In 30 seconds
- Guernsey Cyber Security Centre has flagged a QuickBooks themed phishing campaign. The real risk is payment diversion and supplier fraud, so the fix is as much process as it is technology.
- CISA added new exploited CVEs to the KEV catalogue this week, including an ownCloud vulnerability (CVE-2023-49105). If you have the affected products in your estate, treat it as a live incident prevention task, not a backlog item.
- PaperCut NG and MF are being exploited in the wild. Print management is often overlooked, but it can be a foothold into internal networks if it is exposed or unpatched.
Why it matters
For regulated Channel Islands organisations, the damage is rarely limited to IT. A successful phishing lure aimed at finance teams can lead to misdirected payments, client impact, and a messy recovery effort that involves banks, auditors, and regulators.
At the same time, KEV additions are a reliable weekly signal of what attackers are actively using right now. You do not need perfect vulnerability management to get value from this. You need a simple routine: check whether you are exposed, patch or mitigate quickly, and keep evidence so you can demonstrate control.
This week's theme is ownership. Ownership of finance workflows: how you approve and verify payments. And ownership of your attack surface: what is internet-facing, who patches it, and how quickly you can prove it is done.
Questions to ask your team this week
- 1.For the QuickBooks themed phishing lure, what is our control for payee changes and new supplier onboarding, and is out-of-band verification mandatory?
- 2.Do we have a weekly KEV review with named owners, and can we show patch or mitigation evidence for anything that applies to our estate?
- 3.Do we run PaperCut NG or MF anywhere, including at suppliers who provide managed print, and who is accountable for patching and exposure checks?
- 4.If a phishing-led payment diversion happened tomorrow, who leads containment, bank engagement, client communications, and any regulator notification decisions?
One thing to do this week
Run a 60-minute finance payment diversion drill. Pick one real supplier, simulate a bank detail change request, and test whether your process forces an out-of-band verification step before any payment is released. Capture what worked, what did not, and tighten the workflow.
Sources
- GCSC, "Phishing Investigation: Intuit QuickBooks":
gcsc.gg - CISA, "CISA Adds Three Known Exploited Vulnerabilities to Catalog" (27 August 2026):
cisa.gov - BleepingComputer, "PaperCut warns of NG, MF flaw exploited in zero-day attacks":
bleepingcomputer.com

