<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Mauven MacLeod — The Small Business Cybersecurity Guy</title><description>Every article by Mauven MacLeod. Straight-talking cybersecurity advice for UK small businesses.</description><link>https://thesmallbusinesscybersecurityguy.co.uk/</link><language>en-gb</language><item><title>Threat Analysis: Critical Vulnerabilities and UK Cyber Threats</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-uk-cyber-threats-2026-07-31/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-uk-cyber-threats-2026-07-31/</guid><description>Latest cyber threats and vulnerabilities impacting UK SMBs this July.</description><pubDate>Fri, 31 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>cloud-security</category><category>vendor-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Russian Email Attack Extended to Outlook, New NPM Risks</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-russian-outlook-attack-npm-worms-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-russian-outlook-attack-npm-worms-2026/</guid><description>Outlook email vulnerabilities and npm package risks highlight threats facing UK SMBs.</description><pubDate>Thu, 30 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>nation-state-attacks</category><category>supply-chain-risk</category><category>credential-theft</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Emerging Android RAT and Botnet Activity</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-flying-eagle-dysphoria-botnet-2026-07-29/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-flying-eagle-dysphoria-botnet-2026-07-29/</guid><description>Flying Eagle Android RAT and Dysphoria Botnet expose UK businesses to mobile fraud and sophisticated C2 threats.</description><pubDate>Wed, 29 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>mobile-banking-fraud</category><category>botnet</category><category>credential-theft</category><category>uk-business</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Helpdesk Hijackers and Critical WordPress Exploits, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-helpdesk-hijackers-wordpress-exploits-2026-07-28/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-helpdesk-hijackers-wordpress-exploits-2026-07-28/</guid><description>Helpdesk Hijackers exploit Teams, while WordPress vulnerabilities threaten site security. Act fast!</description><pubDate>Tue, 28 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>credential-theft</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Key Vulnerabilities Affecting UK SMBs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-key-vulnerabilities-july-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-key-vulnerabilities-july-2026/</guid><description>Critical vulnerabilities in Microsoft Defender and Java Spring Boot pose risks to UK SMBs. Update now.</description><pubDate>Mon, 27 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vulnerability-management</category><category>microsoft-defender</category><category>java-spring-boot</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Mistic Backdoor and FortiBleed Campaign, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-mistic-fortibleed-2026-07-24/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-mistic-fortibleed-2026-07-24/</guid><description>Mistic backdoor linked to ransomware, and the FortiBleed campaign highlight growing risks. Learn how to protect your SMB.</description><pubDate>Fri, 24 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>ransomware-groups</category><category>credential-theft</category><category>supply-chain-risk</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: AI Security Risks for UK SMBs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-ai-security-risks-uk-smbs-2026-07-23/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-ai-security-risks-uk-smbs-2026-07-23/</guid><description>New AI vulnerabilities like Dolphin X Stealer and rogue ChatGPT agents are targeting UK businesses. Here’s the analysis.</description><pubDate>Thu, 23 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>ai-threats</category><category>ransomware-groups</category><category>credential-theft</category><category>malware</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: UK SMBs and Key Cyber Threats in July 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-uk-smbs-cyber-threats-2026-07-22/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-uk-smbs-cyber-threats-2026-07-22/</guid><description>UK SMBs face critical cybersecurity threats from re-extortion ransomware and an exploited Langflow RCE flaw.</description><pubDate>Wed, 22 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>credential-theft</category><category>cloud-security</category><category>vendor-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Qilin Ransomware Exploits New VPN Flaw, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-qilin-ransomware-vpn-flaw-2026-07-21/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-qilin-ransomware-vpn-flaw-2026-07-21/</guid><description>A critical VPN flaw exploited by Qilin ransomware poses risks to UK SMBs. Urgent action required.</description><pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>remote-access</category><category>vendor-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: ServiceNow RCE Under Active Exploitation, Passkey Vishing, and the FortiBleed Credential Campaign</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-servicenow-rce-passkey-vishing-fortibleed-2026-07-20/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-servicenow-rce-passkey-vishing-fortibleed-2026-07-20/</guid><description>Three active threats UK SMBs need to act on today: a critical ServiceNow RCE, passkey enrolment vishing, and a large-scale FortiGate credential harvesting campaign.</description><pubDate>Mon, 20 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>remote-access</category><category>social-engineering</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: FortiSandbox Under Active Exploit, LegacyHive Zero-Day, and ClickFix Everywhere</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-fortisandbox-legacyhive-clickfix-2026-07-17/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-fortisandbox-legacyhive-clickfix-2026-07-17/</guid><description>FortiSandbox flaws are being actively exploited, a Windows zero-day with no patch is now public, and ClickFix attacks are hitting UK businesses daily. Here is what you need to know.</description><pubDate>Fri, 17 Jul 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>credential-theft</category><category>vendor-risk</category><category>remote-access</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Scattered Spider Sentenced, Trojanised Collaboration Tools, and the AsyncAPI Supply Chain Compromise</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-scattered-spider-tfl-starland-asyncapi-2026-07-16/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-scattered-spider-tfl-starland-asyncapi-2026-07-16/</guid><description>Five and a half years each for the TfL hackers. A Russian group hiding malware inside legitimate collaboration tools. And a supply chain worm loose in the npm ecosystem. Here is what today actually means.</description><pubDate>Thu, 16 Jul 2026 14:30:00 GMT</pubDate><category>uk-business</category><category>nation-state-attacks</category><category>social-engineering</category><category>credential-theft</category><category>supply-chain-risk</category><category>incident-response</category><category>smb-security</category><author>Mauven MacLeod</author></item><item><title>Hello, Mauven Here: Why the ICO&apos;s Experian Loss Matters More Than You Think</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ico-experian-upper-tribunal-loss-data-brokers-signal-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ico-experian-upper-tribunal-loss-data-brokers-signal-2026/</guid><description>Hello, Mauven here. The Upper Tribunal dismissed the ICO&apos;s Experian appeal in April 2024. Here is what the outcome signals about UK data broker regulation.</description><pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>compliance-failure</category><category>data-protection</category><category>public-sector-security</category><category>business-risk</category><category>executive-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: SharePoint Under Active Attack, AiTM Phishing Surge, and npm Supply Chain Compromise</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-sharepoint-aitm-npm-supply-chain-2026-07-15/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-sharepoint-aitm-npm-supply-chain-2026-07-15/</guid><description>Three stories today that UK SMBs cannot afford to ignore: SharePoint flaws being actively exploited, a sophisticated AiTM phishing operation, and a poisoned npm supply chain.</description><pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>supply-chain-risk</category><category>credential-theft</category><category>social-engineering</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: MFA-Bypassing Phishing Kits and AI-Accelerated Attack Infrastructure, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-mfa-bypass-phishing-kits-ai-c2-2026-07-14/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-mfa-bypass-phishing-kits-ai-c2-2026-07-14/</guid><description>Your MFA is not the safety net you think it is. Two new phishing kits are bypassing it right now, and AI is doing the heavy lifting for attackers.</description><pubDate>Tue, 14 Jul 2026 13:30:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>credential-theft</category><category>cloud-security</category><category>business-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Russian State Actors, ShareFile Emergency Shutdown, and DocuSign RMM Abuse, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-russian-router-exploitation-sharefile-shutdown-2026-07-13/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-russian-router-exploitation-sharefile-shutdown-2026-07-13/</guid><description>The NCSC has joined a Nine-Eyes advisory on Russian state actors targeting poorly configured routers. Meanwhile, Progress ShareFile has ordered an emergency server shutdown over an undisclosed threat.</description><pubDate>Mon, 13 Jul 2026 13:00:00 GMT</pubDate><category>nation-state-attacks</category><category>uk-business</category><category>smb-security</category><category>remote-access</category><category>supply-chain-risk</category><category>social-engineering</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: CitrixBleed 2 Ransomware Chain, SilabRAT MaaS, and the NHS Email Incident That Should Not Have Happened</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-citrixbleed2-silabrat-nhs-2026-07-10/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-citrixbleed2-silabrat-nhs-2026-07-10/</guid><description>Three stories today that together explain exactly how UK SMBs get compromised in 2026. One is a patched vulnerability nobody patched. One is a £3,900-a-month RAT. One is a CC field.</description><pubDate>Fri, 10 Jul 2026 13:00:00 GMT</pubDate><category>ransomware-groups</category><category>credential-theft</category><category>remote-access</category><category>smb-security</category><category>incident-response</category><category>vendor-risk</category><category>uk-business</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Microsoft Defender Zero-Day Patched, Vidar Infostealer Surge, and What the NCSC&apos;s New Cyber Essentials Pathway Actually Means</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-defender-zero-day-vidar-cyber-essentials-2026-07-09/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-defender-zero-day-vidar-cyber-essentials-2026-07-09/</guid><description>A Defender zero-day with public exploit code, a Vidar infostealer surge hitting developer toolchains, and a quiet but significant change to Cyber Essentials Plus certification.