Mauven MacLeod presents today’s Threat Analysis, focusing on pressing cyber threats faced by UK small and medium businesses. She explores two major issues: vishing attacks exploiting Microsoft Teams and vulnerabilities in WordPress. Vishing attacks target companies through Microsoft Teams, where attackers impersonate IT helpdesk staff and deploy the GoGRPC backdoor. This can lead to ransomware attacks, compromising sensitive company data. Mauven emphasises the importance of staff awareness and technological safeguards to mitigate risks. The episode also highlights critical vulnerabilities in WordPress Core, affecting versions 6.9.0 to 7.0.1. These vulnerabilities allow unauthorised remote code execution, potentially leading to total site takeovers. Businesses are urged to apply patches immediately to protect their websites and customer data. The National Cyber Security Centre underlines the urgency of this action. Mauven stresses that these insights should lead to a comprehensive cybersecurity strategy, incorporating regular updates, employee training, and robust security policies.