Back to blog
Deal Diligence 2 min read

CYBER FRIDAY

CYBER FRIDAY
YJ

Yasmine Johnston-Ison

Three CISA alerts in the last ten days. Two ransomware crews casting wide nets. A patch deadline that lands this Friday. If you're closing on a business right now, cyber hygiene is diligence.

This week's roundup:

  • Citrix NetScaler under active attack — CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on Aug 26, with a remediation deadline of Aug 29. If your target company uses Citrix for remote access, the clock is already ticking. (Source: CISA)
  • Qilin ransomware on a tear — The Qilin group claimed hits on the US Bureau of ATF and a Florida specialty-finance firm this week alone. Same crew, wide net — ransomware operators aren't just chasing Fortune 500s. (Sources: ATF, BreachSense)
  • Microsoft SQL Server RCE still in the wild — CISA added a 2019-era SQL Server remote code execution flaw (CVE-2019-1068) to its KEV catalog on Aug 26. Seven-year-old vulnerabilities in business-critical databases are exactly the kind of thing that survives a sloppy ownership handoff. (Source: CISA / GBHackers)

The deal lens:

When you acquire a small business, you inherit its IT debt — every unpatched server, every forgotten appliance, every default password the prior owner never changed. A Citrix box past its patch deadline or a SQL Server running a seven-year-old flaw isn't an IT ticket; it's deal risk. Cyber diligence isn't checking a box — it's understanding what you're actually buying before the ransomware note arrives.

What's on your diligence checklist? If cyber isn't a line item yet, let's talk.

#CyberSecurity #ThreatIntel #SMBAcquisition #DueDiligence

Need Structured Guidance for Your Acquisition?

Book a 45-minute strategy call with our team to discuss your search progress, deal thesis, or transition plans.

Book an Appointment

45 minutes to confirm fit and define next steps.