Back to Blog
Cybersecurity AI Managed IT Small Business

AI-Powered Cyberattacks: What Australian Small Businesses Actually Need to Know in 2026

By CloudGeeks Team | 2 September 2026 | 9 min read

There is a lot of noise about AI and cybersecurity at the moment, most of it either vendor marketing or vague alarm. This is an attempt at the version a Sydney small business can actually use: what changed this year, what it means for a twenty-person company with a WordPress site, and what is worth doing about it.

The short version is not “AI hackers are coming for you”. It is more specific and more useful than that.

Not chosen, just found: not personally targeted, but found faster by automation

What actually changed

For as long as anyone has been doing this work, the scarce resource in security was finding the flaw. Skilled researchers were few, their time expensive, and the amount of software worth examining effectively infinite. Everything downstream — triage, patching, disclosure — was sized around that scarcity.

That has shifted, and there are public numbers.

Vulnerability discovery has become cheap at scale. Anthropic’s Project Glasswing reported more than 10,000 high and critical severity vulnerabilities identified, with access expanding from around 50 to roughly 150 organisations. The programme’s own summary names triage and remediation — not discovery — as the bottleneck.

Small, unmaintained software is now worth examining. This is the part with the widest blast radius for small business. A security researcher used a current model to review dozens of WordPress plugins and found 16 confirmed vulnerabilities, concentrated in smaller, less-maintained ones. That category was previously protected mostly by not being worth a human researcher’s afternoon.

“Nobody has looked at this” was never a security property. It just functioned as one, and it is going away.

Three public numbers: 10,000 high and critical, 16 plugin vulnerabilities, 75 to 259 a week

The window after disclosure has narrowed. In the three weeks after a WordPress core remote code execution flaw was disclosed this year, one security vendor reported attacks against it rising from about 10,000 to over 900,000 per day, with attackers rapidly cycling variations of the technique.

Ninety-fold in three weeks. Our colleague at Ash Ganda wrote the technical analysis of what that does to patch policy; this is the commercial translation.

Three weeks after disclosure: about 10,000 a day rising to over 900,000 a day

What this does and does not mean for you

Let us be accurate, because the alarming version of this story is not the true one.

You are not being personally targeted. Nothing about this makes a twenty-person accounting firm in Parramatta interesting to a skilled attacker. That was never the risk and it still is not.

The risk is that you are found faster by automation. Attacks against small businesses are overwhelmingly opportunistic and automated. Software scans the internet for a known flaw and exploits everything it finds. What has changed is the number of known flaws, the speed at which exploitation ramps up after disclosure, and the fact that the long tail of obscure plugins is now being examined.

The exposure window is what matters. If a flaw in a plugin you run is disclosed on Monday, and attacks against it are at scale by Wednesday, and you patch whenever someone next logs in — the gap between those is your actual risk. Not your firewall, not your antivirus. The gap.

We looked at what patching that stream costs an Australian small business recently, and the volume alone makes the point: over a recent five-week stretch, Wordfence disclosed between 75 and 259 WordPress vulnerabilities per week. One week saw 249.

Most of those will never affect you. You do not run most of that software. But you will not know which ones matter unless somebody is looking.

The number that actually describes your exposure

Not “are we patched?” — that is a snapshot and it flatters you.

How many hours from a disclosure that affects you, to that disclosure being closed on your systems?

Most small businesses cannot answer this, and the honest answer is usually “whenever someone next logs in”, which can be weeks. Set that against attacks reaching scale within days of disclosure and the mismatch is not subtle.

If you take one thing from this article, make it the decision to find out what your number is. Everything else is downstream of it.

The number that matters is hours to patched, and most cannot answer it

What is actually worth doing

Not more scanning. Most businesses already generate more security findings than they act on, and adding a faster generator to an unchanged process produces a longer backlog rather than lower risk.

Fix the order: response time first, detection after

Four things move the needle, in order of value.

Four things in order: know what you run, reduce what you run, assign patch response, close the basics

1. Know what you run. When a disclosure lands, the first question is “are we affected?” — and most businesses cannot answer it quickly. A current list of your sites, plugins, versions and who owns each one is unglamorous, is usually a spreadsheet, and is the single highest-leverage item here. Every hour spent working out what you run is an hour inside the exposure window.

2. Reduce what you run. Every plugin you remove is a vulnerability you will never need to patch. Most WordPress sites we audit carry several plugins nobody can account for, at least one abandoned by its author. That is free risk reduction and it takes an afternoon.

3. Decide who owns patch response, and what “promptly” means. It can be you, a maintenance plan, or a provider. What it cannot be is unassigned — unassigned means whenever somebody happens to notice. Put a number on it: 48 hours for critical, a fortnight for the rest, is a reasonable small-business standard.

4. Get the basics closed. Multi-factor authentication on every account that can install software. Current versions. Backups you have actually restored. Security headers set. None of this is exciting and all of it is what actually stops opportunistic automation. Our under-an-hour audit checklist walks the whole set.

What AI does not change

Worth saying, because the marketing implies otherwise.

It does not make the fundamentals obsolete. The businesses being compromised this year are overwhelmingly being compromised through unpatched software, reused passwords and accounts that should have been closed — the same three as last year. Faster discovery makes the unpatched-software route more dangerous. It does not introduce a new one that bypasses MFA and current versions.

It also does not mean you need an AI security product. If your patch response time is measured in weeks, buying a tool that finds problems faster makes the queue longer, not the business safer.

Fix the response time first. Then, if you have budget left, spend it on detection. In that order, because the reverse is how businesses end up with an expensive dashboard and the same exposure.

Where a provider helps

Honestly: the value is not access to better technology. It is that patch response becomes somebody’s actual job, with a number attached, rather than a task that competes with running your business.

If you are evaluating one, the questions worth asking are narrow:

  • What is your target time to patch a critical vulnerability, and how do you measure it?
  • Do you maintain an inventory of what we run, and can I see it?
  • How do you find out a disclosure affects us?
  • When did you last restore one of our backups?
  • What happens out of hours?

Vague answers to those are informative. A provider doing this properly answers each in a sentence.


Frequently asked questions

Are AI-powered cyberattacks a real threat to small business? The realistic risk is not a sophisticated attacker choosing you. It is that vulnerability discovery has become much cheaper, so more flaws are found in more software — including the small, unmaintained plugins that were previously ignored — and automated exploitation ramps up faster after disclosure.

Does this mean I need AI security software? Usually not, and not first. If your response time to a known vulnerability is measured in weeks, faster detection lengthens the queue rather than reducing risk. Close the response gap before buying detection.

What is the single most useful thing to do? Find out how long it currently takes you to patch a disclosed vulnerability that affects you. Most businesses have never measured it, and it is the number that describes actual exposure.

Are WordPress sites especially at risk? WordPress is not less secure than alternatives, but it is common, and its plugin ecosystem is large and unevenly maintained. High volume plus a long tail of unmaintained code is what makes it attractive to automated attacks.

How quickly should we patch? For a small business, 48 hours for critical vulnerabilities and a fortnight for everything else is a defensible standard — provided somebody owns it and it is measured rather than assumed.


CloudGeeks provides managed IT, cloud and cybersecurity for Sydney businesses, including patch management with defined response times. Websites and technical SEO sit with Cosmos Web Tech; mobile apps with Awesome Apps. All divisions of GTS.

Ready to upgrade your IT and cloud setup?

Let's talk about cloud, infrastructure, or cybersecurity. We help Sydney SMBs cut hosting costs, harden their stack, and stop firefighting.

Bella Vista, Sydney