</description><pubDate>Thu, 09 Jul 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>social-engineering</category><category>compliance-failure</category><category>supply-chain-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Ubiquiti UniFi Critical Flaws and Adobe ColdFusion Under Active Exploitation, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-unifi-coldfusion-active-exploitation-2026-07-08/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-unifi-coldfusion-active-exploitation-2026-07-08/</guid><description>Two max-severity vulnerabilities are being actively exploited right now. If your office runs Ubiquiti kit or any ColdFusion-backed web infrastructure, read this first.</description><pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>incident-response</category><category>infrastructure-security</category><category>vendor-risk</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Microsoft Teams Helpdesk Scams, Multi-Stage Phishing RATs, and the UK Cyber Pledge Nobody Asked About</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-teams-helpdesk-scam-asyncrat-phishing-2026-07-07/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-teams-helpdesk-scam-asyncrat-phishing-2026-07-07/</guid><description>Fake IT support on Teams. Steganographic RAT delivery via phishing. And Capita signed a government cyber pledge. It has been that kind of day.</description><pubDate>Tue, 07 Jul 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>social-engineering</category><category>credential-theft</category><category>remote-access</category><category>business-risk</category><category>incident-response</category><category>uk-business</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Adobe ColdFusion CVE-2026-48282 and the Fake Helpdesk Wave Hitting UK Businesses</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-coldfusion-cve-2026-48282-vishing-pink-2026-07-06/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-coldfusion-cve-2026-48282-vishing-pink-2026-07-06/</guid><description>CVE-2026-48282 is being exploited in the wild. Meanwhile, a criminal group called Pink is ringing your staff and talking their way past MFA. Here is what both mean for your business.</description><pubDate>Mon, 06 Jul 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>credential-theft</category><category>vendor-risk</category><category>remote-access</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: ARToken M365 Phishing Platform, Avalon Ransomware Framework, and a 2-Million-Device Botnet, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-artoken-avalon-netnut-botnet-2026-07-03/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-artoken-avalon-netnut-botnet-2026-07-03/</guid><description>Three active campaigns with direct UK SMB exposure: a sophisticated M365 phishing platform, a legal-lure ransomware framework, and a residential proxy botnet the FBI just cracked open.</description><pubDate>Fri, 03 Jul 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>ransomware-groups</category><category>social-engineering</category><category>cloud-security</category><category>vendor-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: The Gentlemen Ransomware and ARToken Phishing Platform, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-gentlemen-ransomware-artoken-m365-2026-07-01/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-gentlemen-ransomware-artoken-m365-2026-07-01/</guid><description>Two threats. One kills your endpoint security before you know it&apos;s there. The other hands your Microsoft 365 to criminals on a subscription basis.</description><pubDate>Wed, 01 Jul 2026 09:00:00 GMT</pubDate><category>ransomware-groups</category><category>credential-theft</category><category>smb-security</category><category>uk-business</category><category>cloud-security</category><category>msp-security</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: BlueHammer Ransomware Escalation and SimpleHelp RMM Exploitation, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-bluehammer-ransomware-simplehelp-rmm-2026-06-30/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-bluehammer-ransomware-simplehelp-rmm-2026-06-30/</guid><description>Ransomware gangs are now exploiting a Windows Defender privilege escalation flaw confirmed by CISA. If your MSP uses SimpleHelp, you have a second problem to deal with today.</description><pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate><category>ransomware-groups</category><category>smb-security</category><category>msp-security</category><category>remote-access</category><category>vendor-risk</category><category>supply-chain-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Hello, Mauven Here: The UK Data Broker Market Just Got a Legal Upgrade It Did Not Deserve</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/duaa-data-broker-legitimate-interests-uk-directors-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/duaa-data-broker-legitimate-interests-uk-directors-2026/</guid><description>The Data Use and Access Act 2025 clarifies that direct marketing can be a legitimate interest. The data broker industry is delighted. You should pay attention.</description><pubDate>Tue, 30 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>compliance-failure</category><category>data-protection</category><category>business-risk</category><category>executive-security</category><category>public-sector-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Oracle EBS Under Active Exploitation and the DriveSurge Drive-By Campaign, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-oracle-ebs-drivesurge-uk-smbs-2026-06-29/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-oracle-ebs-drivesurge-uk-smbs-2026-06-29/</guid><description>Oracle&apos;s E-Business Suite is being actively exploited right now. And a new initial access broker is turning legitimate websites into malware delivery points.</description><pubDate>Mon, 29 Jun 2026 14:30:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>supply-chain-risk</category><category>credential-theft</category><category>business-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>The Week Ahead: Stop Treating KEV Like a Newsletter</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/week-ahead-kev-catalogue-weekly-habit-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/week-ahead-kev-catalogue-weekly-habit-uk-smb-2026/</guid><description>KEV is not interesting. It is known exploited. Turning the catalogue into a five-minute weekly check is the cheapest security upgrade most SMBs can make.</description><pubDate>Sun, 28 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>remote-access</category><category>incident-response</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Mini Shai-Hulud and CVE-2026-20245 - What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-mini-shai-hulud-cve-2026-20245-2026-06-26/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-mini-shai-hulud-cve-2026-20245-2026-06-26/</guid><description>Today&apos;s focus: Supply chain attacks on npm packages and active zero-day exploitation in Cisco SD-WAN. Crucial for UK SMBs.</description><pubDate>Fri, 26 Jun 2026 09:00:00 GMT</pubDate><category>supply-chain-risk</category><category>cloud-security</category><category>smb-security</category><category>vendor-risk</category><category>malware</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: New Backdoor and FortiGate Campaign Uncovered, What SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/new-backdoor-fortigate-threats-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/new-backdoor-fortigate-threats-2026/</guid><description>Exploring recent threats: a new backdoor may be linked to ransomware, and a large-scale FortiGate campaign affects security.</description><pubDate>Thu, 25 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>credential-theft</category><category>supply-chain-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Mistic Backdoor and KongTuke Broker, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-mistic-backdoor-2026-06-24/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-mistic-backdoor-2026-06-24/</guid><description>UK SMBs must be aware: Mistic backdoor linked to ransomware broker is active. What this means for your security.</description><pubDate>Wed, 24 Jun 2026 15:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>vendor-risk</category><category>incident-response</category><category>supply-chain-risk</category><author>Mauven MacLeod</author></item><item><title>Defence in Depth Is Not a Bundle You Can Buy</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/defence-in-depth-not-a-bundle-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/defence-in-depth-not-a-bundle-uk-smb-2026/</guid><description>Buying a firewall, endpoint protection, and a backup product is not Defence in Depth. It is a collection of controls. The difference matters.</description><pubDate>Tue, 23 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>remote-access</category><category>business-risk</category><category>compliance-failure</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Klue Supply Chain Attack and Five Eyes Warning</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/klue-attack-five-eyes-warning-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/klue-attack-five-eyes-warning-2026/</guid><description>Klue&apos;s Salesforce breach affects UK SMBs. Dive into supply chain vulnerabilities and AI risks.</description><pubDate>Tue, 23 Jun 2026 09:00:00 GMT</pubDate><category>supply-chain-risk</category><category>smb-security</category><category>uk-business</category><category>nation-state-attacks</category><category>cloud-security</category><category>vendor-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Key UK Cyber Threats, Strategic Insights for 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-cyber-threats-analysis-2026-06-22/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-cyber-threats-analysis-2026-06-22/</guid><description>Analysing key cyber threats affecting UK businesses today. From supply chain attacks to AI risks, stay informed.</description><pubDate>Mon, 22 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>supply-chain-risk</category><category>ransomware-groups</category><category>cloud-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: npm Supply Chain Surge and Splunk Under Active Exploit, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-npm-supply-chain-splunk-exploit-2026-06-19/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-npm-supply-chain-splunk-exploit-2026-06-19/</guid><description>Your developers&apos; tools and your logging stack are both under active attack today. Here is what is actually happening and what to do about it.</description><pubDate>Fri, 19 Jun 2026 14:00:00 GMT</pubDate><category>supply-chain-risk</category><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>vendor-risk</category><category>incident-response</category><category>msp-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: FortiBleed, SocGholish Takedown, and WordPress Supply Chain, 18th June 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-fortibleed-socgholish-wordpress-supply-chain-2026-06-18/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-fortibleed-socgholish-wordpress-supply-chain-2026-06-18/</guid><description>73,000 Fortinet VPN credentials leaked, Evil Corp&apos;s botnet dismantled, and WordPress plugin supply chain compromised again. Three stories that matter to UK small businesses today.