73,000 Fortinet VPN credentials leaked, Evil Corp's botnet dismantled, and WordPress plugin supply chain compromised again. Three stories that matter to UK small businesses today.
Three active threats UK SMBs cannot ignore today: ransomware hiding in Microsoft's own infrastructure, a Joomla CMS exploit already in the wild, and an unpatched Defender zero-day.
CISA confirmed active exploitation of a Joomla plugin flaw on Tuesday. Microsoft has no patch for its Defender zero-day. Two fires, one week. Here is what to do.
Two critical vulnerabilities confirmed in active exploitation this week. If you run Joomla or use any web application with token-based login, read this now.
DragonForce is hiding ransomware command traffic inside Microsoft Teams. Fortinet FortiSandbox has critical flaws being actively exploited. Here is what UK SMBs need to know today.
Three stories from the last 24 hours that should matter to every small business in the UK. Two are actively exploited. One was patched three weeks after it was found.
Microsoft 365 Copilot has a critical vulnerability chain that lets an attacker steal your mailbox data with a single crafted URL. Cisco SD-WAN is under active exploitation. Both matter to UK SMBs right now.
A high-volume ransomware operation with Russian-speaking roots and an AI-powered phishing platform impersonating trusted brands. Both are active today.
No credentials required. A WordPress plugin flaw published yesterday lets unauthenticated attackers create admin accounts. Here is what to do before lunch.
Microsoft's biggest-ever Patch Tuesday, a critical Veeam backup flaw, and a WordPress plugin that hands attackers your server. Three stories. One to-do list.
Two active campaigns are hitting organisations that look exactly like UK SMBs. One calls your staff pretending to be IT support. The other fakes LinkedIn and Indeed.