<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Corrine Jefferson — The Small Business Cybersecurity Guy</title><description>Every article by Corrine Jefferson. Straight-talking cybersecurity advice for UK small businesses.</description><link>https://thesmallbusinesscybersecurityguy.co.uk/</link><language>en-gb</language><item><title>The Latest Threats Facing UK Small Businesses: Critical Exploits Uncovered</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-update-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-update-2026/</guid><description>Unpack today&apos;s critical vulnerabilities threatening small businesses: IBM, Spikster, and WordPress under fire.</description><pubDate>Fri, 31 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>cloud-security</category><category>compliance-failure</category><author>Corrine Jefferson</author></item><item><title>Critical Vulnerabilities Threaten UK Small Business Cybersecurity</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-threat-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-threat-2026/</guid><description>Newly discovered vulnerabilities expose UK businesses to unauthorised access and serious risks. Here&apos;s what you need to know.</description><pubDate>Thu, 30 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>credential-theft</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Vulnerabilities Exposed: IBM WebSphere&apos;s Alarming Security Flaws</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ibm-websphere-security-flaws-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ibm-websphere-security-flaws-2026/</guid><description>Discover critical security flaws in IBM WebSphere impacting UK small businesses. Act now to secure your operations.</description><pubDate>Wed, 29 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>business-risk</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>UK Small Businesses: FortiOS and VeloCloud Vulnerabilities Demand Immediate Action</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/fortios-velocloud-vulnerabilities-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/fortios-velocloud-vulnerabilities-uk-smb-2026/</guid><description>FortiOS and VeloCloud vulnerabilities expose UK SMBs to critical risks. Don&apos;t wait, take action now.</description><pubDate>Tue, 28 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>network-security</category><category>business-risk</category><category>vulnerability-management</category><author>Corrine Jefferson</author></item><item><title>UK Small Business Cybersecurity: Emerging Threats You Can&apos;t Ignore</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-threats-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-threats-2026/</guid><description>Fastjson and Cl0p ransomware exploitations are active. Know the risks and defensive steps.</description><pubDate>Mon, 27 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>business-risk</category><category>remote-access</category><author>Corrine Jefferson</author></item><item><title>Critical Security Alerts for UK SMBs: What You Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/critical-security-alerts-uk-smbs-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/critical-security-alerts-uk-smbs-2026/</guid><description>Microsoft Exchange and Azure vulnerabilities demand immediate attention from UK SMEs.</description><pubDate>Fri, 24 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>remote-access</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Critical Cybersecurity Alert: Small Businesses at Risk from New Exploits</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/small-business-cybersecurity-alert-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/small-business-cybersecurity-alert-2026/</guid><description>Exploited vulnerabilities in SharePoint and Oracle put small businesses at risk. Act fast to secure your infrastructure.</description><pubDate>Thu, 23 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>incident-response</category><category>cloud-security</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>Critical Flaws in WordPress and Oracle: A Wake-Up Call for UK SMBs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-oracle-vulnerabilities-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-oracle-vulnerabilities-uk-smb-2026/</guid><description>WordPress and Oracle flaws threaten UK SMBs. Here&apos;s what you need to do now to secure your business.</description><pubDate>Wed, 22 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>compliance-failure</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>Russian Spy Cameras, WordPress RCE, and AI Phishing Kits: Your Weekly Threat Brief</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-threat-brief-21-july-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-threat-brief-21-july-2026/</guid><description>Three stories this week. All of them matter. One of them is watching your car park right now.</description><pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>nation-state-attacks</category><category>social-engineering</category><category>iot-surveillance</category><category>ransomware-groups</category><category>supply-chain-risk</category><author>Corrine Jefferson</author></item><item><title>SonicWall Zero-Days and a Critical NGINX Flaw: What UK Small Businesses Need to Know This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/sonicwall-zero-days-nginx-flaw-uk-smb-briefing-july-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/sonicwall-zero-days-nginx-flaw-uk-smb-briefing-july-2026/</guid><description>Two serious vulnerabilities landed this week. One was exploited before anyone even knew it existed. Here is the plain-English briefing for UK small businesses.</description><pubDate>Mon, 20 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>vendor-risk</category><category>incident-response</category><category>business-risk</category><category>msp-security</category><author>Corrine Jefferson</author></item><item><title>SharePoint Is Being Actively Exploited Right Now. Is Your Business Exposed?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/sharepoint-exploited-zoom-wireguard-uk-smb-july-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/sharepoint-exploited-zoom-wireguard-uk-smb-july-2026/</guid><description>CISA added a Microsoft SharePoint remote code execution flaw to its active exploitation list on 16 July 2026. Here is what UK small businesses need to do today.</description><pubDate>Fri, 17 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>credential-theft</category><category>business-risk</category><category>cloud-security</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Patch Tuesday Delivered 570 Fixes. A Zero-Day Arrived Hours Later. What UK Small Businesses Need to Do Right Now.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-july-2026-zero-day-knx-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-july-2026-zero-day-knx-uk-smb-2026/</guid><description>570 Microsoft patches. A Windows zero-day PoC published hours later. A building automation protocol now on the CISA KEV list. This week is not one to ignore.</description><pubDate>Thu, 16 Jul 2026 07:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>incident-response</category><category>business-risk</category><category>compliance-failure</category><category>remote-access</category><category>supply-chain-risk</category><author>Corrine Jefferson</author></item><item><title>Microsoft&apos;s Record 622-Flaw Patch Tuesday and Two Active Zero-Days: What UK Small Businesses Must Do Today</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/microsoft-patch-tuesday-july-2026-zero-days-uk-smb/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/microsoft-patch-tuesday-july-2026-zero-days-uk-smb/</guid><description>Two Microsoft zero-days are being actively exploited right now. One requires no login whatsoever. Here is what to do before close of business.