attacks route through legitimate Google domains and use familiar workplace scenarios like document reviews and package deliveries, making them extremely difficult to identify. Employee training on verification procedures is essential.

ConnectWise has issued urgent guidance about a security flaw in ScreenConnect's file transfer functionality. Businesses using this popular remote access tool should immediately restrict file transfer permissions while awaiting a permanent fix.

N-able released an emergency hotfix for a maximum-severity remote code execution vulnerability in their remote monitoring platform. Customers must apply this critical update immediately to prevent potential exploitation.

The UK's National Cyber Security Centre warns that "shadow AI", unauthorized AI tools used by employees, creates significant data exposure risks. Organizations need clear policies defining which AI services are approved for business use.

The common theme across these threats is that both your employees and your technology vendors represent major security factors that require active management and oversight.

Why phishing training matters when Google services become attack vectors

Hackers are weaponizing legitimate Google domains to deliver phishing campaigns that impersonate common workplace workflows. CISA and the UK's National Cyber Security Centre both highlight that employee verification behavior is now your strongest control. For manufacturing and professional services firms, the attack pattern is identical: trusted sender, urgent task, request for credentials. Action: Require your team to verify any request for passwords or sensitive data by contacting the sender through a known phone number or in-person. ConnectWise also released guidance on restricting ScreenConnect file transfer permissions to limit lateral movement if credentials are compromised. Test employee responses monthly.

Key takeaways

  • Google services are now delivery vehicles for phishing, not just email. Teach staff to verify sender identity outside the message.
  • ConnectWise issued urgent guidance on ScreenConnect file transfer flaws. Restrict permissions immediately while awaiting the permanent patch.
  • Shadow AI (unapproved employee tools) creates data exposure. Publish a clear policy on which AI services employees can use.

Frequently asked questions

How do I know if my team is vulnerable to Google phishing?

Ask yourself: Do your employees verify sender identity before opening links or attachments from Google Docs, Gmail, or Google Drive? If not, run a phishing simulation this week. CISA offers free guidance on testing frameworks.

What should I do about ScreenConnect right now?

Log into your ScreenConnect instance and restrict file transfer permissions to administrators only. ConnectWise has published step-by-step guidance. Apply the permanent fix as soon as it is released.

What counts as shadow AI I should block?

Shadow AI means unapproved tools like ChatGPT, Claude, or Copilot used outside your IT controls. Your policy should specify which AI services employees can use and require approval before uploading sensitive data. Document your approved list and share it with all staff.

Can my MSP help with phishing training and tool audits?

Yes. A managed service provider can audit your current tools (ScreenConnect, N-able, remote access), deploy phishing simulations, and enforce policies on shadow AI usage. This is standard part of breach response and compliance management.

Sources

Keep reading