</description><pubDate>Thu, 18 Jun 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>supply-chain-risk</category><category>ransomware-groups</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: DragonForce Hides in Microsoft Teams, Joomla Flaw Actively Exploited, and RoguePlanet Still Unpatched</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-dragonforce-teams-joomla-rogueplanet-2026-06-17/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-dragonforce-teams-joomla-rogueplanet-2026-06-17/</guid><description>Three active threats UK SMBs cannot ignore today: ransomware hiding in Microsoft&apos;s own infrastructure, a Joomla CMS exploit already in the wild, and an unpatched Defender zero-day.</description><pubDate>Wed, 17 Jun 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>social-engineering</category><category>credential-theft</category><category>remote-access</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: DragonForce Hides in Microsoft Teams, Fortinet Flaws Hit, and Your WordPress Site Is Probably Compromised</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-dragonforce-teams-fortinet-fortisandbox-2026-06-16/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-dragonforce-teams-fortinet-fortisandbox-2026-06-16/</guid><description>DragonForce is hiding ransomware command traffic inside Microsoft Teams. Fortinet FortiSandbox has critical flaws being actively exploited. Here is what UK SMBs need to know today.</description><pubDate>Tue, 16 Jun 2026 13:00:00 GMT</pubDate><category>ransomware-groups</category><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>vendor-risk</category><category>incident-response</category><category>supply-chain-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: SearchLeak and Cisco SD-WAN Auth Bypass, What UK SMBs Need to Know Today</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-searchleak-cisco-sdwan-2026-06-15/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-searchleak-cisco-sdwan-2026-06-15/</guid><description>Microsoft 365 Copilot has a critical vulnerability chain that lets an attacker steal your mailbox data with a single crafted URL. Cisco SD-WAN is under active exploitation. Both matter to UK SMBs right now.</description><pubDate>Mon, 15 Jun 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>cloud-security</category><category>credential-theft</category><category>vendor-risk</category><category>supply-chain-risk</category><category>remote-access</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: AI-Powered Phishing Surge, Novo Nordisk Clinical Data Breach, and What UK SMBs Must Do Now</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-ai-phishing-novo-nordisk-breach-2026-06-12/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-ai-phishing-novo-nordisk-breach-2026-06-12/</guid><description>AI-powered phishing is scaling faster than organisations can train against it. Three stories today that UK SMBs cannot afford to ignore.</description><pubDate>Fri, 12 Jun 2026 14:00:00 GMT</pubDate><category>social-engineering</category><category>credential-theft</category><category>uk-business</category><category>smb-security</category><category>vendor-risk</category><category>supply-chain-risk</category><category>compliance-failure</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: The Gentlemen Ransomware and AI-Powered Phishing, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-gentlemen-ransomware-ai-phishing-2026-06-12/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-gentlemen-ransomware-ai-phishing-2026-06-12/</guid><description>A high-volume ransomware operation with Russian-speaking roots and an AI-powered phishing platform impersonating trusted brands. Both are active today.</description><pubDate>Fri, 12 Jun 2026 13:00:00 GMT</pubDate><category>ransomware-groups</category><category>social-engineering</category><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>business-risk</category><category>supply-chain-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Fake Helpdesk Vishing Campaign and ClickFix RAT Delivery, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-vishing-clickfix-rat-uk-smb-2026-06-05/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-vishing-clickfix-rat-uk-smb-2026-06-05/</guid><description>Two active campaigns are hitting organisations that look exactly like UK SMBs. One calls your staff pretending to be IT support. The other fakes LinkedIn and Indeed.</description><pubDate>Fri, 05 Jun 2026 09:00:00 GMT</pubDate><category>social-engineering</category><category>credential-theft</category><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>incident-response</category><category>cloud-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: npm Supply Chain Attack, Five Eyes China Warning, and NCSC Dependency Alert</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-npm-supply-chain-five-eyes-china-ncsc-2026-06-04/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-npm-supply-chain-five-eyes-china-ncsc-2026-06-04/</guid><description>Three separate threat streams converging today, and all three have direct exposure for UK SMBs and their IT suppliers.</description><pubDate>Thu, 04 Jun 2026 13:00:00 GMT</pubDate><category>supply-chain-risk</category><category>nation-state-attacks</category><category>uk-business</category><category>smb-security</category><category>vendor-risk</category><category>credential-theft</category><category>msp-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: PhaaS Campaigns, Teams-Based RAT Deployment, and Unpatched Acer Router Zero-Days Threatening UK SMBs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-phaas-nimbus-rat-acer-zero-days-2026-06-03/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-phaas-nimbus-rat-acer-zero-days-2026-06-03/</guid><description>Three active threats converging on UK SMBs today: a mass phishing platform bypassing MFA, a RAT delivered via Microsoft Teams, and two unpatched maximum-severity router vulnerabilities.</description><pubDate>Wed, 03 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>credential-theft</category><category>remote-access</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Nimbus RAT via Teams Vishing, Oracle WebLogic KEV, and the npm Supply Chain Under Active Attack</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-nimbus-rat-teams-oracle-kev-npm-supply-chain-2026-06-02/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-nimbus-rat-teams-oracle-kev-npm-supply-chain-2026-06-02/</guid><description>Three active threats that UK SMBs need to act on today: a Java RAT delivered via Microsoft Teams, a two-year-old Oracle flaw now on the CISA KEV list, and 33 malicious npm packages stealing cloud credentials.</description><pubDate>Tue, 02 Jun 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>social-engineering</category><category>supply-chain-risk</category><category>credential-theft</category><category>remote-access</category><category>uk-business</category><category>vendor-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Netlogon RCE and Palo Alto Auth Bypass Now Actively Exploited, What UK SMBs Need to Do Today</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-netlogon-rce-palo-alto-auth-bypass-2026-06-01/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-netlogon-rce-palo-alto-auth-bypass-2026-06-01/</guid><description>Patch windows have closed. Both the Windows Netlogon RCE and Palo Alto GlobalProtect auth bypass are now being exploited in the wild. Here is what that means for your business.</description><pubDate>Mon, 01 Jun 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>credential-theft</category><category>incident-response</category><category>vendor-risk</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: FortiClient EMS Exploitation, Phoenix PhaaS, and AI-Assisted Attacks, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-forticlient-ems-phoenix-phaas-ai-attacks-2026-05-29/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-forticlient-ems-phoenix-phaas-ai-attacks-2026-05-29/</guid><description>Three active threats converge today: a FortiClient EMS zero-day delivering infostealers, a PhaaS kit with MFA bypass, and AI-assisted espionage campaigns lowering the barrier for every attacker downstream.</description><pubDate>Fri, 29 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>social-engineering</category><category>vendor-risk</category><category>ransomware-groups</category><category>remote-access</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: BlackFile Extortion, ShinyHunters Data Theft, and the Voice Phishing Wave Hitting UK Businesses</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-blackfile-shinyhunters-voice-phishing-2026-05-28/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-blackfile-shinyhunters-voice-phishing-2026-05-28/</guid><description>Two financially-motivated threat groups are running active campaigns that should concern every UK business with a helpdesk, a SaaS stack, or customers whose data you hold.</description><pubDate>Thu, 28 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>credential-theft</category><category>vendor-risk</category><category>incident-response</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Blockchain C2, LiteSpeed cPanel Exploit, and SRG&apos;s Physical Pivot, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-blockchain-c2-cpanel-srg-physical-2026-05-27/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-blockchain-c2-cpanel-srg-physical-2026-05-27/</guid><description>Blockchain-based C2 infrastructure, an actively exploited cPanel flaw, and an extortion gang that now shows up in person. Mauven explains what the advisories are not telling you.</description><pubDate>Wed, 27 May 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>credential-theft</category><category>supply-chain-risk</category><category>remote-access</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: OAuth Device Code Phishing, Laravel Supply Chain Compromise, and an Actively Exploited Drupal Flaw</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-oauth-phishing-laravel-supply-chain-drupal-2026-05-26/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-oauth-phishing-laravel-supply-chain-drupal-2026-05-26/</guid><description>Three separate threats with direct SMB exposure landed today. One targets Microsoft 365 credentials, one hits developers and their clients, and one is already being exploited in the wild.</description><pubDate>Tue, 26 May 2026 13:00:00 GMT</pubDate><category>credential-theft</category><category>supply-chain-risk</category><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Kali365 MFA Bypass and Laravel Supply Chain Compromise, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-kali365-laravel-supply-chain-2026-05-25/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-kali365-laravel-supply-chain-2026-05-25/</guid><description>MFA is not the safety net you think it is. The FBI confirmed it this week. Here is what UK SMBs need to do right now.</description><pubDate>Mon, 25 May 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>supply-chain-risk</category><category>cloud-security</category><category>social-engineering</category><category>msp-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Drupal SQL Injection Under Active Exploitation, Ubiquiti Max-Severity Flaws, and The Gentlemen Ransomware&apos;s UK Reach</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-drupal-sql-injection-ubiquiti-gentlemen-ransomware-2026-05-22/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-drupal-sql-injection-ubiquiti-gentlemen-ransomware-2026-05-22/</guid><description>Active exploitation of Drupal&apos;s SQL injection flaw began within 48 hours of disclosure. If your website or your supplier&apos;s runs Drupal, this is not a drill.</description><pubDate>Fri, 22 May 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>vendor-risk</category><category>supply-chain-risk</category><category>incident-response</category><category>network-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Fox Tempest Malware-Signing Service, Supply Chain npm Attacks, and a Maximum-Severity Cisco Flaw</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-fox-tempest-npm-supply-chain-cisco-2026-05-21/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-fox-tempest-npm-supply-chain-cisco-2026-05-21/</guid><description>A malware-signing service is making ransomware harder to detect. npm packages with millions of downloads are compromised. And Cisco just patched a perfect-10 vulnerability.