</description><pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>remote-access</category><category>business-risk</category><category>compliance-failure</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Your Joomla Website Is Being Actively Exploited Right Now. What Are You Doing About It?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/joomla-zero-day-exploits-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/joomla-zero-day-exploits-uk-smb-2026/</guid><description>Attackers are executing arbitrary code on Joomla websites right now. CISA confirmed it. Here is what UK small businesses need to do today.</description><pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>supply-chain-risk</category><category>incident-response</category><category>compliance-failure</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>Your Security Tool Has a Hole in It: The Hermes WebUI RCE and the Windows Defender Patch That Breaks Things</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/hermes-webui-rce-windows-defender-rogueplanet-uk-smb-briefing-july-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/hermes-webui-rce-windows-defender-rogueplanet-uk-smb-briefing-july-2026/</guid><description>Two critical vulnerabilities this week prove that your security tools are now the target. Here is the plain-English briefing.</description><pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>remote-access</category><category>business-risk</category><category>incident-response</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>Your WordPress Plugin Is a Loaded Gun: The CVE-2026-58480 File Upload Flaw Explained</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-blocksy-cve-2026-58480-rce-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-blocksy-cve-2026-58480-rce-uk-smb-2026/</guid><description>CVSS 9.8. No authentication required. A WordPress plugin flaw published yesterday lets attackers run arbitrary code on your server. Here is what it means.</description><pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>compliance-failure</category><category>business-risk</category><category>supply-chain-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Adobe ColdFusion Is Being Actively Exploited Right Now. And Your MSP&apos;s Remote Access Tool Might Be Next.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/coldfusion-cve-2026-48282-simplehelp-rmm-exploited-july-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/coldfusion-cve-2026-48282-simplehelp-rmm-exploited-july-2026/</guid><description>A perfect-10 Adobe flaw exploited within two hours. Hundreds of unpatched RMM servers still exposed. Two stories your IT provider needs to hear today.</description><pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>supply-chain-risk</category><category>incident-response</category><category>vendor-risk</category><category>remote-access</category><author>Corrine Jefferson</author></item><item><title>SharePoint Is Being Actively Exploited Right Now. Is Yours Patched?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/sharepoint-cve-2026-45659-exploited-ai-ransomware-july-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/sharepoint-cve-2026-45659-exploited-ai-ransomware-july-2026/</guid><description>A SharePoint vulnerability is being actively exploited right now. CISA confirmed it. Microsoft sat on the disclosure for weeks. Here is what you need to know.</description><pubDate>Fri, 03 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>incident-response</category><category>cloud-security</category><category>vendor-risk</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>SharePoint Is Being Actively Exploited Right Now: What UK Small Businesses Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/sharepoint-exploit-ip-cameras-ai-ransomware-smb-brief-july-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/sharepoint-exploit-ip-cameras-ai-ransomware-smb-brief-july-2026/</guid><description>SharePoint has a confirmed, actively-exploited code execution flaw. CISA added it to the KEV list yesterday. If your business uses SharePoint, read this now.</description><pubDate>Thu, 02 Jul 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>remote-access</category><category>business-risk</category><category>incident-response</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>Your MSP&apos;s Remote Support Tool Is Being Used Against You Right Now</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/simplehelp-cve-2026-48558-msp-rce-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/simplehelp-cve-2026-48558-msp-rce-uk-smb-2026/</guid><description>A maximum-severity flaw in SimpleHelp RMM is being actively exploited. Attackers are walking straight through your MSP&apos;s front door. Here is what that means for your business.</description><pubDate>Wed, 01 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>msp-security</category><category>credential-theft</category><category>supply-chain-risk</category><category>remote-access</category><category>incident-response</category><category>uk-business</category><author>Corrine Jefferson</author></item><item><title>Your IT Support Tool Has a Master Key. Someone Just Found It.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/simplehelp-authentication-bypass-cve-2026-48558-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/simplehelp-authentication-bypass-cve-2026-48558-uk-smb-2026/</guid><description>The remote support tool your IT provider uses to fix your computers has a flaw that lets attackers walk straight in. No password required.</description><pubDate>Tue, 30 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>remote-access</category><category>credential-theft</category><category>vendor-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Critical Vulnerabilities Impacting UK SMBs: WordPress Plugins and Cisco Exploits</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/critical-vulnerabilities-uk-smbs-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/critical-vulnerabilities-uk-smbs-2026/</guid><description>WordPress plugin flaws and a Cisco exploit are high-risk for UK SMBs. Urgent updates recommended.</description><pubDate>Thu, 25 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>incident-response</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>Critical Vulnerabilities: What UK SMEs Need to Know Now</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/critical-vulnerabilities-uk-smes-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/critical-vulnerabilities-uk-smes-2026/</guid><description>Lantronix and UniFi OS vulnerabilities demand immediate attention from UK SMEs to prevent breaches.</description><pubDate>Wed, 24 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>compliance-failure</category><category>business-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>What the Fortinet Bypass Tells Us About Trusting the Edge</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/fortinet-forticloud-sso-bypass-edge-trust-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/fortinet-forticloud-sso-bypass-edge-trust-uk-smb-2026/</guid><description>An authentication bypass leaves a quiet signal: admin activity, not exploit traffic. Most small businesses are not watching for it.