In today’s episode of Threat Analysis, Mauven MacLeod explores two significant cyber threats impacting UK small and medium-sized businesses: the Mistic backdoor and the FortiBleed campaign. Both threats exploit vulnerabilities requiring immediate attention. The Mistic backdoor, potentially operated by the notorious access broker Woodgnat, uses sideloading attacks to infiltrate systems. This method often goes unnoticed and has been a staple in cybercriminal activities for years, affecting industries like professional services and healthcare. Mauven emphasises the importance of meaningful conversations with IT teams to mitigate such risks and secure vendor relationships effectively. The episode then shifts focus to the FortiBleed campaign, which targets Fortinet’s FortiGate firewalls. These essential components of network security are under significant threat as FortiBleed employs an immediate credential theft strategy. This can escalate from potential risk to an operational crisis rapidly. Mauven advises businesses to apply necessary patches promptly and enhance network monitoring protocols to detect unusual activities. Both threats underscore the necessity for proactive cybersecurity measures.