</description><pubDate>Thu, 21 May 2026 15:00:00 GMT</pubDate><category>smb-security</category><category>supply-chain-risk</category><category>ransomware-groups</category><category>vendor-risk</category><category>uk-business</category><category>msp-security</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>What The NCSC Has Been Telling You About BitLocker For Years</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ncsc-bitlocker-tpm-pin-yellowkey-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ncsc-bitlocker-tpm-pin-yellowkey-uk-2026/</guid><description>The NCSC&apos;s Windows guidance has recommended TPM plus PIN for years. Most UK organisations ignored it. YellowKey just changed what that decision costs.</description><pubDate>Wed, 20 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>compliance-failure</category><category>executive-security</category><category>public-sector-security</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: FlowerStorm PhaaS MFA Bypass and Vidar Go Infostealer, UK SMB Threat Brief 19th May 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-flowerstorm-phaas-vidar-go-2026-05-19/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-flowerstorm-phaas-vidar-go-2026-05-19/</guid><description>MFA bypass-as-a-service is now sophisticated enough to defeat most SMB defences. Vidar is back, rebuilt in Go, and harder to detect than ever.</description><pubDate>Tue, 19 May 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>social-engineering</category><category>cloud-security</category><category>msp-security</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>43% Breached and Nobody Is Surprised: What the DSIT Survey Really Tells Us About UK Business Security</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/dsit-breaches-survey-2025-2026-reaction-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/dsit-breaches-survey-2025-2026-reaction-uk-smb-2026/</guid><description>43% of UK businesses breached. Revenue impact doubled. Board engagement finally rising. Mauven MacLeod reads between the lines of the DSIT survey.</description><pubDate>Tue, 19 May 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>compliance-failure</category><category>business-risk</category><category>social-engineering</category><category>supply-chain-risk</category><category>public-sector-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: NGINX Rift Under Active Exploitation and Grafana Source Code Theft, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-nginx-rift-grafana-breach-2026-05-18/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-nginx-rift-grafana-breach-2026-05-18/</guid><description>A days-old NGINX vulnerability is already being probed and exploited. Grafana&apos;s source code was stolen via a single access token. Two stories, one theme: patch windows are collapsing.</description><pubDate>Mon, 18 May 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>supply-chain-risk</category><category>credential-theft</category><category>remote-access</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Exchange Zero-Day, Device Code Phishing, and npm Supply Chain Attack, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-exchange-zero-day-device-code-phishing-npm-supply-chain-2026-05-15/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-exchange-zero-day-device-code-phishing-npm-supply-chain-2026-05-15/</guid><description>Three active threats converge today: an exploited Exchange zero-day, a surge in device code phishing targeting Microsoft 365, and a supply chain attack that caught OpenAI. All three have direct implications for UK SMBs.</description><pubDate>Fri, 15 May 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>supply-chain-risk</category><category>social-engineering</category><category>incident-response</category><category>cloud-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: KongTuke Teams Attacks and Fragnesia Linux Flaw, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-kongtuke-teams-fragnesia-linux-2026-05-14/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-kongtuke-teams-fragnesia-linux-2026-05-14/</guid><description>An initial access broker is using Microsoft Teams to own corporate networks in five minutes flat. A Linux kernel privilege escalation with working exploit code dropped today. Neither is theoretical.</description><pubDate>Thu, 14 May 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>credential-theft</category><category>remote-access</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: The Gentlemen Ransomware and Supply Chain Poisoning, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-gentlemen-ransomware-supply-chain-2026-05-13/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-gentlemen-ransomware-supply-chain-2026-05-13/</guid><description>A new ransomware operation with Qilin connections is accelerating. Supply chain attacks are poisoning developer tools and AI platforms. Here is what matters today.</description><pubDate>Wed, 13 May 2026 13:00:00 GMT</pubDate><category>ransomware-groups</category><category>supply-chain-risk</category><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>credential-theft</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>When Cheap IT Voids Your Cyber Cover: The UK Government Numbers Bosses Are Avoiding</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cheap-it-voids-cyber-insurance-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cheap-it-voids-cyber-insurance-uk-2026/</guid><description>Hello, Mauven here. Cyber insurance uptake is up. So are denied claims. The common thread is the IT contract that never asked to read the policy.</description><pubDate>Wed, 13 May 2026 07:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>compliance-failure</category><category>business-risk</category><category>msp-security</category><category>vendor-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Shai-Hulud Supply Chain Campaign and The Gentleman Ransomware, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-shai-hulud-supply-chain-etherrat-gentleman-ransomware-2026-05-12/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-shai-hulud-supply-chain-etherrat-gentleman-ransomware-2026-05-12/</guid><description>Signed packages, a six-minute supply chain blitz, and ransomware using blockchain to hide its C2. Today&apos;s brief covers two threats that reach well beyond enterprise targets.</description><pubDate>Tue, 12 May 2026 14:00:00 GMT</pubDate><category>supply-chain-risk</category><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>credential-theft</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: AI-Generated Exploits, Cloud-Native Phishing, and TrickMo&apos;s Blockchain Pivot, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-ai-exploits-cloud-phishing-trickmo-2026-05-11/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-ai-exploits-cloud-phishing-trickmo-2026-05-11/</guid><description>AI is now writing zero-day exploits. Cloud infrastructure is being weaponised against your staff. And TrickMo just made its banking trojan significantly harder to detect.</description><pubDate>Mon, 11 May 2026 09:00:00 GMT</pubDate><category>nation-state-attacks</category><category>social-engineering</category><category>credential-theft</category><category>cloud-security</category><category>smb-security</category><category>uk-business</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: APT28 Router Hijacking, Ivanti Zero-Day, and the RMM Abuse Wave Hitting UK SMBs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-apt28-dns-hijack-ivanti-zerodday-rmm-abuse-2026-05-08/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-apt28-dns-hijack-ivanti-zerodday-rmm-abuse-2026-05-08/</guid><description>APT28 is rewriting your router&apos;s DNS settings. Ivanti EPMM has a zero-day with active exploitation. And threat actors are abusing remote management tools to drop malware via phishing. Here is what UK SMBs need to know today.</description><pubDate>Fri, 08 May 2026 14:30:00 GMT</pubDate><category>nation-state-attacks</category><category>remote-access</category><category>credential-theft</category><category>smb-security</category><category>vendor-risk</category><category>incident-response</category><category>uk-business</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: PAN-OS Zero-Day, Storm-1175 Ransomware, and the Supply Chain Problem Nobody Is Fixing</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-panos-zero-day-storm-1175-supply-chain-2026-05-07/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-panos-zero-day-storm-1175-supply-chain-2026-05-07/</guid><description>State-sponsored actors had a month inside Palo Alto firewalls before the advisory came out. Storm-1175 is still moving. And your developers may have already run the poisoned package.</description><pubDate>Thu, 07 May 2026 09:00:00 GMT</pubDate><category>nation-state-attacks</category><category>ransomware-groups</category><category>supply-chain-risk</category><category>smb-security</category><category>remote-access</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: PAN-OS Zero-Day and MuddyWater&apos;s Teams Deception, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-panos-zero-day-muddywater-teams-2026-05-06/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-panos-zero-day-muddywater-teams-2026-05-06/</guid><description>A Palo Alto firewall zero-day is being actively exploited right now. And MuddyWater is using Microsoft Teams to walk through your front door. Both matter today.</description><pubDate>Wed, 06 May 2026 13:30:00 GMT</pubDate><category>nation-state-attacks</category><category>remote-access</category><category>social-engineering</category><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Concern Is Not a Control: Why UK Small Business Cyber Hygiene Went Backwards While Awareness Went Up</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-awareness-action-gap-uk-small-business-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-awareness-action-gap-uk-small-business-2026/</guid><description>Awareness went up. Risk assessments went down. Continuity plans dropped 9 points. If concern was a control, the survey numbers would look very different.</description><pubDate>Wed, 06 May 2026 07:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>compliance-failure</category><category>executive-security</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Trojanised Microsoft Teams Installers, Third-Party Supplier Breaches, and £102M in UK Romance Fraud</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-teams-installer-supply-chain-romance-fraud-2026-05-05/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-teams-installer-supply-chain-romance-fraud-2026-05-05/</guid><description>A fake Teams installer is dropping backdoors globally. A third-party analytics vendor handed ShinyHunters 119,000 email addresses. And UK romance fraud hit £102M last year. Three stories, one briefing.</description><pubDate>Tue, 05 May 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>supply-chain-risk</category><category>credential-theft</category><category>vendor-risk</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: MOVEit Automation Auth Bypass, Linux &apos;Copy Fail&apos; Exploitation, and PyPI Supply Chain Attack — What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-moveit-linux-pypi-supply-chain-2026-05-04/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-moveit-linux-pypi-supply-chain-2026-05-04/</guid><description>Three high-impact threats landed simultaneously on 4th May 2026. If your business uses MOVEit, runs Linux servers, or has developers using Python, read this now.