Commonwealth Sentinel: Cyber Security Consulting

Commonwealth Sentinel: Cyber Security Consulting At Commonwealth Sentinel, we focus on cyber security so you can focus on other things.
for local government, non-profit, and small business.

09/03/2026

The Kentucky Administrative Office of the Courts has confirmed that the filing system used by the Kentucky Supreme Court and the Court of Appeals was part of a cyber security incident affecting twelve jurisdictions. The unauthorized access took place in March and was discovered on June 30, according to court officials.

That system, called C-Track, is operated by an outside vendor, Thomson Reuters Court Management Solutions. The information potentially exposed includes names, Social Security numbers, driver's license numbers, dates of birth, and medical and health insurance information. Trial court records were not affected, because Kentucky courts at that level use separate internal e-filing systems. Anyone whose information was involved is being offered one year of credit monitoring and identity theft protection.

The vendor is the detail that matters most for every other organization reading this. A court, a city hall, or a small business can run its own systems carefully and still be exposed through a contractor that holds its records. Ask every vendor who touches your data what they store, where they store it, and how quickly they would tell you if something went wrong.

Read more in the comments.

Commonwealth Sentinel, 502-234-5554.

09/02/2026
Google and Mozilla both pushed browser updates this week. Chrome 152 fixes 26 flaws, two of them rated critical. Firefox...
09/02/2026

Google and Mozilla both pushed browser updates this week. Chrome 152 fixes 26 flaws, two of them rated critical. Firefox 155 fixes 29, with 13 rated high.

No one has reported attacks using these yet. That is the useful part. The gap between a patch going out and someone building an attack around it is usually short, so this is worth doing now rather than Friday.

Updating takes about a minute. Close every browser window, then open it again. In Chrome, check Settings and then About Chrome. In Firefox, check the Help menu and then About Firefox.

If your office has ten computers, ten people need to do this. Someone should check that they did.

Questions about keeping your systems current? Call us at 502-234-5554.

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

Has a package you didn't order ever shown up at your house? It happens more than you'd think, and the FTC put out an ale...
09/02/2026

Has a package you didn't order ever shown up at your house?

It happens more than you'd think, and the FTC put out an alert about it last week. Something small and cheap arrives with your name on the label. Inside there's a little card with no sender on it and a QR code. Scan this to find out who sent your gift.

Don't scan it. The page on the other side is built to take your card number and your password, and the FBI says some of these codes push you to install an app that quietly pulls data off your phone.

Here's the part most people don't know: you get to keep the item. Federal law says merchandise you didn't order and didn't agree to buy is yours. No returning it, no paying for it.

The reason this works isn't clever. You can hover over a link in an email and see where it goes. You can't do that with a QR code. It's just a picture, and this one came to your porch in a box instead of landing in your spam folder.

Full piece in the comments, including the five things to actually do with the box. 🔗 👇️

09/01/2026

Almost 22,000 Microsoft Exchange servers are still sitting online without the fix Microsoft shipped in August. Exchange is the software that runs company email. An attacker who gets in through this hole can read every mailbox on the server, send mail as anyone in the office, and pull down attachments. The code to break in is now public.

Most small offices and city halls do not run their own mail server anymore. If your email is Microsoft 365 in the cloud, this one is not yours to worry about. But plenty of counties, school districts, and family businesses still have a server in a closet somewhere. If that is you, the question for your IT person today is short: are the August updates installed?

If you are running Exchange 2016 or 2019, there is a second question behind it. Microsoft ends support for those versions in October. After that, the next flaw will not come with a fix. Plan the replacement now, while it is still a line item and not an emergency.

Full story in the comments.

People assume paying the ransom ends it. Often it does not.Plenty of organizations have paid and never received a workin...
09/01/2026

People assume paying the ransom ends it. Often it does not.

Plenty of organizations have paid and never received a working key. Others got their files back and then heard from the same people again, because the attackers had already copied the data and could sell it or threaten to publish it. Some now go a step further and pressure the customers whose information was in the file.

That is the shape of it today. Paying is a hope, not a plan.

The plan looks like this, and it is written down before anything happens:

Who gets called first, with phone numbers that work when email is down.

Which machines get unplugged from the network, and who has authority to say so at two in the morning.

Where the backups are, when they were last tested, and how long a restore actually takes.

