The Small Business Cyber Security Guy

Threat Analysis : Cyber News for Small Business

Business EN ↓ 19 episodes

Threat Analysis is the daily cyber security briefing for people who are tired of corporate fog, vendor panic, and security theatre dressed up as strategy. Hosted by Mauven MacLeod, it cuts through the noise around cyber threats, ransomware, data breaches, regulation, supply chain risk, and the latest bright idea from people who think a dashboard is the same thing as resilience. Every weekday, Mauven looks at what happened, why it matters, who should be paying attention, and what small and medium sized businesses should do before the mess arrives with a press statement and a very expensive cons...

Author

The Small Business Cyber Security Guy

Category

Business

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors 10.07.2026

Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors This episode examines three current UK cyber security incidents that share a troubling characteristic: all were preventable. Mauven MacLeod analyses the seven-step ransomware chain exploiting unpatched Citrix NetScaler appliances (CVE-2025-5777), documented by Huntress across multiple UK organisations. The briefing covers...

RoguePlanet Zero-Day, Vidar Supply Chain Infiltration, and CE Plus Pathways 09.07.2026

RoguePlanet Zero-Day, Vidar Supply Chain Infiltration, and CE Plus Pathways A delayed patch for the RoguePlanet zero-day in Windows Defender has finally arrived, but working exploit code was publicly available for weeks before Microsoft closed the vulnerability. Mauven examines what that exposure window means for UK SMBs and why confirming patch deployment today is not optional. The Vidar infostea...

Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch 08.07.2026

Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch Ubiquiti has released security updates addressing seven critical vulnerabilities in UniFi OS, including one rated CVSS 10.0 that permits unauthenticated remote code execution. The widespread deployment of UniFi hardware in UK small business networks makes this a priority patching event. Separately, CISA has added an Adobe ColdFusion v...

Teams Impersonation, Multi-Stage Phishing, and the UK Cyber Pledge 07.07.2026

Teams Impersonation, Multi-Stage Phishing, and the UK Cyber Pledge This episode examines three active threat vectors affecting UK businesses in July 2026. First, a sophisticated Microsoft Teams impersonation campaign documented by Unit 42, in which attackers pose as IT helpdesk staff to deploy EtherRAT remote access trojans without requiring any technical vulnerability. Second, a global phishing o...

Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs 06.07.2026

Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs Today’s briefing covers two active threats facing UK small businesses. First, CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed to be under active exploitation by the Canadian Centre for Cyber Security and verified by BleepingComputer. The flaw permits unauthenticated remote code execution with a CVSS score...

Device Code Phishing, Avalon Ransomware, and the NetNut Botnet Takedown 03.07.2026

Device Code Phishing, Avalon Ransomware, and the NetNut Botnet Takedown This briefing examines three significant threats to UK small and medium businesses in July 2026. First, Cisco Talos’s analysis of ARToken, a phishing-as-a-service platform exploiting Microsoft 365 device code authentication flows to bypass multi-factor authentication. The technique, productised for affiliate use, requires imme...

Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat 01.07.2026

Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat The Gentlemen ransomware group has emerged as a top-ten global threat actor by deploying zero-day driver exploits to disable endpoint security tools before launching encryption attacks. Using a vulnerable Kontron driver and the Bring Your Own Vulnerable Driver technique, the group neutralises detection systems silently,...

Windows Defender Flaw Hits Commodity Ransomware; RMM Tools Under Attack 30.06.2026

Windows Defender Flaw Hits Commodity Ransomware; RMM Tools Under Attack Two critical threats demand immediate attention from UK small businesses today. First, the BlueHammer vulnerability in Microsoft Defender has transitioned from targeted zero-day attacks to commodity ransomware operations, a shift that dramatically expands the pool of threat actors capable of exploiting it. CISA’s addition of B...

Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild 29.06.2026

Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild Oracle E-Business Suite vulnerability CVE-2026-46817 is under active exploitation, with confirmed activity from threat intelligence firm Defused. Nissan’s recent breach of its Oracle PeopleSoft instance underscores the broader risk to Oracle’s enterprise portfolio. UK small businesses face exposure through supply chain relationship...