</description><pubDate>Mon, 04 May 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>supply-chain-risk</category><category>vendor-risk</category><category>incident-response</category><category>msp-security</category><category>remote-access</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: TeamPCP Supply Chain Attack and the Coming Patch Tsunami, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-teampcp-supply-chain-patch-tsunami-2026-05-02/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-teampcp-supply-chain-patch-tsunami-2026-05-02/</guid><description>A supply chain attack on open-source security tooling and a Linux privilege escalation exploit with working code in the wild. Two threats. One uncomfortable Friday.</description><pubDate>Sat, 02 May 2026 09:00:00 GMT</pubDate><category>supply-chain-risk</category><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>incident-response</category><category>cloud-security</category><category>msp-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Critical cPanel Exploit, TeamPCP Supply Chain Attacks, and the NCSC&apos;s Patch Wave Warning</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-cpanel-teampcp-ncsc-patch-wave-2026-05-01/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-cpanel-teampcp-ncsc-patch-wave-2026-05-01/</guid><description>A critical cPanel flaw is being actively exploited with ransomware already reported. TeamPCP is poisoning open-source security tools. The NCSC says a patch wave is coming. Today is not a quiet day.</description><pubDate>Fri, 01 May 2026 13:30:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>supply-chain-risk</category><category>ransomware-groups</category><category>vendor-risk</category><category>incident-response</category><category>compliance-failure</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: CVE-2026-41940 cPanel Zero-Day, Linux Copy Fail LPE, and UK Breach Rate Holds at 43%</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-cpanel-zero-day-linux-lpe-uk-breach-rate-2026-04-30/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-cpanel-zero-day-linux-lpe-uk-breach-rate-2026-04-30/</guid><description>A critical cPanel authentication bypass has been exploited since February. A new Linux root exploit dropped today. And 43% of UK businesses were compromised last year. Pick your priority.</description><pubDate>Thu, 30 Apr 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>vendor-risk</category><category>incident-response</category><category>compliance-failure</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: cPanel Auth Bypass, ClickFix Phishing, and VECT Ransomware — What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-cpanel-clickfix-vect-ransomware-2026-04-29/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-cpanel-clickfix-vect-ransomware-2026-04-29/</guid><description>This week&apos;s threat brief covers a critical cPanel auth bypass requiring emergency patching, ClickFix phishing campaigns stealing credentials via PowerShell, and VECT ransomware that wipes files it cannot encrypt.</description><pubDate>Wed, 29 Apr 2026 16:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>ransomware-groups</category><category>social-engineering</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>The Cyber Resilience Pledge: What the Corridor Conversations at CyberUK Actually Revealed</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-resilience-pledge-insider-analysis-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-resilience-pledge-insider-analysis-uk-2026/</guid><description>I was in the room when the Cyber Resilience Pledge was announced. The speeches were confident. The corridor conversations afterwards were not.</description><pubDate>Wed, 29 Apr 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>compliance-failure</category><category>supply-chain-risk</category><category>public-sector-security</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: BlackFile Extortion, Supply Chain Poisoning, and OAuth Phishing — UK SMB Threat Brief, April 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-blackfile-supply-chain-oauth-phishing-2026-04-28/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-blackfile-supply-chain-oauth-phishing-2026-04-28/</guid><description>Three active campaigns converge on UK small businesses this week: voice-driven extortion, poisoned developer packages, and OAuth phishing that bypasses MFA. Here is what they are not telling you.</description><pubDate>Tue, 28 Apr 2026 14:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>credential-theft</category><category>supply-chain-risk</category><category>cloud-security</category><category>vendor-risk</category><author>Mauven MacLeod</author></item><item><title>A Black Box with Flashy Lights: The NCSC&apos;s SilentGlass and the Question Nobody Is Asking</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/silentglass-ncsc-hdmi-displayport-security-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/silentglass-ncsc-hdmi-displayport-security-smb-2026/</guid><description>NCSC&apos;s SilentGlass is technically sound government kit, now available commercially. But if you&apos;re still fighting phishing, it&apos;s probably not your next purchase.</description><pubDate>Tue, 28 Apr 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>nation-state-attacks</category><category>public-sector-security</category><category>vendor-risk</category><category>executive-security</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: PyPI and npm Supply Chain Attacks, What UK SMBs Need to Know About the TeamPCP Campaign</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-pypi-npm-supply-chain-teampcp-2026-04-27/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-pypi-npm-supply-chain-teampcp-2026-04-27/</guid><description>TeamPCP is back. Three concurrent package compromises in one week. Here is what UK businesses using Python or Node.js tooling need to do right now.</description><pubDate>Mon, 27 Apr 2026 16:00:00 GMT</pubDate><category>supply-chain-risk</category><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>cloud-security</category><category>vendor-risk</category><category>msp-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: BlackFile Extortion and Supply Chain Poisoning — UK Cyber Threats, 27 Apr 2026</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-blackfile-supply-chain-pypi-2026-04-27/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-blackfile-supply-chain-pypi-2026-04-27/</guid><description>Voice phishing plus credential harvesting. Malicious Python packages with 11 million monthly downloads. This is what active UK cyber threats look like today.</description><pubDate>Mon, 27 Apr 2026 13:00:00 GMT</pubDate><category>social-engineering</category><category>credential-theft</category><category>supply-chain-risk</category><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: Supply Chain Poisoning via PyPI and npm, What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-pypi-npm-supply-chain-attack-2026-04-27/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-pypi-npm-supply-chain-attack-2026-04-27/</guid><description>PyPI and npm are under active supply chain attack. If your business uses Python packages or JavaScript tooling u2014 or relies on suppliers who do u2014 this is not a developer problem. It is your problem.</description><pubDate>Mon, 27 Apr 2026 08:00:00 GMT</pubDate><category>supply-chain-risk</category><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>cloud-security</category><category>vendor-risk</category><category>msp-security</category><author>Mauven MacLeod</author></item><item><title>Threat Analysis: UK Cyber Threats Roundup, What SMBs Need to Know This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-uk-cyber-threats-smb-roundup-2026-04-26/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/threat-analysis-uk-cyber-threats-smb-roundup-2026-04-26/</guid><description>A quiet day on the KEV and NVD feeds. Mauven explains why that is not the same as a safe day.</description><pubDate>Sun, 26 Apr 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>nation-state-attacks</category><category>ransomware-groups</category><category>business-risk</category><category>incident-response</category><category>supply-chain-risk</category><author>Mauven MacLeod</author></item><item><title>The NCSC Built Protective DNS for Government. Private Sector SMBs Are Still Guessing.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ncsc-protective-dns-private-sector-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ncsc-protective-dns-private-sector-smb-2026/</guid><description>The NCSC has blocked 1.5 million malicious domains with Protective DNS. Private sector SMBs do not qualify. Here is what that gap means and how to close it.</description><pubDate>Wed, 22 Apr 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>public-sector-security</category><category>business-risk</category><category>vendor-risk</category><category>supply-chain-risk</category><category>incident-response</category><author>Mauven MacLeod</author></item><item><title>Preparing for the Next Wave of Cyber Threats: Insights for UK SMBs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/preparing-for-the-next-wave-of-cyber-threats-insights-for-uk-smbs/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/preparing-for-the-next-wave-of-cyber-threats-insights-for-uk-smbs/</guid><description>63% of UK SMBs faced cyber incidents in 2023. Learn how to prepare and protect your business assets effectively.</description><pubDate>Sat, 18 Apr 2026 16:00:00 GMT</pubDate><category>cyber threats</category><category>preparation</category><category>UK SMB</category><category>security</category><author>Mauven MacLeod</author></item><item><title>The War Exclusion in Your Cyber Policy: Why Being Collateral Damage Might Not Be Covered</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/lloyds-state-backed-cyber-exclusion-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/lloyds-state-backed-cyber-exclusion-uk-smb-2026/</guid><description>Your cyber policy probably excludes losses from state-backed attacks. You may not have read that clause. If a nation-state campaign sweeps through your sector, it could void your cover entirely.</description><pubDate>Wed, 08 Apr 2026 06:00:00 GMT</pubDate><category>cyber-insurance</category><category>nation-state-attacks</category><category>uk-business</category><category>lloyds-exclusion</category><category>threat-intelligence</category><category>smb-security</category><category>2026-threats</category><author>Mauven MacLeod</author></item><item><title>Unsupported Software and UK GDPR: The Compliance Risk You Cannot Ignore</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/out-of-support-software-uk-gdpr-compliance-risk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/out-of-support-software-uk-gdpr-compliance-risk-2026/</guid><description>Article 32 of UK GDPR requires &apos;appropriate technical measures&apos; to protect personal data. Running unpatched, out-of-support software is very difficult to defend as appropriate.</description><pubDate>Wed, 01 Apr 2026 07:00:00 GMT</pubDate><category>uk-gdpr</category><category>compliance-failure</category><category>end-of-life-software</category><category>data-protection</category><category>ico-enforcement</category><category>cyber-essentials</category><category>smb-security</category><author>Mauven MacLeod</author></item><item><title>Understanding the Risks of Remote Work: Securing Your Home Office</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/understanding-the-risks-of-remote-work-securing-your-home-office/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/understanding-the-risks-of-remote-work-securing-your-home-office/</guid><description>Your remote workers aren&apos;t in your office, but your data still is. Here&apos;s why most home working security failures are people problems, not tech problems.