Commonwealth Sentinel Cyber Security
@cwealthsentinel
At Commonwealth Sentinel, we focus on cyber security so you can focus on other things.# CyberSecurity for local government, non-profit, and small business. #FemaleFounder
CISA is urging every organization running on-prem SharePoint Server to act now: three flaws are under active attack, two more are critical. This is the self-hosted version, not the Microsoft 365 cloud most small offices use. Patch, enable AMSI, check your logs. More in the thread. #CyberSecurity
One clear thing worth knowing, every Friday. No jargon, no scare tactics, just plain advice for people who run real organizations. That's Be Cyber Safe, our free weekly newsletter. One subscriber a month wins a free security scan. Sign up at CommonwealthSentinel.com
Car insurance doesn't make it okay to drive drunk. Same goes for cyber insurance: it helps you recover after an attack, it doesn't prevent one. Most insurers now require basics like MFA before they'll write a policy. More in the thread. #CyberSecurity #CyberInsurance
Cyber attacks are climbing: UK up 34% in June, global up 17%. Attackers are widening their reach and ransomware groups keep reshuffling. You can't control the trend, but you can control the basics: back up, turn on a second login step, patch, train your people. More in the thread. #CyberSecurity
Ransomware attacks rose 20% in the first half of 2026. Small and midsize businesses took more than 60% of the hits, because they're often the least defended. Back up your data, turn on a second login step, train your people. More in the thread. #CyberSecurity
Email is still one of the easiest ways for a bad actor to get into your network. They only need to get it right once. You need to get it right every time. Policies, training, and a second login step (MFA) help close that gap. More in the thread. #CyberSecurity #EmailSecurity
If you use Firefox or Chrome, update today. Mozilla and Google just patched critical flaws, and for two Firefox bugs the exploit code is already public. Adobe and VMware pushed fixes too. Updates aren't busywork, they close the doors attackers use. More in the thread. #CyberSecurity
An antivirus and a firewall are a start, not a finish line. Real protection layers people, policies, device protection, and monitoring together. Think defense in depth, not one lock on one door. More in the thread. #CyberSecurity #DataSecurity
95% of data breaches trace back to an employee mistake, usually one click on a bad link. Security training can cut the impact of an attack by more than 70%. Best return on investment in cyber security, full stop. More in the thread. #CyberSecurity #SecurityTraining
This week: ShinyHunters breached 100+ orgs (incl. Nissan) via an Oracle PeopleSoft flaw, Aflac exposed 4.38M customers' bank data, and an actively exploited SharePoint RCE hit CISA's KEV list. Our Top 5 cyber stories, explained link in comments 👇️
Leaders don't need to be cyber security experts. They do need straight answers: what are we protecting, who has access, is the budget enough, what's the plan if something happens. Five questions worth asking this week. More in the thread. #CyberSecurity #Leadership
Half of local governments with the tools to detect cyber attacks report being attacked daily. Unlike a business, a government can't close its doors and start over. When systems go down, so does dispatch, the courthouse, water service. More in the thread. #CyberSecurity #LocalGovernment
"ILoveYou" is one of the top 20 passwords showing up in Dark Web data breaches. So are "123456," "Qwerty," and "Password." If any of these look familiar, today's the day to change them. More in the thread. #CyberSecurity #PasswordSecurity
A recent survey found cyber security is now the top priority for city and county CIOs, ahead of broadband and citizen engagement. IT keeps your operations running. Cyber security protects those operations. Two different jobs. More in the thread. #CyberSecurity #LocalGovernment
CryptoCore stole an estimated $5.4M from crypto users in 6 months using deepfakes and hijacked YouTube channels. Here's how the scam worked, and how to spot a deepfake before it costs you. Case study below. #CyberSecurity
The toughest phishing emails to catch look like they came from a coworker or a company you trust. Before you act on a request for account info or a payment, call and verify it yourself using a number you already have. More in the thread. #CyberSecurity #Phishing
Vishing is voice phishing by phone. The caller pretends to be your bank, the IRS, or a utility, and pushes you to act immediately. The fix: hang up, then call the organization back yourself using a number you already know is real. More in the thread. #CyberSecurity #Vishing
Nearly half of all cyber attacks target small businesses. The average cost runs about $200,000. Only 14 percent of small businesses say they are prepared for one. Preparation does not have to be complicated. It has to start.
Researchers say a ransomware attack, JadePuffer, ran almost entirely on an AI agent. It broke in, stole credentials, and encrypted data on its own, adjusting when steps failed. The way in was a flaw patched over a year ago. More in the thread. #CyberSecurity #Ransomware READ MORE LINK IN COMMENTS
Happy Fourth of July from the Commonwealth Sentinel team. Today we are grateful for those who have served and continue to serve the Commonwealth, in uniform and in public office alike. Wishing you and yours a safe and meaningful holiday.