The Latest Threats Facing UK Small Businesses: Critical Exploits Uncovered
Unpack today's critical vulnerabilities threatening small businesses: IBM, Spikster, and WordPress under fire.
Read more →
Intelligence analyst
Threat intelligence for small businesses, with clinical precision.
Subscribe to Corrine Jefferson’s articles (RSS)Corrine brings a threat intelligence background to the publication. She thinks in terms of threat actors, attack surfaces, indicators of compromise, and risk matrices, and she is exact with her terminology: threats, vulnerabilities, and risks are not the same thing, and she will tell you which is which.
She writes the Tuesday deep-dive, the longest and most technical slot, framed around the threat landscape: who is attacking, why, how, and what the indicators look like. Her aim is situational awareness, not just another checklist.
She does not speculate or sensationalise, and where the evidence is unclear she says so. However deep the technical detail runs, she always brings it back to what a small business owner actually needs to know and do.
Unpack today's critical vulnerabilities threatening small businesses: IBM, Spikster, and WordPress under fire.
Read more →
Newly discovered vulnerabilities expose UK businesses to unauthorised access and serious risks. Here's what you need to know.
Read more →
Discover critical security flaws in IBM WebSphere impacting UK small businesses. Act now to secure your operations.
Read more →
FortiOS and VeloCloud vulnerabilities expose UK SMBs to critical risks. Don't wait, take action now.
Read more →
Fastjson and Cl0p ransomware exploitations are active. Know the risks and defensive steps.
Read more →
Microsoft Exchange and Azure vulnerabilities demand immediate attention from UK SMEs.
Read more →
Exploited vulnerabilities in SharePoint and Oracle put small businesses at risk. Act fast to secure your infrastructure.
Read more →
WordPress and Oracle flaws threaten UK SMBs. Here's what you need to do now to secure your business.
Read more →
Three stories this week. All of them matter. One of them is watching your car park right now.
Read more →
Two serious vulnerabilities landed this week. One was exploited before anyone even knew it existed. Here is the plain-English briefing for UK small businesses.
Read more →
CISA added a Microsoft SharePoint remote code execution flaw to its active exploitation list on 16 July 2026. Here is what UK small businesses need to do today.
Read more →
570 Microsoft patches. A Windows zero-day PoC published hours later. A building automation protocol now on the CISA KEV list. This week is not one to ignore.
Read more →
Two Microsoft zero-days are being actively exploited right now. One requires no login whatsoever. Here is what to do before close of business.
Read more →
Attackers are executing arbitrary code on Joomla websites right now. CISA confirmed it. Here is what UK small businesses need to do today.
Read more →
Two critical vulnerabilities this week prove that your security tools are now the target. Here is the plain-English briefing.
Read more →
CVSS 9.8. No authentication required. A WordPress plugin flaw published yesterday lets attackers run arbitrary code on your server. Here is what it means.
Read more →
A perfect-10 Adobe flaw exploited within two hours. Hundreds of unpatched RMM servers still exposed. Two stories your IT provider needs to hear today.
Read more →
A SharePoint vulnerability is being actively exploited right now. CISA confirmed it. Microsoft sat on the disclosure for weeks. Here is what you need to know.
Read more →
SharePoint has a confirmed, actively-exploited code execution flaw. CISA added it to the KEV list yesterday. If your business uses SharePoint, read this now.
Read more →
A maximum-severity flaw in SimpleHelp RMM is being actively exploited. Attackers are walking straight through your MSP's front door. Here is what that means for your business.
Read more →
The remote support tool your IT provider uses to fix your computers has a flaw that lets attackers walk straight in. No password required.
Read more →
WordPress plugin flaws and a Cisco exploit are high-risk for UK SMBs. Urgent updates recommended.
Read more →
Lantronix and UniFi OS vulnerabilities demand immediate attention from UK SMEs to prevent breaches.
Read more →
An authentication bypass leaves a quiet signal: admin activity, not exploit traffic. Most small businesses are not watching for it.
Read more →
Ignoring IBM Langflow and WordPress plugin threats could sink your SMB. Here's what you need to know.
Read more →
Legacy routers infected by AryStinger show why UK SMBs need to update their network security.
Read more →
Three threats that landed overnight. One is actively exploited right now. Here is what UK small businesses need to know before Friday.
Read more →
Microsoft has confirmed a Defender zero-day with no patch in sight. If your business runs Windows, this is not a drill.
Read more →
CISA confirmed active exploitation of a Joomla plugin flaw on Tuesday. Microsoft has no patch for its Defender zero-day. Two fires, one week. Here is what to do.
Read more →
Two critical vulnerabilities confirmed in active exploitation this week. If you run Joomla or use any web application with token-based login, read this now.
Read more →
Three stories from the last 24 hours that should matter to every small business in the UK. Two are actively exploited. One was patched three weeks after it was found.
Read more →
Splunk has a 9.8-rated unauthenticated remote code execution flaw. You probably don't run Splunk. Your MSP might. That's the problem.