</description><pubDate>Sun, 29 Mar 2026 18:00:00 GMT</pubDate><category>Remote Work</category><category>Cybersecurity</category><category>Home Office</category><category>Small Business</category><author>Mauven MacLeod</author></item><item><title>Confidence Is Not a Security Control: What Happened When Noel Left Us Unsupervised</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/confidence-is-not-a-security-control-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/confidence-is-not-a-security-control-uk-smb-2026/</guid><description>Noel left us unsupervised, two bottles of Prosecco, and a microphone. What followed was a serious conversation about the security vulnerability nobody likes to name: overconfidence. The kind that sounds completely reasonable in a meeting — and has preceded some very expensive afternoons.</description><pubDate>Mon, 23 Mar 2026 11:58:00 GMT</pubDate><category>Security Culture</category><category>Overconfidence</category><category>UK Small Business</category><category>Podcast</category><category>SMB Security</category><author>Mauven MacLeod</author></item><item><title>Why SMBs Draw Their Cyber Essentials Scope Around the Comfortable Parts</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/why-smbs-draw-their-cyber-essentials-scope-around-the-comfortable-parts/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/why-smbs-draw-their-cyber-essentials-scope-around-the-comfortable-parts/</guid><description>After years observing how organisations navigate security certification, I have reached a fairly uncomfortable conclusion: most scope failures in Cyber Essentials are not technical errors. They are decisions. Somebody looked at the full picture of what should be in scope, felt the weight of what that would require, and drew the line somewhere more manageable. I understand the impulse. I have watched it play out at every scale. But CE v3.3 closes the ambiguities that made that line defensible. An</description><pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate><category>cyber-essentials</category><category>scope-management</category><category>uk-smb</category><category>compliance-behaviour</category><category>ncsc</category><category>cloud-security</category><category>director-liability</category><author>Mauven MacLeod</author></item><item><title>Russian Hackers Are Silently Reading Your WhatsApp Messages Right Now</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/signal-whatsapp-account-hijacking-russia-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/signal-whatsapp-account-hijacking-russia-uk-smb-2026/</guid><description>Hello, Mauven here. Yesterday, Dutch military and domestic intelligence confirmed what European security agencies have been circling for weeks: Russian state-sponsored hackers are running a large-scale global campaign to take over Signal and WhatsApp accounts. Not by breaking the encryption. By asking for the keys. Two governments have now issued formal warnings. Dutch officials have confirmed their own employees are among the victims. And the attack method is devastatingly simple. If your busin</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate><category>social-engineering</category><category>nation-state-attacks</category><category>whatsapp-security</category><category>signal-security</category><category>account-hijacking</category><category>smb-security</category><category>uk-business</category><author>Mauven MacLeod</author></item><item><title>The ICO Called It a &quot;Significant Victory&quot;. Try Telling That to 14 Million People Who Got Nothing.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ico-currys-dsg-victory-victims-got-nothing-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ico-currys-dsg-victory-victims-got-nothing-uk-2026/</guid><description>The ICO&apos;s General Counsel called the Currys Court of Appeal ruling &quot;a significant victory.&quot; And in strict legal terms, she is right. Lord Justice Warby&apos;s judgment closes a dangerous loophole and clarifies that personal data must be assessed from the controller&apos;s perspective. But while the lawyers celebrate, roughly 14 million people are sitting with expired limitation periods and no compensation route. The legal system confirmed DSG was in the wrong at the precise moment most victims could no lo</description><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate><category>ico-enforcement</category><category>dsg-retail-breach</category><category>data-breach-victims</category><category>uk-data-protection</category><category>compliance-failure</category><category>2026-threats</category><category>uk-business</category><author>Mauven MacLeod</author></item><item><title>Your Cloud Stack Is Not Just Stationery: The Bet Your Business Made Without Realising It</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/your-cloud-stack-is-not-just-stationery-the-bet-your-business-made-without-realising-it/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/your-cloud-stack-is-not-just-stationery-the-bet-your-business-made-without-realising-it/</guid><description>You did not set out to build US-centric infrastructure. You just bought what was on page one of Google. Email, documents, calendars, chat, CRM, help desk, backups, monitoring: all US-owned, all subject to US law, all chosen on price and convenience without a single conversation about jurisdictional risk. Mauven MacLeod explains why your 30-person firm has made exactly the same strategic bet as the NHS and the Ministry of Defence, why &quot;it is just stationery&quot; stopped being true about five years ag</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate><category>smb-security</category><category>vendor-risk</category><category>uk-business</category><category>cloud-security</category><category>data-sovereignty</category><category>2026-threats</category><category>business-risk</category><author>Mauven MacLeod</author></item><item><title>Four Game-Changing Cyber Stories in One Episode</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/four-game-changing-cyber-stories-one-episode/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/four-game-changing-cyber-stories-one-episode/</guid><description>The acting head of America&apos;s cybersecurity agency just uploaded government secrets to ChatGPT. Meanwhile, a Dublin IT manager discovered £18,000 worth of unused incident response services sitting in his cyber insurance policy. Passkeys can eliminate phishing attacks completely. And those viral Trump cloud cartoons? They&apos;re exposing the infrastructure dependency crisis threatening UK businesses. Four critical cybersecurity stories. Three expert guests. 45 minutes that could transform how your bus</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate><category>passkeys-authentication</category><category>cisa-breach</category><category>cyber-insurance-discovery</category><category>cloud-sovereignty</category><category>government-security-failure</category><category>authentication-security</category><category>insurance-services</category><author>Mauven MacLeod</author></item><item><title>US Cloud Sovereignty Isn&apos;t a Trump Problem, It&apos;s a Three-Company Problem: Why UK SMBs Need to Understand Infrastructure Dependency</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/us-cloud-sovereignty-infrastructure-dependency-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/us-cloud-sovereignty-infrastructure-dependency-uk-smb-2026/</guid><description>You&apos;ve seen the memes. Trump is controlling cloud providers like puppets. Trump is literally unplugging Europe from US infrastructure. They&apos;re viral because they touch a nerve about something real: UK businesses run on American infrastructure controlled by American laws. But the political framing misses the actual problem. This isn&apos;t about any particular president or administration. This is about 15 years of infrastructure consolidation, creating structural dependency that predates and will outl</description><pubDate>Sat, 31 Jan 2026 00:00:00 GMT</pubDate><category>cloud-security</category><category>data-sovereignty</category><category>gdpr-compliance</category><category>vendor-risk</category><category>infrastructure-dependency</category><category>us-cloud-act</category><category>smb-security-reality</category><author>Mauven MacLeod</author></item><item><title>Fortinet&apos;s Security Crisis: Why Does Nobody Care That Your VPN Is a Nation-State Playground?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/fortinet-security-failures-vpn-breaches-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/fortinet-security-failures-vpn-breaches-uk-2026/</guid><description>Here&apos;s a question that should keep every director awake: what happens when the device meant to protect your network becomes the primary way attackers get in? Between 2023 and now, Fortinet&apos;s SSL VPN has been exploited three separate times using the same type of vulnerability. Chinese intelligence services stole configurations from 20,000 organizations worldwide. Cyber insurers charge double the premiums for businesses using Fortinet kit. Yet Fortinet posted 50% revenue growth and continues to do</description><pubDate>Fri, 23 Jan 2026 00:00:00 GMT</pubDate><category>fortinet-vulnerabilities</category><category>vpn-security</category><category>nation-state-attacks</category><category>cyber-insurance</category><category>director-liability</category><category>technical-debt</category><category>vendor-accountability</category><author>Mauven MacLeod</author></item><item><title>The Psychology of Risk Denial: Why Smart People Convince Themselves They&apos;re Too Small to Matter</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-cyber-risk-denial-why-boards-ignore-breach-statistics/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-cyber-risk-denial-why-boards-ignore-breach-statistics/</guid><description>Why do intelligent board members hear &quot;43% of UK businesses got breached&quot; and think &quot;that won&apos;t happen to us&quot;? It&apos;s not stupidity; it&apos;s psychology. Optimism bias makes us believe bad things happen to others. Present bias makes tomorrow&apos;s disaster less urgent than today&apos;s deadline. Availability heuristic makes personal experience trump statistics. Illusion of control makes certificates feel like protection. Normalcy bias treats &quot;it hasn&apos;t happened yet&quot; as evidence. Dunning-Kruger creates confiden</description><pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>Why Smart People Keep Ignoring Smart Device Security: The Psychology Behind IoT Blindness</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cognitive-bias-destroying-uk-business-security-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cognitive-bias-destroying-uk-business-security-2025/</guid><description>After this week&apos;s podcast revelation about the marketing agency losing client files through an unsecured printer, my inbox has been full of variations on the same question: how do intelligent business owners with otherwise solid security miss something this obvious? The answer isn&apos;t comfortable, but it&apos;s important: IoT security failures aren&apos;t about lack of intelligence. They&apos;re about systematic psychological blind spots that affect everyone from small business owners to government departments. </description><pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate><category>iot-security</category><author>Mauven MacLeod</author></item><item><title>The Psychology of Security Failures: Why Smart People Keep Making the Same Stupid Mistakes</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-cybersecurity-failures-organisational-learning-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-cybersecurity-failures-organisational-learning-2025/</guid><description>Noel