</description><pubDate>Wed, 24 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>credential-theft</category><category>vendor-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Why Ignoring These Critical Vulnerabilities Could Sink Your SMB</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/critical-vulnerabilities-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/critical-vulnerabilities-uk-smb-2026/</guid><description>Ignoring IBM Langflow and WordPress plugin threats could sink your SMB. Here&apos;s what you need to know.</description><pubDate>Tue, 23 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>cloud-security</category><category>business-risk</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>UK Small Business Cybersecurity: Don&apos;t Ignore These Vulnerabilities</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-vulnerabilities-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-vulnerabilities-2026/</guid><description>Legacy routers infected by AryStinger show why UK SMBs need to update their network security.</description><pubDate>Mon, 22 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>network-security</category><category>incident-response</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>INC Ransomware, DragonForce in Teams, and a Splunk Zero-Day: Your UK SMB Threat Briefing for 19 June 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-threat-briefing-19-june-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-threat-briefing-19-june-2026/</guid><description>Three threats that landed overnight. One is actively exploited right now. Here is what UK small businesses need to know before Friday.</description><pubDate>Fri, 19 Jun 2026 09:00:00 GMT</pubDate><category>ransomware-groups</category><category>smb-security</category><category>uk-business</category><category>incident-response</category><category>remote-access</category><category>supply-chain-risk</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>RoguePlanet: Microsoft&apos;s Unpatched Defender Flaw and What UK Small Businesses Should Do Right Now</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/rogueplanet-defender-zero-day-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/rogueplanet-defender-zero-day-uk-smb-2026/</guid><description>Microsoft has confirmed a Defender zero-day with no patch in sight. If your business runs Windows, this is not a drill.</description><pubDate>Thu, 18 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>incident-response</category><category>business-risk</category><category>compliance-failure</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>Your Joomla Website Is Being Attacked Right Now. And Microsoft Defender Has No Patch.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/joomla-jce-exploit-defender-zero-day-uk-smb-june-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/joomla-jce-exploit-defender-zero-day-uk-smb-june-2026/</guid><description>CISA confirmed active exploitation of a Joomla plugin flaw on Tuesday. Microsoft has no patch for its Defender zero-day. Two fires, one week. Here is what to do.</description><pubDate>Wed, 17 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>vendor-risk</category><category>incident-response</category><category>business-risk</category><category>compliance-failure</category><author>Corrine Jefferson</author></item><item><title>Joomla Sites Are Being Hacked Right Now: What UK Small Businesses Need to Know This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/joomla-jwt-active-exploitation-uk-smb-brief-june-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/joomla-jwt-active-exploitation-uk-smb-brief-june-2026/</guid><description>Two critical vulnerabilities confirmed in active exploitation this week. If you run Joomla or use any web application with token-based login, read this now.</description><pubDate>Wed, 17 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>compliance-failure</category><category>business-risk</category><category>remote-access</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Your WordPress Site Has a Backdoor. Your Shared Host Has a Symlink Problem. And Microsoft Just Patched Your Emails Being Stolen With One Click.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-backdoors-shared-hosting-m365-copilot-threats-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-backdoors-shared-hosting-m365-copilot-threats-2026/</guid><description>Three stories from the last 24 hours that should matter to every small business in the UK. Two are actively exploited. One was patched three weeks after it was found.</description><pubDate>Tue, 16 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>supply-chain-risk</category><category>cloud-security</category><category>vendor-risk</category><category>incident-response</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>Splunk&apos;s 9.8 RCE: What a Logging Tool Vulnerability Means for UK Small Business Supply Chains</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/splunk-rce-cve-2026-20253-uk-smb-supply-chain-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/splunk-rce-cve-2026-20253-uk-smb-supply-chain-2026/</guid><description>Splunk has a 9.8-rated unauthenticated remote code execution flaw. You probably don&apos;t run Splunk. Your MSP might. That&apos;s the problem.</description><pubDate>Mon, 15 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>supply-chain-risk</category><category>msp-security</category><category>vendor-risk</category><category>remote-access</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>The Gentlemen Are at Your Door and BitLocker Won&apos;t Save You: This Week&apos;s Threats Explained</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/gentlemen-ransomware-bitlocker-bypass-smb-brief-june-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/gentlemen-ransomware-bitlocker-bypass-smb-brief-june-2026/</guid><description>478 victims, worm-like spread, and a BitLocker bypass that works on patched Windows. This week&apos;s threats are not theoretical. Here is the brief.</description><pubDate>Fri, 12 Jun 2026 09:00:00 GMT</pubDate><category>ransomware-groups</category><category>smb-security</category><category>uk-business</category><category>incident-response</category><category>business-risk</category><category>credential-theft</category><category>remote-access</category><author>Corrine Jefferson</author></item><item><title>Your WordPress Site Just Handed a Stranger the Admin Keys: The Threat Intelligence Brief for 11 June 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-brief-wordpress-admin-takeover-jdy-botnet-june-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-brief-wordpress-admin-takeover-jdy-botnet-june-2026/</guid><description>No credentials required. A WordPress plugin flaw published yesterday lets unauthenticated attackers create admin accounts. Here is what to do before lunch.</description><pubDate>Thu, 11 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>nation-state-attacks</category><category>vendor-risk</category><category>supply-chain-risk</category><category>business-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Patch Tuesday June 2026: What UK Small Businesses Actually Need to Do Right Now</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-june-2026-uk-smb-action-guide/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-june-2026-uk-smb-action-guide/</guid><description>Microsoft&apos;s biggest-ever Patch Tuesday, a critical Veeam backup flaw, and a WordPress plugin that hands attackers your server. Three stories. One to-do list.</description><pubDate>Wed, 10 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>incident-response</category><category>compliance-failure</category><category>vendor-risk</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>Your VPN Has No Password. Check Point Just Confirmed It. What Are You Doing About It?