BaltimoreCyber Brief
All briefs
31 August 2026·4 min read

QuickBooks phishing is hitting the islands, and exploited vulnerabilities are still the fastest way in. This week: stop payment fraud, close the obvious doors.

Channel IslandsPatch prioritisationPayment fraud prevention

In 30 seconds

  • Guernsey Cyber Security Centre has flagged a QuickBooks themed phishing campaign. The real risk is payment diversion and supplier fraud, so the fix is as much process as it is technology.
  • CISA added new exploited CVEs to the KEV catalogue this week, including an ownCloud vulnerability (CVE-2023-49105). If you have the affected products in your estate, treat it as a live incident prevention task, not a backlog item.
  • PaperCut NG and MF are being exploited in the wild. Print management is often overlooked, but it can be a foothold into internal networks if it is exposed or unpatched.

Why it matters

For regulated Channel Islands organisations, the damage is rarely limited to IT. A successful phishing lure aimed at finance teams can lead to misdirected payments, client impact, and a messy recovery effort that involves banks, auditors, and regulators.

At the same time, KEV additions are a reliable weekly signal of what attackers are actively using right now. You do not need perfect vulnerability management to get value from this. You need a simple routine: check whether you are exposed, patch or mitigate quickly, and keep evidence so you can demonstrate control.

This week's theme is ownership. Ownership of finance workflows: how you approve and verify payments. And ownership of your attack surface: what is internet-facing, who patches it, and how quickly you can prove it is done.

Questions to ask your team this week

  1. 1.For the QuickBooks themed phishing lure, what is our control for payee changes and new supplier onboarding, and is out-of-band verification mandatory?
  2. 2.Do we have a weekly KEV review with named owners, and can we show patch or mitigation evidence for anything that applies to our estate?
  3. 3.Do we run PaperCut NG or MF anywhere, including at suppliers who provide managed print, and who is accountable for patching and exposure checks?
  4. 4.If a phishing-led payment diversion happened tomorrow, who leads containment, bank engagement, client communications, and any regulator notification decisions?

One thing to do this week

Run a 60-minute finance payment diversion drill. Pick one real supplier, simulate a bank detail change request, and test whether your process forces an out-of-band verification step before any payment is released. Capture what worked, what did not, and tighten the workflow.

Sources

  • GCSC, "Phishing Investigation: Intuit QuickBooks":
    gcsc.gg
  • CISA, "CISA Adds Three Known Exploited Vulnerabilities to Catalog" (27 August 2026):
    cisa.gov
  • BleepingComputer, "PaperCut warns of NG, MF flaw exploited in zero-day attacks":
    bleepingcomputer.com

Want to discuss anything from this week's brief?

Join the conversation on LinkedIn