spent Monday and Tuesday explaining what reverse benchmarking is and how to implement it technically. Both excellent. Both necessary. Both completely inadequate if you don&apos;t understand why organizations systematically fail to learn from disasters. Here&apos;s the uncomfortable truth: most breaches happen not because organisations don&apos;t know what to do, but because human psychology actively prevents them from doing it. Normalcy bias makes us believe disasters happen to others. Optimism bias creat</description><pubDate>Wed, 03 Dec 2025 00:00:00 GMT</pubDate><category>security-psychology</category><category>organisational-behaviour</category><category>blame-culture</category><category>security-awareness</category><category>human-factors</category><category>decision-making</category><category>uk-cybersecurity</category><author>Mauven MacLeod</author></item><item><title>Why Personal Accountability Changes Everything: The Psychology of Director Liability</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-director-liability-cybersecurity-accountability-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-director-liability-cybersecurity-accountability-2025/</guid><description>After two days discussing frameworks and technical standards, let&apos;s examine why personal accountability actually works when corporate fines consistently fail. The psychology is fascinating and explains decades of regulatory success and failure. When British Airways faced a £20 million fine, nobody lost their job. When HSE prosecutes directors, workplace safety transforms overnight. The difference isn&apos;t the amount of money. It&apos;s whose money gets spent and whose freedom gets threatened. Human psyc</description><pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>The Psychology of Cybersecurity Negligence: Why Smart People Make Fatal Decisions</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-cyber-negligence-synnovis/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-cyber-negligence-synnovis/</guid><description>Nobody wakes up and decides to let patients die through cybersecurity negligence. Yet that is precisely what happened at Synnovis. The executives who failed to enable multi-factor authentication were not cartoon villains. They were educated professionals running a critical healthcare organisation. So why did they make a decision that, in hindsight, seems obviously catastrophic? The answer lies in the psychological mechanisms that allow intelligent people to rationalise terrible choices, the orga</description><pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate><category>cybersecurity psychology</category><category>decision-making bias</category><category>risk perception</category><category>corporate negligence</category><category>executive accountability</category><category>organisational behaviour</category><category>security culture</category><category>Synnovis analysis</category><category>systemic failure</category><author>Mauven MacLeod</author></item><item><title>Ofcom&apos;s Secret VPN Surveillance: When Britain Embraced the Authoritarian Playbook</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ofcom-vpn-surveillance-online-safety-act/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ofcom-vpn-surveillance-online-safety-act/</guid><description>Ofcom admits it is monitoring VPN use across Britain with a secret AI tool and unnamed data sources. That should worry any small business that relies on encrypted links for daily work. The tool cannot tell a secure office connection from someone dodging age checks. Section 121 still sits in law, ready to force scanning of encrypted chats. Does that sound like a free internet to you? Document your use. Keep your controls tight. Ask your MP why this is acceptable. Do you want regulators watching y</description><pubDate>Tue, 11 Nov 2025 00:00:00 GMT</pubDate><category>Ofcom</category><category>Online Safety Act</category><category>Section 121</category><category>VPN Monitoring</category><category>Big Brother</category><category>Orwellian</category><category>VPN Surveillance</category><author>Mauven MacLeod</author></item><item><title>The Nottingham Agency That Spent £47,000 on Cloud Bills They Didn&apos;t Need</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/nottingham-agency-cloud-cost-disaster-recovery-case-study-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/nottingham-agency-cloud-cost-disaster-recovery-case-study-2025/</guid><description>Twenty-three employees. Eighteen months. Forty-seven thousand pounds wasted on cloud infrastructure they didn&apos;t need, SaaS subscriptions nobody used, and auto-scaling rules designed by a consultant who&apos;d never checked back. This isn&apos;t a horror story about a massive enterprise with unlimited budget. This is CloudBridge Digital, a Nottingham digital agency that discovered they&apos;d been hemorrhaging cash while Microsoft, AWS, and a parade of SaaS vendors quietly helped themselves to the company bank </description><pubDate>Fri, 07 Nov 2025 00:00:00 GMT</pubDate><category>cloud-cost-case-study</category><category>uk-smb-failure</category><category>nottingham-business</category><category>cloud-waste</category><category>cost-recovery</category><category>aws-costs</category><category>saas-spending</category><category>finalspark</category><category>business-lessons</category><category>smb-cloud-strategy</category><author>Mauven MacLeod</author></item><item><title>When the Panic Becomes Obvious</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/microsoft-three-mile-island-nuclear-ai-data-centres-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/microsoft-three-mile-island-nuclear-ai-data-centres-2025/</guid><description>Three Mile Island. You remember it, right? The 1979 nuclear accident that terrified an entire generation and effectively killed nuclear power plant construction in America for 40 years? Microsoft just spent $1.6 billion to restart Unit 1. Not for clean energy virtue signaling. Because they&apos;re bloody desperate. Google committed to 500 megawatts of Small Modular Reactors. Amazon&apos;s all-in on multiple nuclear projects. Meta wants up to 4 gigawatts. Billions in nuclear investment. Timeline: 2028 to 2</description><pubDate>Wed, 05 Nov 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>The British Library&apos;s £7 Million MFA Decision</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/british-library-ransomware-mfa-failure-doorman-fallacy-mauvens-take/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/british-library-ransomware-mfa-failure-doorman-fallacy-mauvens-take/</guid><description>The British Library decided not to implement MFA on administrator accounts. Their reasoning: &quot;practicality, cost and impact on ongoing programmes.&quot; That decision cost them £7 million in recovery, 600GB of staff data dumped on the dark web, and over a year of service disruption. This is Mauven&apos;s Take on one of the clearest examples of the doorman fallacy in UK history. When cost-cutting decisions focus narrowly on immediate expense whilst ignoring catastrophic downside risk, you get exactly this </description><pubDate>Wed, 29 Oct 2025 00:00:00 GMT</pubDate><category>cost-cutting-failures</category><category>security-training</category><category>mfa-removal</category><category>cyber-insurance</category><category>it-staff</category><category>business-risk</category><category>smb-security</category><category>uk-business</category><category>doorman-fallacy</category><category>episode-24</category><category>vendor-relationships</category><category>efficency-theatre</category><category>british-library</category><category>ransomware-attack</category><category>mfa-failure</category><category>rhysida-ransomware</category><category>public-sector-security</category><category>ico-enforcement</category><category>ncsc-guidance</category><author>Mauven MacLeod</author></item><item><title>When DNS Goes Down, Civilisation&apos;s Collapse Plays Out in Your Suburban Flat</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/aws-dns-outage-october-2025-smart-homes-dumb-boxes/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/aws-dns-outage-october-2025-smart-homes-dumb-boxes/</guid><description>All right folks, buckle in. Last Monday, the planet just got schooled yet again in why we&apos;ve put all our digital eggs in one totally cracked basket. AWS US-EAST-1 region had a DNS hiccup and half the world&apos;s internet decided it was nap time. Snapchat, Venmo, even the app that tells you if your cat&apos;s used the loo, all snuffed out. Why does a digital sneeze in Virginia take out customer payments in Edinburgh? And here&apos;s the kicker: this is the third major outage in five years for the same bloody r</description><pubDate>Sun, 26 Oct 2025 00:00:00 GMT</pubDate><category>aws-outage</category><category>dns-failure</category><category>smart-home-security</category><category>cloud-dependency</category><category>us-east-1</category><category>single-point-failure</category><category>business-continuity</category><author>Mauven MacLeod</author></item><item><title>Another UK SME Wastes £20k on &apos;Comprehensive CyberSec&apos;: Still Gets Breached</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-sme-cybersec-waste-breach-birmingham-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-sme-cybersec-waste-breach-birmingham-2025/</guid><description>Security vendors are playing you for fools, and they&apos;re getting rich doing it. Every week I watch UK business owners waste £20,000 on &quot;comprehensive cybersecurity platforms&quot; when they needed £5,000 of basic IT security. The industry deliberately muddies the difference between InfoSec, CyberSec, and IT Security because confused customers pay premium prices for inappropriate solutions. Meanwhile, 50% of small businesses were breached in 2025, proving that expensive confusion doesn&apos;t equal protecti</description><pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate><category>podcast</category><category>infosec</category><category>cybersec</category><category>it-security</category><category>uk-smb-authentication</category><category>fido2</category><category>hardware-security-keys</category><category>authentrend</category><category>phishing-resistant-mfa</category><category>cyber-essentials</category><category>ncsc</category><category>secuity-budget</category><category>vendor-confusion</category><category>it-security-fundamentals</category><category>Multi-factor-authentication</category><category>uk-business-security</category><category>small-business-cybersecurity</category><category>episode-launch</category><author>Mauven MacLeod</author></item><item><title>The MFA Reality Check - Why Only 30% of Schools Have It Properly Enabled</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/school-multi-factor-authentication-enabled/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/school-multi-factor-authentication-enabled/</guid><description>Only 30% of schools have Multi-Factor Authentication enabled, but the reality is worse than that statistic suggests. Many schools have &quot;partial MFA&quot; - enabled for head teachers and SENCOs but not teaching assistants or admin staff. From a security perspective, everyone with access needs MFA, or you&apos;re not protected. The challenge? Phone-based authenticator apps conflict with safeguarding policies that ban phones near children. Hardware security keys offer the solution. FIDO2-certified tokens fro</description><pubDate>Wed, 15 Oct 2025 00:00:00 GMT</pubDate><category>MFA</category><category>multi factor authentication UK</category><category>Hardware Tokens</category><category>Fido2</category><category>Security Keys</category><category>Biometrics</category><category>authentrend</category><author>Mauven