Read more →
478 victims, worm-like spread, and a BitLocker bypass that works on patched Windows. This week's threats are not theoretical. Here is the brief.
Read more →
No credentials required. A WordPress plugin flaw published yesterday lets unauthenticated attackers create admin accounts. Here is what to do before lunch.
Read more →
Microsoft's biggest-ever Patch Tuesday, a critical Veeam backup flaw, and a WordPress plugin that hands attackers your server. Three stories. One to-do list.
Read more →
Attackers bypassed Check Point VPN passwords in the wild before a patch existed. If your remote access still runs IKEv1, you are already compromised.
Read more →
Cisco SD-WAN and SolarWinds Serv-U are both being actively exploited this week. One has no patch. Here is the data, stripped of vendor spin.
Read more →
CISA just added two actively exploited flaws to its KEV catalog. If you run WordPress or Magento, you are in the crosshairs today.
Read more →
Two WordPress flaws scored 9.8. An unpatched Windows credential leak has no CVE number. Here is what UK small businesses need to act on this week.
Read more →
Attackers are actively exploiting a critical Windows Netlogon flaw. No login required. One packet and your domain controller is compromised.
Read more →
Palo Alto's GlobalProtect VPN has a confirmed authentication bypass under active exploitation. If you haven't patched, your network perimeter is already open.
Read more →
Fake Fortinet patches, AI-driven database raids, and a WordPress plugin handing out admin rights to strangers. Three stories that matter this week.
Read more →
Attackers can brute-force their way into any WordPress account in minutes. A Windows kernel flaw hands them SYSTEM privileges. Both need fixing today.
Read more →
Joomla has three privilege escalation flaws scored 9.8. Ghost CMS is already being exploited across 700 websites. SharePoint needs patching now.
Read more →
Seven hundred-plus websites turned into traps. One fake CAPTCHA. One click. Full device compromise. This is ClickFix, and it is coming for your team.
Read more →
Drupal's being actively exploited right now. 15,000 attempts, 65 countries, CISA confirmed. If your site runs Drupal, you have a deadline of 27 May.
Read more →
Three WordPress plugins just handed attackers the keys to your website. CVSS 9.8. No login required. Here is what to do before Friday.
Read more →
A USB stick defeats BitLocker. Three WordPress plugins hand attackers full admin access. The intelligence is clear. Here is what to do about it.
Read more →
CISA confirmed active exploitation of a Microsoft Exchange vulnerability this week. UK small businesses running on-premise email need to act today.
Read more →
NGINX powers roughly a third of the web. CVE-2026-42945 is being exploited right now. Here is what UK small businesses need to do before Friday.
Read more →
Three critical flaws landed overnight. WordPress sites, Microsoft Authenticator, and on-premises email are all in the frame. Here is the data, without the spin.
Read more →
A wormable Windows Server flaw, a payment platform with a forgeable secret key, and 130 patches. Here is what matters to your business this week.
Read more →
120 vulnerabilities. A critical Windows Netlogon flaw. A Windows DNS buffer overflow. This is not a drill. Here is what to do this week.
Read more →
Three stories this week that every UK small business owner needs to hear. One phishing email. Twenty months undetected. One million pounds.
Read more →
Strip out Microsoft licensing. If your provider is below £50 per user per month outside London or £75 inside it, something has been removed. The maths does not lie.
Read more →
Attackers can own your WordPress store without a password. cPanel has fresh critical flaws. CISA just confirmed active exploitation of Ivanti. Three reasons to act today.
Read more →
Attackers are inside Ivanti EPMM before patches existed. If your business manages mobile devices, this is not someone else's problem.
Read more →
A critical Palo Alto firewall flaw is being actively exploited with no patch yet available. If your MSP manages a PAN-OS device, ask them one question.
Read more →
A single broken cryptographic signature took large parts of Germany's internet offline. Your business has the same invisible dependency.
Read more →
WordPress sites can be taken over without a password. A Linux root exploit is being actively weaponised. And a nation-state group is still walking through Exchange servers that weren't patched in 2021.
Read more →
Phishing caused 69% of the most disruptive breaches. 51% of victims were hit by phishing alone. The fight has moved from inboxes to identity controls.
Read more →
cPanel is on CISA's active exploit list. MOVEit has a new authentication bypass. Your cheap router may already be compromised. Here is what matters today.
Read more →
CISA confirmed active exploitation of a Linux root access flaw this week. If your business runs Linux anywhere, including on a NAS or cloud VM, read this now.
Read more →
Unauthenticated attackers can upload malware or log in as your site admin right now. Two critical WordPress flaws. No patch excuses.
Read more →
44,000 hosting control panels confirmed compromised. A WordPress plugin is handing out admin access to anyone who asks. This week's threats are not theoretical.
Read more →
Public exploit code for a Linux root access flaw has defenders scrambling. If your business runs Linux anywhere, this is not a drill.