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/check-point-vpn-wordpress-rce-uk-smb-june-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/check-point-vpn-wordpress-rce-uk-smb-june-2026/</guid><description>Attackers bypassed Check Point VPN passwords in the wild before a patch existed. If your remote access still runs IKEv1, you are already compromised.</description><pubDate>Tue, 09 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>credential-theft</category><category>vendor-risk</category><category>business-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>No Patch, Active Exploitation: What This Week&apos;s Cisco and SolarWinds Flaws Mean for Your Business</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cisco-sdwan-solarwinds-servu-exploits-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cisco-sdwan-solarwinds-servu-exploits-uk-smb-2026/</guid><description>Cisco SD-WAN and SolarWinds Serv-U are both being actively exploited this week. One has no patch. Here is the data, stripped of vendor spin.</description><pubDate>Mon, 08 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>supply-chain-risk</category><category>msp-security</category><category>incident-response</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>Your WordPress Site Is Being Attacked Right Now. Your Magento Store Too.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-magento-actively-exploited-uk-smb-june-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-magento-actively-exploited-uk-smb-june-2026/</guid><description>CISA just added two actively exploited flaws to its KEV catalog. If you run WordPress or Magento, you are in the crosshairs today.</description><pubDate>Fri, 05 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>compliance-failure</category><category>business-risk</category><category>incident-response</category><category>supply-chain-risk</category><author>Corrine Jefferson</author></item><item><title>WordPress Takeovers, Windows Blind Spots, and the Patch You Skipped Two Years Ago: Your Weekly Threat Brief</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-threat-brief-june-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-threat-brief-june-2026/</guid><description>Two WordPress flaws scored 9.8. An unpatched Windows credential leak has no CVE number. Here is what UK small businesses need to act on this week.</description><pubDate>Wed, 03 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>vendor-risk</category><category>ransomware-groups</category><category>remote-access</category><category>compliance-failure</category><author>Corrine Jefferson</author></item><item><title>Windows Netlogon Is Being Actively Exploited Right Now. Is Your Server Patched?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/windows-netlogon-cve-2026-41089-actively-exploited-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/windows-netlogon-cve-2026-41089-actively-exploited-2026/</guid><description>Attackers are actively exploiting a critical Windows Netlogon flaw. No login required. One packet and your domain controller is compromised.</description><pubDate>Tue, 02 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>remote-access</category><category>business-risk</category><category>incident-response</category><category>infrastructure-security</category><author>Corrine Jefferson</author></item><item><title>Your Firewall Has a Front Door. Attackers Found It in May 2026.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/pan-os-auth-bypass-cve-2026-0257-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/pan-os-auth-bypass-cve-2026-0257-uk-smb-2026/</guid><description>Palo Alto&apos;s GlobalProtect VPN has a confirmed authentication bypass under active exploitation. If you haven&apos;t patched, your network perimeter is already open.</description><pubDate>Mon, 01 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>vendor-risk</category><category>incident-response</category><category>network-security</category><category>compliance-failure</category><author>Corrine Jefferson</author></item><item><title>FortiClient Servers Are Delivering Malware, AI Is Running the Attacks, and WordPress Just Handed Out Admin Rights: Your Threat Brief for 29 May 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/forticlient-malware-ai-attacks-wordpress-threat-brief-may-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/forticlient-malware-ai-attacks-wordpress-threat-brief-may-2026/</guid><description>Fake Fortinet patches, AI-driven database raids, and a WordPress plugin handing out admin rights to strangers. Three stories that matter this week.</description><pubDate>Fri, 29 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>ransomware-groups</category><category>supply-chain-risk</category><category>remote-access</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>WordPress OTP Bypass and the Windows Kernel Flaw Your Business Needs to Patch Today</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-otp-bypass-windows-kernel-flaw-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-otp-bypass-windows-kernel-flaw-smb-2026/</guid><description>Attackers can brute-force their way into any WordPress account in minutes. A Windows kernel flaw hands them SYSTEM privileges. Both need fixing today.</description><pubDate>Thu, 28 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>compliance-failure</category><category>business-risk</category><category>remote-access</category><author>Corrine Jefferson</author></item><item><title>Joomla, Ghost CMS, and SharePoint: Three Patches Your Business Cannot Afford to Skip This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/joomla-ghost-sharepoint-critical-patches-may-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/joomla-ghost-sharepoint-critical-patches-may-2026/</guid><description>Joomla has three privilege escalation flaws scored 9.8. Ghost CMS is already being exploited across 700 websites. SharePoint needs patching now.</description><pubDate>Wed, 27 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>vendor-risk</category><category>incident-response</category><category>compliance-failure</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>Ghost CMS and ClickFix: The Web Trap Your Staff Will Fall For</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ghost-cms-clickfix-attack-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ghost-cms-clickfix-attack-uk-smb-2026/</guid><description>Seven hundred-plus websites turned into traps. One fake CAPTCHA. One click. Full device compromise. This is ClickFix, and it is coming for your team.</description><pubDate>Tue, 26 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>supply-chain-risk</category><category>business-risk</category><category>incident-response</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>Drupal Is Being Actively Exploited Right Now: What UK Small Businesses Need to Do Today</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/drupal-cve-2026-9082-actively-exploited-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/drupal-cve-2026-9082-actively-exploited-uk-smb-2026/</guid><description>Drupal&apos;s being actively exploited right now. 15,000 attempts, 65 countries, CISA confirmed. If your site runs Drupal, you have a deadline of 27 May.</description><pubDate>Mon, 25 May 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>business-risk</category><category>compliance-failure</category><category>supply-chain-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>WordPress Is a Ransomware Welcome Mat: Three Critical Vulnerabilities You Need to Patch Right Now</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-critical-vulnerabilities-uk-smb-may-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-critical-vulnerabilities-uk-smb-may-2026/</guid><description>Three WordPress plugins just handed attackers the keys to your website. CVSS 9.8. No login required. Here is what to do before Friday.