MacLeod</author></item><item><title>When Six Ministers Co-Sign a Letter to Your CEO, It&apos;s Time to Listen</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-ministers-ncsc-cyber-security-warning-2025-business-leaders/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-ministers-ncsc-cyber-security-warning-2025-business-leaders/</guid><description>When the Chancellor, three Cabinet Ministers, the NCSC CEO, and the Director General of the National Crime Agency personally co-sign a letter to UK business leaders, you don&apos;t ignore it. The NCSC just reported 204 nationally significant cyber incidents, with 18 highly significant attacks marking a 50% increase for the third consecutive year. Marks &amp; Spencer lost over £300 million. A healthcare attack contributed to a patient death. Empty shelves appeared in supermarkets. The government has g</description><pubDate>Tue, 14 Oct 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>Confessions of a Reformed School Hacker: How Getting Caught Changed My Career</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/the-geography-teachers-fatal-mistake/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/the-geography-teachers-fatal-mistake/</guid><description>Curiosity, access, and a careless password shaped my career. At sixteen I learned the simplest attack works best. I watched a teacher type admin123! and saw the whole network open up. No exploits. Just human nature. That is the insider threat in plain sight. People bypass clumsy controls to get work done. Do your policies help or hinder? Make secure the easy path with least privilege, SSO, MFA, logging, and coaching. Treat incidents as data, not drama. Channel curiosity before it goes undergroun</description><pubDate>Wed, 01 Oct 2025 00:00:00 GMT</pubDate><category>insider threats uk</category><category>shoulder surfing password</category><category>human centred security</category><category>least privilege mfa</category><category>student hackers schools</category><author>Mauven MacLeod</author></item><item><title>The DORA Reckoning: How September&apos;s Cyberattacks Just Triggered Europe&apos;s First Cross-Border Regulatory Crisis</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/dora-compliance-crisis-collins-aerospace-jlr-cyberattacks/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/dora-compliance-crisis-collins-aerospace-jlr-cyberattacks/</guid><description>September 2025&apos;s Collins Aerospace and JLR cyberattacks weren&apos;t just operational disasters - they triggered Europe&apos;s first cross-border regulatory crisis under DORA. While aviation experts focused on flight delays, they missed the real story: EU authorities now have direct oversight powers over US companies like Collins Aerospace serving European financial infrastructure. DORA&apos;s January 2025 implementation created unprecedented cross-border enforcement mechanisms that most businesses don&apos;t under</description><pubDate>Wed, 24 Sep 2025 00:00:00 GMT</pubDate><category>DORA Regulation</category><category>cybersecurity compliance</category><category>digital operational resilience</category><category>EU financial regulation</category><category>Collins Aerospace</category><category>critical infrastructure</category><author>Mauven MacLeod</author></item><item><title>Analyzing the Patterns: When Single IT Manager Models Fail Spectacularly</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/it-horror-stories-single-manager-model-failures/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/it-horror-stories-single-manager-model-failures/</guid><description>Let&apos;s examine the data: 30 years of single IT manager failures. The patterns are consistent, the outcomes predictable, and the business impact devastating. Here&apos;s what happens when your &quot;Dave from IT&quot; model reaches its inevitable breaking point.</description><pubDate>Wed, 24 Sep 2025 00:00:00 GMT</pubDate><category>Dave From IT</category><category>Risk Management</category><category>Business Continuity</category><author>Mauven MacLeod</author></item><item><title>Five Questions That Reveal Your Business Needs Strategic IT Leadership (And It&apos;s Not What You Think)</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/five-questions-strategic-it-leadership-assessment-uk-smb-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/five-questions-strategic-it-leadership-assessment-uk-smb-2025/</guid><description>Most UK businesses think they&apos;re fine without strategic IT leadership until they&apos;re not. These five diagnostic questions expose the difference between thriving with technology and merely surviving despite it. Question 1: Are technology decisions made strategically or reactively? If you&apos;re replacing servers because they died rather than planned refresh cycles, you need help. Question 5: Will current systems scale gracefully as you grow? Planning to double in size without considering technology im</description><pubDate>Wed, 17 Sep 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>Why Small Businesses Must Rethink Cybersecurity NOW (Before It’s Too Late)</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/why-small-businesses-must-rethink-cybersecurity-uk-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/why-small-businesses-must-rethink-cybersecurity-uk-2025/</guid><description>Cybersecurity is not just an enterprise problem. With 96% of attacks targeting small businesses and 60% of victims closing within six months, UK SMEs face a survival crisis. This article exposes the myths keeping businesses vulnerable, the real financial impact of attacks, and the role of supply chain risk. It explains why Cyber Essentials and board-level governance are no longer optional, but essential. Written for directors and leaders, it lays out practical steps to protect your business befo</description><pubDate>Wed, 10 Sep 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>The Psychology of Cyber Essentials: Why Smart People Make Terrible Security Decisions</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-cyber-essentials-smart-people-terrible-security-decisions/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/psychology-cyber-essentials-smart-people-terrible-security-decisions/</guid><description>Hello, Mauven here. After Monday&apos;s podcast and yesterday&apos;s technical deep-dive, I want to tackle the elephant in the room: if Cyber Essentials is so brilliant, why do smart business owners avoid it like a tax audit? The answer isn&apos;t ignorance or stubbornness - it&apos;s human psychology. Our brains evolved to make quick survival decisions, not manage enterprise cybersecurity frameworks. We&apos;re fighting millions of years of evolution with documentation requirements and compliance deadlines. Understandi</description><pubDate>Wed, 30 Jul 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>The CVE-2025-53770 Crisis: Why Your SharePoint Response Reveals More About Human Psychology Than Technical Competence</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cve-2025-53770-sharepoint-crisis-psychology-security-response/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cve-2025-53770-sharepoint-crisis-psychology-security-response/</guid><description>After analyzing the global response to CVE-2025-53770, the critical SharePoint zero-day that&apos;s compromised 75+ organizations in 48 hours, I&apos;m convinced this isn&apos;t about technical competence. It&apos;s about human psychology. Right now, IT administrators who know their systems are vulnerable (CVSS 9.8) are doing nothing because of normalcy bias, sunk cost fallacy, and optimism bias. The organizations getting breached aren&apos;t those lacking knowledge - they&apos;re the ones whose psychology prevents acting on</description><pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>The Psychology of Technical Debt: Why Smart Teams Make Tomorrow&apos;s Security Problems</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/technical-debt-psychology-smart-teams-security-problems-july-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/technical-debt-psychology-smart-teams-security-problems-july-2025/</guid><description>After this week&apos;s podcast on technical debt and supply chain failures, I want to examine why intelligent, well-meaning IT teams consistently create tomorrow&apos;s security disasters. Technical debt isn&apos;t just a coding problem - it&apos;s a psychological trap that 78% of UK businesses fall into repeatedly. We take shortcuts under pressure, defer security updates for stability, and convince ourselves that &quot;temporary&quot; solutions won&apos;t become permanent vulnerabilities. Understanding the cognitive biases behin</description><pubDate>Wed, 16 Jul 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>Catwatchful Exposed: When Surveillance Technology Becomes a Weapon</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/catwatchful-stalkerware-exposed-ncsc-analysis-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/catwatchful-stalkerware-exposed-ncsc-analysis-2025/</guid><description>Former UK Government Cyber analyst Mauven MacLeod exposes the disturbing Catwatchful stalkerware operation that suffered a massive breach in June 2025, revealing 62,000 customer accounts and 26,000 monitored victims across seven countries. This isn&apos;t just cybersecurity failure - it&apos;s weaponised surveillance technology enabling domestic abuse and stalking. The breach exposed plaintext passwords, comprehensive victim data dating to 2018, and the operation&apos;s Uruguay-based administrator. From a government security </description><pubDate>Sun, 06 Jul 2025 00:00:00 GMT</pubDate><author>Mauven MacLeod</author></item><item><title>The Psychology of Password Chaos: Why Smart People Make Terrible Choices</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/password-psychology-smart-people-terrible-choices-june-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/password-psychology-smart-people-terrible-choices-june-2025/</guid><description>After Monday&apos;s podcast and yesterday&apos;s NCSC deep-dive, I want to tackle the elephant in the room: if three random words are so brilliant, why do smart business owners still use &quot;password123&quot;? Why does 78% password reuse persist despite constant breach warnings? The answer isn&apos;t technical ignorance - it&apos;s human psychology. We&apos;re fighting millions of years of evolution with spreadsheets and complexity requirements. Our brains aren&apos;t wired for digital security, they&apos;re wired for survival shortcuts.</description><pubDate>Thu, 26 Jun 2025 00:00:00 GMT</pubDate><category>password-psychology</category><category>human-behaviour</category><category>cybersecurity-psychology</category><category>mauven-macleod</category><category>behavioural-security</category><category>Password-Management</category><author>Mauven MacLeod</author></item><item><title>Middle East Conflict Escalation Creates Immediate Cyber Threats for UK Small Businesses</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-middle-east-threats-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-small-business-cybersecurity-middle-east-threats-2025/</guid><description>Last Friday, it was someone else&apos;s war. Over the weekend, Iranian hackers considered your Microsoft 365 account enemy infrastructure. American B-2 bombers dropped 14 bunker-busters on Iranian nuclear facilities over the weekend. The cyber retaliation has already begun, and UK small businesses as we all use US cloud services are the in the firing line primary targets. Remember NotPetya? Ukrainian attack, global devastation. Windows is Windows regardless of location. Your customer database could b</description><pubDate>Tue, 24 Jun 2025 00:00:00 GMT</pubDate><category>podcast-preview</category><category>Small Business Cyber Security</category><author>Mauven MacLeod</author></item></channel></rss>