Understanding Mini Shai-Hulud and Cisco's Zero-Day Vulnerabilities 26.06.2026

Understanding Mini Shai-Hulud and Cisco’s Zero-Day Vulnerabilities In today’s episode of Threat Analysis, Mauven MacLeod delves into two significant cybersecurity threats impacting UK small and medium businesses. The Mini Shai-Hulud supply chain attack targets the development community by exploiting npm packages, risking developers’ credentials and threatening software integrity. Microsoft emphasi...

Emerging Cyber Threats to UK SMEs 25.06.2026

Emerging Cyber Threats to UK SMEs In this episode of Threat Analysis, Mauven MacLeod dives into two pressing cybersecurity threats affecting UK small and medium businesses. The first is the Mistic backdoor, linked to the notorious Woodgnat, which employs the cunning technique of sideloading. This method uses legitimate software to conceal malicious activity, posing significant risks such as data l...

Understanding the Mistic Backdoor Threat to UK SMBs 24.06.2026

Understanding the Mistic Backdoor Threat to UK SMBs In this episode of Threat Analysis, Mauven MacLeod explores the emerging threat landscape for UK small and medium businesses, focusing on the Mistic backdoor. This malware, linked to the ransomware access broker KongTuke, poses significant risks to crucial sectors such as insurance, education, IT, and professional services. The discussion highlig...

Klue Supply Chain Breach and AI Cybersecurity Warnings 23.06.2026

Klue Supply Chain Breach and AI Cybersecurity Warnings In this episode of Threat Analysis, Mauven MacLeod explores a pressing supply chain attack that targets Salesforce environments through Klue’s backend systems. The breach, executed by the Icarus threat group, highlights the vulnerabilities of OAuth tokens and the implications for UK small businesses. Mauven discusses the importance of reviewin...

Key Cyber Threats Impacting UK Businesses 22.06.2026

Key Cyber Threats Impacting UK Businesses Join Mauven MacLeod for today’s Threat Analysis, a briefing focused on the latest cyber threats facing UK businesses. The episode covers the sophisticated attack on 3CXDesktopApp, which exploits supply chain vulnerabilities through trojanised installers. We also delve into the FortiBleed campaign, highlighting the increased risk posed by attacks on Fortine...

Active Splunk Exploit and npm Supply Chain Campaign 19.06.2026

Active Splunk Exploit and npm Supply Chain Campaign CISA has confirmed active exploitation of a critical Splunk Enterprise vulnerability, with a patch deadline of 22 June 2026 for US federal agencies. UK organisations face the same threat but lack a legal mandate. Separately, over 140 npm packages in the mastra ecosystem were compromised through account takeover, pushing typosquatted dependencies...

DragonForce Hides in Teams, Joomla at Maximum Severity, and RoguePlanet Waits for a Patch 17.06.2026

DragonForce Hides in Teams, Joomla at Maximum Severity, and RoguePlanet Waits for a Patch Three active threats demand immediate attention from UK small and medium businesses. Symantec researchers have documented DragonForce ransomware concealing command-and-control infrastructure inside Microsoft Teams relay servers using a custom backdoor that exploits anonymous visitor tokens. The intrusion evad...

DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites 16.06.2026

DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites Three critical threats demand immediate attention from UK small businesses today. DragonForce ransomware has deployed a custom backdoor that tunnels command-and-control traffic through Microsoft Teams relay infrastructure, exploiting implicit trust in cloud services. Multiple critical vulnerabilities in Fortinet’...

One-Click Data Theft via M365 Copilot and Active Cisco SD-WAN Exploitation 16.06.2026

One-Click Data Theft via M365 Copilot and Active Cisco SD-WAN Exploitation Two critical vulnerabilities demand immediate attention from UK businesses today. Researchers have disclosed SearchLeak, a prompt injection vulnerability chain in Microsoft 365 Copilot Enterprise that allows attackers to steal data from mailboxes, OneDrive, and SharePoint with a single malicious link. The attack exploits Co...

AI Phishing, Clinical Data Theft, and the CC Field Mistake 13.06.2026

AI Phishing, Clinical Data Theft, and the CC Field Mistake Mauven MacLeod examines three incidents that illustrate how UK businesses are actually compromised in 2026. Google has sued a Chinese phishing operation selling AI-generated SMS fraud toolkits via Telegram, producing messages now indistinguishable from legitimate communications. Novo Nordisk disclosed that attackers accessed pseudonymised...

Listen to the Threat Analysis : Cyber News for Small Business podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.