</description><pubDate>Fri, 22 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>compliance-failure</category><category>business-risk</category><category>supply-chain-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>YellowKey, WordPress Takeovers, and Cameras With No Locks: This Week&apos;s Threats UK SMBs Cannot Ignore</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/yellowkey-wordpress-smb-threats-may-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/yellowkey-wordpress-smb-threats-may-2026/</guid><description>A USB stick defeats BitLocker. Three WordPress plugins hand attackers full admin access. The intelligence is clear. Here is what to do about it.</description><pubDate>Thu, 21 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>credential-theft</category><category>infrastructure-security</category><category>business-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Microsoft Exchange Is Being Actively Exploited Right Now. Is Your Business Exposed?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/microsoft-exchange-cisa-exploit-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/microsoft-exchange-cisa-exploit-uk-smb-2026/</guid><description>CISA confirmed active exploitation of a Microsoft Exchange vulnerability this week. UK small businesses running on-premise email need to act today.</description><pubDate>Tue, 19 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>incident-response</category><category>business-risk</category><category>compliance-failure</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>NGINX Is Being Actively Exploited Right Now. Is Your Web Server Patched?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/nginx-cve-2026-42945-active-exploitation-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/nginx-cve-2026-42945-active-exploitation-uk-smb-2026/</guid><description>NGINX powers roughly a third of the web. CVE-2026-42945 is being exploited right now. Here is what UK small businesses need to do before Friday.</description><pubDate>Mon, 18 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>infrastructure-security</category><category>business-risk</category><category>incident-response</category><category>supply-chain-risk</category><author>Corrine Jefferson</author></item><item><title>WordPress Plugins, Microsoft Authenticator, and Your Email Server: The Threats That Landed Overnight</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-authenticator-exchange-vulnerabilities-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-authenticator-exchange-vulnerabilities-uk-smb-2026/</guid><description>Three critical flaws landed overnight. WordPress sites, Microsoft Authenticator, and on-premises email are all in the frame. Here is the data, without the spin.</description><pubDate>Fri, 15 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>compliance-failure</category><category>business-risk</category><category>remote-access</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>May 2026 Patch Tuesday: What UK Small Businesses Actually Need to Do This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/may-2026-patch-tuesday-uk-smb-action-guide/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/may-2026-patch-tuesday-uk-smb-action-guide/</guid><description>A wormable Windows Server flaw, a payment platform with a forgeable secret key, and 130 patches. Here is what matters to your business this week.</description><pubDate>Thu, 14 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>supply-chain-risk</category><category>business-risk</category><category>vendor-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Patch Tuesday May 2026: What UK Small Businesses Actually Need to Do This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-may-2026-smb-action-guide/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-may-2026-smb-action-guide/</guid><description>120 vulnerabilities. A critical Windows Netlogon flaw. A Windows DNS buffer overflow. This is not a drill. Here is what to do this week.</description><pubDate>Wed, 13 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>compliance-failure</category><category>remote-access</category><category>infrastructure-security</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Your Website Host Has a Backdoor. Your NAS Has No Patch. And a UK Water Company Just Got Fined £1m.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-threats-cpanel-backdoor-linux-ico-fine-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-threats-cpanel-backdoor-linux-ico-fine-2026/</guid><description>Three stories this week that every UK small business owner needs to hear. One phishing email. Twenty months undetected. One million pounds.</description><pubDate>Tue, 12 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>compliance-failure</category><category>incident-response</category><category>vendor-risk</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>The Anatomy of a £35-Per-User MSP Quote: A Forensic Look at What Has Been Removed</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/msp-pricing-anatomy-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/msp-pricing-anatomy-uk-smb-2026/</guid><description>Strip out Microsoft licensing. If your provider is below £50 per user per month outside London or £75 inside it, something has been removed. The maths does not lie.</description><pubDate>Tue, 12 May 2026 07:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>business-risk</category><category>vendor-risk</category><category>executive-security</category><author>Corrine Jefferson</author></item><item><title>WordPress Shops, cPanel Hosts, and Ivanti Devices: This Week&apos;s Threats Your Business Cannot Ignore</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-cpanel-ivanti-threats-uk-smb-may-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-cpanel-ivanti-threats-uk-smb-may-2026/</guid><description>Attackers can own your WordPress store without a password. cPanel has fresh critical flaws. CISA just confirmed active exploitation of Ivanti. Three reasons to act today.</description><pubDate>Mon, 11 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>vendor-risk</category><category>supply-chain-risk</category><category>incident-response</category><category>cloud-security</category><author>Corrine Jefferson</author></item><item><title>Ivanti EPMM Is Being Actively Exploited Right Now. Is Your MDM a Back Door?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ivanti-epmm-zero-day-exploited-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ivanti-epmm-zero-day-exploited-uk-smb-2026/</guid><description>Attackers are inside Ivanti EPMM before patches existed. If your business manages mobile devices, this is not someone else&apos;s problem.</description><pubDate>Fri, 08 May 2026 07:29:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>credential-theft</category><category>incident-response</category><category>vendor-risk</category><category>business-risk</category><author>Corrine Jefferson</author></item><item><title>Palo Alto Firewalls Are Being Hacked Right Now: What UK Small Businesses Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/pan-os-cve-2026-0300-active-exploit-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/pan-os-cve-2026-0300-active-exploit-uk-smb-2026/</guid><description>A critical Palo Alto firewall flaw is being actively exploited with no patch yet available. If your MSP manages a PAN-OS device, ask them one question.