Small businesses often have a larger attack surface than their size suggests. Achieving cyber readiness is presented as the initial and crucial step toward building resilience against potential threats.

Small and medium-sized businesses (SMBs) are increasingly recognizing the critical importance of cybersecurity, with a recent report indicating that 45% of SMBs experienced a cyber incident in the past year. Despite this, 61% express concern about potential attacks in the next 12 months, highlighting a persistent gap between awareness and preparedness. These businesses, which constitute 90% of global enterprises, employ 70% of the workforce, and contribute 50% to global GDP, face significant challenges in allocating limited resources effectively to cybersecurity.
The ESET SMB Cyber Readiness Index 2026 report emphasizes that cyber resilience—the capacity to maintain operations and recover during a serious incident—should be a primary objective for SMBs. This journey begins with cyber readiness, which involves establishing processes and controls for threat prevention, detection, and response. The report reveals that while many SMBs eventually recover from incidents, 34% require two to six weeks to resolve them, a duration that can be catastrophic for smaller firms.
SMBs share similar concerns with larger corporations, primarily focusing on data loss, operational disruption, and financial impact. The expanding corporate attack surface, the continuous evolution of the threat landscape, and the increasing volume and speed of attacks, often leveraging advanced technologies, contribute to these anxieties. Employees also remain a significant source of risk, and businesses must comply with a growing number of regulatory mandates.
While 73% of SMBs are integrating artificial intelligence (AI) into their operations, they acknowledge the new risks this introduces. A plurality of respondents cited AI-powered malware as their most concerning threat. However, current data suggests that AI-powered malware is still relatively uncommon. Instead, the most frequent causes of incidents are phishing and unpatched vulnerabilities, consistent with findings from other sources like Verizon's latest report, which lists exploitation and phishing among the top three initial access vectors for SMBs. Weak passwords and a lack of security monitoring also rank high as vulnerabilities.
The more immediate threat from AI often comes from within, with "shadow AI" being a common non-malicious insider action. Nonetheless, AI and automation are enabling threat actors to enhance their capabilities in social engineering, vulnerability research, and exploitation. SMBs are keen to leverage AI to counter these threats, using it for anticipating attacks, faster identification and mitigation, and detecting social engineering. The challenge lies in the availability and accessibility of such tools for SMBs.
The report indicates that cybersecurity awareness training significantly strengthens an SMB's cyber-readiness posture. However, adoption rates are notably higher among businesses that have experienced multiple incidents (81% versus 53% for those with fewer incidents). These organizations also report higher confidence in their resilience, possibly due to the reactive implementation of best-practice security measures after an incident. Ideally, SMBs would proactively embrace cyber readiness rather than learning lessons through adverse events.
Despite the challenges, there is positive news: four out of five respondents consider their security budgets sufficient, with half expecting an increase next year. This suggests strategic planning, including outsourcing when financially and operationally sensible. Confidence in cyber resilience has surged from 48% in 2022 to 87% this year. However, experts caution against complacency, as cyber readiness and resilience are ongoing processes, not an end state.
SMBs should continuously focus on prevention-first technologies and processes, including regular training, consistent patching, and robust identity management. Realistic and frequent risk assessments are crucial for prioritizing security investments, and effective incident response plans are necessary for faster recovery and reduced business impact. Outsourcing capabilities like managed detection and response (MDR) can be beneficial, as can improved governance to mitigate shadow IT and AI.
Even with smart budgeting, a quarter of SMBs believe additional funds would accelerate improvements in their cybersecurity posture. Complexity and integration remain significant hurdles for businesses with fewer resources. They seek reliable, feature-rich, and user-friendly services and solutions. The cybersecurity vendor community is urged to provide more accessible tools to enhance the cyber readiness of small businesses, recognizing that there is no single "silver bullet" solution. The journey towards enhanced resilience is continuous, requiring vigilance and adaptability as technology and threats evolve.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed