Four active breach threats target small businesses this week: a GitLab flaw exploited within 24 hours, Microsoft phishing campaigns impersonating executives, a Plesk server vulnerability, and a Revolut data breach via social engineering. Breach response requires immediate patching, staff training, and verification protocols for sensitive requests.
In today's cybersecurity update for September 13th, 2026, small business owners need to take immediate action on several critical threats.
GitLab users face an urgent crisis. A critical vulnerability (CVE-2026-85706) with a perfect 10.0 severity score was disclosed on September 10th and was actively exploited within 24 hours. The path traversal flaw in GitLab's repository commits API allows unauthenticated attackers to access sensitive files without credentials. Businesses running GitLab must update to the latest version immediately.
Microsoft has issued warnings about two dangerous email campaigns. The first involves over a million scam emails sent in early August impersonating CEOs to conduct financial fraud. The second, more sophisticated attack uses passkey-themed social engineering to breach Microsoft cloud environments and exfiltrate data. Businesses should train employees to verify any urgent requests, especially those involving security settings, by calling through official channels.
Plesk Backup Manager contains a serious privilege escalation vulnerability (CVE-2026-68488) affecting Plesk for Linux versions 18.0.80.6 and earlier. The symlink race condition during backup restore operations could allow low-privileged users to gain root access to servers, potentially compromising the entire hosting environment. Website owners using Plesk should update immediately.
Revolut disclosed a data breach where hackers successfully obtained sensitive customer information, including passport copies and full transaction histories, by impersonating a government agency through fraudulent requests. This sophisticated social engineering attack demonstrates the importance of verifying all requests for customer data through independently confirmed official channels, not contact information provided in the request itself.
Key actions: Update GitLab immediately if you use it, educate staff about CEO impersonation and Microsoft phishing campaigns, patch Plesk hosting software, and implement strict verification procedures for any data requests claiming to be from government or law enforcement.
What breach response actions should your business take right now?
GitLab CVE-2026-85706 (10.0 severity) allows unauthenticated attackers to read sensitive files through a path traversal flaw in the repository commits API. If you run GitLab, update immediately. Microsoft's phishing campaigns target executives and use passkey-themed social engineering to breach cloud environments. Train staff to verify urgent requests by calling official numbers, not reply-to addresses. Plesk Backup Manager CVE-2026-68488 exploits a symlink race condition during restore operations, letting low-privileged users escalate to root access. Patch Plesk for Linux 18.0.80.6 and earlier now. All four attacks demonstrate one critical action: verify requests for sensitive data or system access through independently confirmed contact information, not details provided by the requester. CISA alerts confirm these threats are active in production environments.
Key takeaways
- Update GitLab immediately if deployed, patch Plesk Backup Manager for Linux versions 18.0.80.6 and earlier to block root access via symlink exploitation.
- Train staff to verify CEO wire requests and security-related emails by calling official company numbers, not replying to email or using contact info from the message.
- Implement strict verification procedures for any government or law enforcement data requests, confirm through independently sourced contact information before releasing customer information.
- Review and test backup integrity after patching Plesk to confirm no unauthorized access occurred during restore operations.
Frequently asked questions
How fast was the GitLab flaw exploited after disclosure?
CVE-2026-85706 was disclosed on September 10th and actively exploited in production within 24 hours. The path traversal flaw requires no authentication and allows file access via a single HTTP request. Update GitLab immediately if you run it in your environment.
What should employees do if they receive a CEO email requesting urgent wire transfers or security changes?
Never reply to or act on the email. Instead, call your CEO or finance department directly using a phone number from your company directory or official website. Verify the request through this independent channel before proceeding. Microsoft's phishing campaigns clone email addresses and domain names convincingly.
Why is Plesk Backup Manager a risk if we have low-privileged user accounts?
CVE-2026-68488 allows low-privileged users to escalate privileges to root during backup restore operations through a symlink race condition. Root access means attackers can compromise your entire server. Patch immediately and verify backups after patching to confirm no unauthorized access occurred.
How did Revolut's data breach happen, and what does it mean for our customer data procedures?
Hackers impersonated a government agency to fraudulently request customer passport copies and transaction histories. Revolut did not verify the request through independently confirmed channels. Never provide customer data to callers or requesters. Always call government agencies back using official contact information from their websites, never numbers provided in the initial request.
Sources
- https://securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html
- https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
- https://cybersecuritynews.com/plesk-backup-manager-flaw/
- https://cybersecuritynews.com/revolut-data-breach/