</description><pubDate>Thu, 07 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>remote-access</category><category>business-risk</category><category>incident-response</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>One Bad Signature, One National Domain, Global Impact: The .de DNSSEC Outage Explained</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/de-dnssec-outage-broken-signature-dns-failure-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/de-dnssec-outage-broken-signature-dns-failure-uk-2026/</guid><description>A single broken cryptographic signature took large parts of Germany&apos;s internet offline. Your business has the same invisible dependency.</description><pubDate>Thu, 07 May 2026 08:28:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>vendor-risk</category><category>incident-response</category><category>supply-chain-risk</category><author>Corrine Jefferson</author></item><item><title>WordPress Authentication Bypasses, a Linux Root Exploit, and a Nation-State Group Still Using Five-Year-Old Patches: Your Threat Brief for 6 May 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-threat-brief-6-may-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-threat-brief-6-may-2026/</guid><description>WordPress sites can be taken over without a password. A Linux root exploit is being actively weaponised. And a nation-state group is still walking through Exchange servers that weren&apos;t patched in 2021.</description><pubDate>Wed, 06 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>nation-state-attacks</category><category>supply-chain-risk</category><category>vendor-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Phishing Won 69% of UK Cyber Battles Last Year: Why the Fight Has Moved From Your Inbox to Your Identity</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/phishing-identity-controls-uk-business-survey-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/phishing-identity-controls-uk-business-survey-2026/</guid><description>Phishing caused 69% of the most disruptive breaches. 51% of victims were hit by phishing alone. The fight has moved from inboxes to identity controls.</description><pubDate>Tue, 05 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>social-engineering</category><category>business-risk</category><category>compliance-failure</category><author>Corrine Jefferson</author></item><item><title>cPanel Under Active Attack, MOVEit Is Back, and Your Router Is Probably Compromised: The 5 May 2026 Brief</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-brief-5-may-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smb-cyber-brief-5-may-2026/</guid><description>cPanel is on CISA&apos;s active exploit list. MOVEit has a new authentication bypass. Your cheap router may already be compromised. Here is what matters today.</description><pubDate>Tue, 05 May 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>credential-theft</category><category>supply-chain-risk</category><category>vendor-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Linux Root Access Bug Under Active Exploitation: What Every UK Small Business Needs to Know Today</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/linux-root-access-cve-2026-31431-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/linux-root-access-cve-2026-31431-uk-smb-2026/</guid><description>CISA confirmed active exploitation of a Linux root access flaw this week. If your business runs Linux anywhere, including on a NAS or cloud VM, read this now.</description><pubDate>Mon, 04 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>infrastructure-security</category><category>remote-access</category><category>incident-response</category><category>business-risk</category><category>cloud-security</category><author>Corrine Jefferson</author></item><item><title>Your WordPress Site Has a Backdoor. Two of Them, Actually.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-critical-vulnerabilities-smb-may-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/wordpress-critical-vulnerabilities-smb-may-2026/</guid><description>Unauthenticated attackers can upload malware or log in as your site admin right now. Two critical WordPress flaws. No patch excuses.</description><pubDate>Sun, 03 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>compliance-failure</category><category>business-risk</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>44,000 Hacked Control Panels and a WordPress Auth Bypass: What This Week&apos;s Threats Mean for Your Business</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cpanel-wordpress-auth-bypass-smb-threats-may-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cpanel-wordpress-auth-bypass-smb-threats-may-2026/</guid><description>44,000 hosting control panels confirmed compromised. A WordPress plugin is handing out admin access to anyone who asks. This week&apos;s threats are not theoretical.</description><pubDate>Sat, 02 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>vendor-risk</category><category>cloud-security</category><category>business-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>CopyFail, Unauthenticated RCE, and the Threats Your Linux Server Is Facing Right Now</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/copyfail-linux-rce-uk-smb-threat-brief-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/copyfail-linux-rce-uk-smb-threat-brief-2026/</guid><description>Public exploit code for a Linux root access flaw has defenders scrambling. If your business runs Linux anywhere, this is not a drill.</description><pubDate>Fri, 01 May 2026 05:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>infrastructure-security</category><category>remote-access</category><category>vendor-risk</category><category>business-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Your Windows PC Just Got Weaponised by Russian Intelligence. What Are You Doing About It?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/windows-zero-click-apt28-router-cves-uk-smb-brief-april-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/windows-zero-click-apt28-router-cves-uk-smb-brief-april-2026/</guid><description>Russian state hackers are in your Windows machine without a click. Five router flaws scored 9.8 overnight. This week&apos;s threat brief cuts through the noise.</description><pubDate>Wed, 29 Apr 2026 05:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>nation-state-attacks</category><category>remote-access</category><category>business-risk</category><category>incident-response</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>Your Office Router Has 19 Critical Vulnerabilities. Published Yesterday. Exploits Already Public.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/totolink-a8000ru-critical-vulnerabilities-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/totolink-a8000ru-critical-vulnerabilities-uk-smb-2026/</guid><description>Nineteen critical flaws. One router model. All exploits published. If your office uses a Totolink A8000RU, you are already exposed.</description><pubDate>Tue, 28 Apr 2026 07:38:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>network-security</category><category>business-risk</category><category>vendor-risk</category><category>incident-response</category><author>Corrine Jefferson</author></item><item><title>Your MSP&apos;s Remote Support Tool Has a Backdoor. CISA Just Confirmed It.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/simplehelp-vulnerabilities-msp-risk-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/simplehelp-vulnerabilities-msp-risk-uk-smb-2026/</guid><description>CISA just added SimpleHelp remote support vulnerabilities to its actively-exploited list. If your IT provider uses it, attackers may already have a path in.</description><pubDate>Sun, 26 Apr 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>msp-security</category><category>remote-access</category><category>supply-chain-risk</category><category>vendor-risk</category><category>incident-response</category><category>uk-business</category><author>Corrine Jefferson</author></item><item><title>Fourth-Party Supply Chain Exposure: The Threat Vector UK Businesses Are Not Monitoring</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/fourth-party-supply-chain-risk-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/fourth-party-supply-chain-risk-uk-smb-2026/</guid><description>61% of organisations were breached through their supply chain last year. Just 7% monitor beyond immediate suppliers. That is a structural failure, not bad luck.</description><pubDate>Mon, 20 Apr 2026 16:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>supply-chain-risk</category><category>vendor-risk</category><category>business-risk</category><category>cloud-security</category><category>compliance-failure</category><author>Corrine Jefferson</author></item><item><title>Your IT Support Tool Is Now a Burglary Kit: How STAC6405 Is Weaponising Legitimate RMM Software</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/stac6405-rmm-phishing-logmein-screenconnect-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/stac6405-rmm-phishing-logmein-screenconnect-uk-smb-2026/</guid><description>Attackers are weaponising the same remote access tools your IT team uses. Sophos has the receipts. Here is what happened and what you need to do.</description><pubDate>Wed, 08 Apr 2026 10:00:00 GMT</pubDate><category>social-engineering</category><category>remote-access</category><category>msp-security</category><category>credential-theft</category><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><author>Corrine Jefferson</author></item><item><title>Two Zero-Days, Zero Patches, Zero Excuses: Windows and Fortinet Are on Fire This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/windows-bluehammer-fortinet-zero-day-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/windows-bluehammer-fortinet-zero-day-uk-smb-2026/</guid><description>Two working exploits in one week. One public, one confirmed in the wild. Neither fully patched. Here is what UK SMBs need to do right now.</description><pubDate>Tue, 07 Apr 2026 09:43:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>vendor-risk</category><category>msp-security</category><author>Corrine Jefferson</author></item><item><title>The Rise of WhatsApp Malware: What UK SMBs Should Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/the-rise-of-whatsapp-malware-what-uk-smbs-should-know/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/the-rise-of-whatsapp-malware-what-uk-smbs-should-know/</guid><description>Discover the new WhatsApp malware targeting UK SMBs. Learn how to protect your business from harmful VBS payloads and MSI backdoors.</description><pubDate>Tue, 31 Mar 2026 16:28:00 GMT</pubDate><category>WhatsApp</category><category>malware</category><category>cybersecurity</category><category>UK SMBs</category><author>Corrine Jefferson</author></item><item><title>Supply Chain Attacks: How UK SMBs Can Protect Themselves</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/supply-chain-attacks-how-uk-smbs-can-protect-themselves/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/supply-chain-attacks-how-uk-smbs-can-protect-themselves/</guid><description>Is your business unknowingly at risk? Discover how supply chain attacks threaten your operations and learn the essential steps to safeguard your future.</description><pubDate>Sun, 29 Mar 2026 08:00:00 GMT</pubDate><category>supply chain</category><category>cybersecurity</category><category>software security</category><category>small business</category><author>Corrine Jefferson</author></item><item><title>The Future of Cybersecurity: Preparing for AI-Driven Threats</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/the-future-of-cybersecurity-preparing-for-ai-driven-threats/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/the-future-of-cybersecurity-preparing-for-ai-driven-threats/</guid><description>AI-driven threats are evolving fast. Is your business keeping up? Discover how to protect your enterprise from cutting-edge cybercriminal tactics.</description><pubDate>Fri, 27 Mar 2026 21:00:00 GMT</pubDate><category>AI</category><category>Cybersecurity</category><category>Threats</category><category>Small Business</category><author>Corrine Jefferson</author></item><item><title>The Bank of England Just Told You Your Financial Sector Can&apos;t Do Basic Cybersecurity. Again.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/bank-of-england-cbest-2025-financial-sector-cyber-failures-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/bank-of-england-cbest-2025-financial-sector-cyber-failures-uk-smb-2026/</guid><description>The Bank of England runs live cyberattack simulations on the UK&apos;s most critical financial institutions every year. Real attacks, on live systems, designed by intelligence analysts who know exactly how sophisticated threat actors operate. The 2025 results are in. Weak passwords. Overly permissive access controls. Systems that haven&apos;t been patched. Staff who hand over credentials when asked convincingly. Third year running. Same findings. If the institutions that hold your money, process your payr</description><pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate><category>nation-state-attacks</category><category>uk-business</category><category>smb-security</category><category>compliance-failure</category><category>executive-security</category><category>business-risk</category><category>2026-threats</category><author>Corrine Jefferson</author></item><item><title>Attackers Aren&apos;t Hacking In. They&apos;re Logging In. Here&apos;s the Data.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/unit-42-identity-security-analysis-uk-business-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/unit-42-identity-security-analysis-uk-business-2026/</guid><description>I spent time with Mauven this week working through the Unit 42 Global Incident Response Report 2026. Seven hundred and fifty incident response engagements. Fifty-plus countries. Real cases. The headline statistic, 89% of investigations involving identity as a material factor, is striking. But it&apos;s not the number that should concern you most. It&apos;s what that number tells us about where organisations are spending their security budgets versus where attackers are actually operating. They are not in </description><pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate><category>identity-security</category><category>unit-42-report</category><category>credential-theft</category><category>mfa-bypass</category><category>smb-security</category><category>uk-business</category><category>2025-threats</category><author>Corrine Jefferson</author></item><item><title>Is a Card Number Personal Data? The Court of Appeal Has Answered. Here Is What Your Business Needs to Do with That Answer.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/personal-data-definition-controller-perspective-uk-gdpr-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/personal-data-definition-controller-perspective-uk-gdpr-2026/</guid><description>In September 2024, a UK tribunal concluded that 5.6 million stolen card records might not constitute personal data. The argument was structural, not frivolous. Hackers who cannot identify individuals from card numbers alone are not, the Upper Tribunal suggested, processing personal data. The Court of Appeal corrected that in February 2026. Lord Justice Warby&apos;s ruling establishes a clean and reusable test: you assess whether data is personal from the controller&apos;s perspective, not the attacker&apos;s. </description><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate><category>personal-data-definition</category><category>uk-gdpr</category><category>ico-enforcement</category><category>dsg-retail-ruling</category><category>data-protection-law</category><category>jigsaw-identification</category><category>compliance-failiure</category><author>Corrine Jefferson</author></item><item><title>Your Encryption Isn&apos;t Protecting You. Microsoft Just Proved It.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cloud-act-exposure-audit-uk-business-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cloud-act-exposure-audit-uk-business-2026/</guid><description>In early 2026, the FBI served Microsoft with a search warrant. Microsoft handed over the BitLocker encryption keys for three laptops. No hack. No breach. No compromised passwords. Just a warrant, and Microsoft&apos;s compliance. Here is what nobody in UK small business is talking about: those same default settings that allowed this are almost certainly running on your devices right now. And the legal mechanism that made it possible, the US CLOUD Act, reaches across the Atlantic directly into your Mic</description><pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate><category>us-cloud-act</category><category>uk-business</category><category>data-sovereignty</category><category>compliance-failure</category><category>vendor-risk</category><category>2026-threats</category><category>smb-security</category><author>Corrine Jefferson</author></item><item><title>The CLOUD Act and Your UK Business: The Unquantified Legal Risk Nobody Is Testing</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/the-cloud-act-and-your-uk-business-the-unquantified-legal-risk-nobody-is-testing/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/the-cloud-act-and-your-uk-business-the-unquantified-legal-risk-nobody-is-testing/</guid><description>The US CLOUD Act gives American courts the power to compel any US technology company to hand over your data, regardless of whether it sits in a London data centre or a bunker in Wyoming. UK GDPR Article 48 says foreign court orders do not make that transfer lawful. No UK court has tested this conflict. No ICO enforcement action has targeted it. The NCSC does not mention it by name. Corrine Jefferson, our resident intelligence analyst, dissects the legal contradiction sitting quietly in the middl</description><pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate><category>us-cloud-act</category><category>uk-business</category><category>data-sovereignty</category><category>compliance-failure</category><category>vendor-risk</category><category>2026-threats</category><category>smb-security</category><author>Corrine Jefferson</author></item><item><title>Switzerland Rejected Palantir. The UK Gave It the Keys to Everything.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/palantir-uk-contracts-data-sovereignty-risk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/palantir-uk-contracts-data-sovereignty-risk-2026/</guid><description>I used to work in US government intelligence. I now live in London. Those two facts make me uniquely uncomfortable about Palantir&apos;s expanding presence across the British state. In December 2024, Switzerland&apos;s military concluded that data held by Palantir could be accessed by the American government and that leaks &quot;cannot be technically prevented.&quot; Their recommendation was unambiguous: find alternatives. The UK&apos;s response to the same evidence has been to award Palantir more than £900 million in c</description><pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate><category>data-sovereignty</category><category>vendor-risk</category><category>us-cloud-act</category><category>uk-business</category><category>government-contracts</category><category>supply-chain-risk</category><category>compliance-failure</category><author>Corrine Jefferson</author></item><item><title>Nation-States Are Already Inside Your Network. Google Just Proved It.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/nation-state-vpn-edge-device-attacks-uk-business-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/nation-state-vpn-edge-device-attacks-uk-business-2026/</guid><description>I live in London. I used to work in US government intelligence. And when Google Threat Intelligence Group published their defence industrial base report on 10 February, I did what any former analyst does: I stopped reading the headlines and started reading the primary source. The findings are precise and they are uncomfortable. Chinese state-sponsored actors have exploited more than two dozen zero-day vulnerabilities in edge devices from ten different vendors since 2020. Average dwell time insid</description><pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate><author>Corrine Jefferson</author></item><item><title>When the Cybersecurity Guardian Uploads State Secrets to OpenAI: The CISA ChatGPT Incident</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cisa-acting-director-chatgpt-government-data-breach-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cisa-acting-director-chatgpt-government-data-breach-2026/</guid><description>The reality is this: the acting director of America&apos;s civilian cybersecurity agency uploaded sensitive government contracting documents to ChatGPT&apos;s public platform. Multiple automated alerts were triggered. A Department of Homeland Security investigation was launched. And somehow, this still happened. From my former life in government service, I can tell you this isn&apos;t just embarrassing. It&apos;s a systems failure that reveals fundamental problems with how we approach privileged access, AI governan</description><pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate><category>government-security</category><category>ai-security-risks</category><category>cisa</category><category>data-protection</category><category>insider-threat</category><category>us-cybersecurity</category><category>intelligence-analysis</category><author>Corrine Jefferson</author></item><item><title>The Slopocalypse in the Apple App Store: When Five-Star Apps Leak Your Life</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/slopocalypse-insecure-iphone-apps-leaking-data/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/slopocalypse-insecure-iphone-apps-leaking-data/</guid><description>The Apple App Store feels safe. That is the story many people tell themselves. Firehound and Vulnu show why that comfort can be dangerous. Researchers have flagged this week insecure iPhone apps that expose user data through badly secured cloud storage. Some leak private chats, email addresses, and location traces. Many of these apps look polished and carry strong ratings. That is the trap. In this guest post, Corrine Jefferson explains how slop apps slip through review, why AI apps raise the st</description><pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate><category>Apple App Store</category><category>iPhone Security</category><category>mobile app security</category><category>data leaks</category><category>cloud misconfiguration</category><category>AI apps</category><category>privacy</category><category>cyber security</category><category>UK SMB</category><category>Firehound</category><category>app review</category><author>Corrine Jefferson</author></item></channel></rss>