Who talks to staff, to customers, and to the press, and what gets said in the first hour.

The organizations that come through this well are rarely the ones with the best software. They are the ones who decided, in advance and in writing, what they would do.

If you would like help building that plan, we are at 502-234-5554.

Ransomware Attack is something you have probably heard and read a lot about. but if it happens to you, what happens next?

One wrong letter is a business model.Somebody registers the address that sits one keystroke away from the real one. A do...
08/31/2026

One wrong letter is a business model.

Somebody registers the address that sits one keystroke away from the real one. A doubled letter. A missing s. A dot net instead of a dot com. Then they build a page that looks exactly like the site you meant to visit and wait for the ordinary human mistake of typing too fast.

It is called typosquatting. The pages copy banks, Microsoft, Apple, Google, and plenty of smaller names too, because the point is to catch you when you are moving quickly and not looking closely.

What helps, and none of it is complicated:

Bookmark the sites where you log in and use the bookmark instead of typing. This one habit removes most of the risk by itself.

Read the address bar before you type a password. The whole address, not just the part that looks familiar.

Use a password manager. It will not fill your password on a lookalike site, because it knows the difference even when you do not.

Do not reach important sites through links in unsolicited email. Go there yourself.

Most cyber incidents start with an honest mistake by a careful person. The habits above are how you make the mistake harmless.

Typosquatting is much more sinister than a simple typo when messaging your friends and can put you at risk on the internet.

If your city, your business, or your nonprofit runs its website on WordPress, this one is worth ten minutes of somebody'...
08/30/2026

If your city, your business, or your nonprofit runs its website on WordPress, this one is worth ten minutes of somebody's time this week.

Researchers flagged critical flaws in five widely used add-ons: the WPMU DEV dashboard, the Avada theme, TranslatePress, Pods, and GiveWP. Several of them let an attacker who is not logged in at all take over an administrator account or run their own code on the site. GiveWP handles donations, so nonprofits should look there first.

The fix is ordinary maintenance. Sign in, open the plugins and themes page, and update anything on that list to the current version. If a contractor built the site and you have not heard from them lately, ask.

If you want to talk through where your website sits in your overall risk picture, call us at 502-234-5554.

Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code ex*****on.

Somebody in your office is running the place on a free app you have never heard of.Not out of spite. Out of usefulness. ...
08/30/2026

Somebody in your office is running the place on a free app you have never heard of.

Not out of spite. Out of usefulness. The approved system is slow, so they moved the schedule to a spreadsheet in their own cloud drive. The group chat lives on their phone. The file that was too big for email went out through a service they found in ten seconds.

That is shadow IT, and every organization has it. Yours does too.

Here is the part worth understanding. When that employee leaves, or loses the phone, or their teenager uses the same laptop, the organization's records go with it, and nobody knows to look.

The fix is not a ban. Bans just push it further into the dark.

Ask what people are actually using, and make clear the asking is not a trap.

Find out what problem each tool solves. Usually it is a real one you did not know about.

Approve the ones that hold up, replace the ones that do not, and write down where the line is.

You cannot protect what you do not know you have.

Have you ever connected personal devices to the work Wi-Fi without permission? Most of us have. That is what is known as Shadow IT

You would not ask the person who maintains your trucks to decide how much liability insurance the company carries.Yet th...
08/29/2026

You would not ask the person who maintains your trucks to decide how much liability insurance the company carries.

Yet that is roughly what happens when cyber security compliance gets handed to the IT department and called done. IT keeps the systems running. Deciding how much risk an organization is willing to accept is a leadership decision, and it stays with leadership whether or not leadership is paying attention.

Two places this shows up hard.

Insurance. Many cyber policies require specific safeguards to be in place. If they are not, the claim can be denied, and the person who signed the policy is the one holding the bag. Read what your policy actually requires. Ask your IT provider, in writing, whether each item is in place.

Policy. Rules about passwords, data handling, and who may use what belong to management. So does enforcing them. A written policy nobody enforces is worse than none, because it documents that you knew.

Your IT people should be in the room for these conversations. They should not be left alone in it.

Have you ever considered what would happen if your outsourced IT could not keep up with your organization's growth and cyber security compliance needs?

Address

210 King's Daughters Drive
Frankfort, KY
40601

Alerts

Be the first to know and let us send you an email when Commonwealth Sentinel: Cyber Security Consulting posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share