Read more →
Russian state hackers are in your Windows machine without a click. Five router flaws scored 9.8 overnight. This week's threat brief cuts through the noise.
Read more →
Nineteen critical flaws. One router model. All exploits published. If your office uses a Totolink A8000RU, you are already exposed.
Read more →
CISA just added SimpleHelp remote support vulnerabilities to its actively-exploited list. If your IT provider uses it, attackers may already have a path in.
Read more →
61% of organisations were breached through their supply chain last year. Just 7% monitor beyond immediate suppliers. That is a structural failure, not bad luck.
Read more →
Attackers are weaponising the same remote access tools your IT team uses. Sophos has the receipts. Here is what happened and what you need to do.
Read more →
Two working exploits in one week. One public, one confirmed in the wild. Neither fully patched. Here is what UK SMBs need to do right now.
Read more →
Discover the new WhatsApp malware targeting UK SMBs. Learn how to protect your business from harmful VBS payloads and MSI backdoors.
Read more →
Is your business unknowingly at risk? Discover how supply chain attacks threaten your operations and learn the essential steps to safeguard your future.
Read more →
AI-driven threats are evolving fast. Is your business keeping up? Discover how to protect your enterprise from cutting-edge cybercriminal tactics.
Read more →
The Bank of England runs live cyberattack simulations on the UK's most critical financial institutions every year. Real attacks, on live systems, designed by intelligence analysts who know exactly how sophisticated threat actors operate. The 2025 results are in. Weak passwords. Overly permissive access controls. Systems that haven't been patched. Staff who hand over credentials when asked convincingly. Third year running. Same findings. If the institutions that hold your money, process your payr
Read more →
I spent time with Mauven this week working through the Unit 42 Global Incident Response Report 2026. Seven hundred and fifty incident response engagements. Fifty-plus countries. Real cases. The headline statistic, 89% of investigations involving identity as a material factor, is striking. But it's not the number that should concern you most. It's what that number tells us about where organisations are spending their security budgets versus where attackers are actually operating. They are not in
Read more →
In September 2024, a UK tribunal concluded that 5.6 million stolen card records might not constitute personal data. The argument was structural, not frivolous. Hackers who cannot identify individuals from card numbers alone are not, the Upper Tribunal suggested, processing personal data. The Court of Appeal corrected that in February 2026. Lord Justice Warby's ruling establishes a clean and reusable test: you assess whether data is personal from the controller's perspective, not the attacker's.
Read more →
In early 2026, the FBI served Microsoft with a search warrant. Microsoft handed over the BitLocker encryption keys for three laptops. No hack. No breach. No compromised passwords. Just a warrant, and Microsoft's compliance. Here is what nobody in UK small business is talking about: those same default settings that allowed this are almost certainly running on your devices right now. And the legal mechanism that made it possible, the US CLOUD Act, reaches across the Atlantic directly into your Mic
Read more →
The US CLOUD Act gives American courts the power to compel any US technology company to hand over your data, regardless of whether it sits in a London data centre or a bunker in Wyoming. UK GDPR Article 48 says foreign court orders do not make that transfer lawful. No UK court has tested this conflict. No ICO enforcement action has targeted it. The NCSC does not mention it by name. Corrine Jefferson, our resident intelligence analyst, dissects the legal contradiction sitting quietly in the middl
Read more →
I used to work in US government intelligence. I now live in London. Those two facts make me uniquely uncomfortable about Palantir's expanding presence across the British state. In December 2024, Switzerland's military concluded that data held by Palantir could be accessed by the American government and that leaks "cannot be technically prevented." Their recommendation was unambiguous: find alternatives. The UK's response to the same evidence has been to award Palantir more than £900 million in c
Read more →
I live in London. I used to work in US government intelligence. And when Google Threat Intelligence Group published their defence industrial base report on 10 February, I did what any former analyst does: I stopped reading the headlines and started reading the primary source. The findings are precise and they are uncomfortable. Chinese state-sponsored actors have exploited more than two dozen zero-day vulnerabilities in edge devices from ten different vendors since 2020. Average dwell time insid
Read more →
The reality is this: the acting director of America's civilian cybersecurity agency uploaded sensitive government contracting documents to ChatGPT's public platform. Multiple automated alerts were triggered. A Department of Homeland Security investigation was launched. And somehow, this still happened. From my former life in government service, I can tell you this isn't just embarrassing. It's a systems failure that reveals fundamental problems with how we approach privileged access, AI governan
Read more →
The Apple App Store feels safe. That is the story many people tell themselves. Firehound and Vulnu show why that comfort can be dangerous. Researchers have flagged this week insecure iPhone apps that expose user data through badly secured cloud storage. Some leak private chats, email addresses, and location traces. Many of these apps look polished and carry strong ratings. That is the trap. In this guest post, Corrine Jefferson explains how slop apps slip through review, why AI apps raise the st
Read more →Cookie consent
We use Google Analytics to understand how visitors use this site. No personal data is sold or shared. Privacy Policy