Podcast thumbnail for The 10 Minute Cyber Fix

The 10 Minute Cyber Fix

Claim This Podcast

by The Small Business Cyber Security Guy Productions

16 episodes
Updated Daily
Accepts GuestsHas SponsorsLocation 🇬🇧

Podcast Overview

Your daily cybersecurity briefing for UK small businesses and tech enthusiasts. Every weekday morning, cybersecurity consultant Lucy Harper delivers the cyber intelligence you need to protect your business in just ten minutes. No jargon, no fear-mongering, just practical advice about current threats targeting UK SMEs. From ransomware attacks hitting local businesses to new phishing campaigns, each episode explains what's happening, why it matters, and exactly what you can do about it. Perfect for your morning commute or coffee break. Every M-F Listen Notes

Language

🇺🇲

Publishing Since

8/4/2025

1 verified contact email on file for The 10 Minute Cyber Fix

Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.

Recent Episodes

Episode thumbnail for Your Business Dies When Your Internet Provider Gets Hacked: The 13-Day COLT Nightmare

August 26, 2025

Your Business Dies When Your Internet Provider Gets Hacked: The 13-Day COLT Nightmare

<p><strong>Episode Summary</strong></p><p>COLT Technology Services, a major UK telecommunications provider, suffers from ongoing ransomware attacks, causing week-long outages affecting thousands of businesses. Host Lucy Harper breaks down the SharePoint vulnerability exploitation and provides emergency supplier risk protection strategies for UK SMEs.</p><p><strong>What You&#39;ll Learn</strong></p><ul><li>How WarLock ransomware compromised COLT using Microsoft SharePoint zero-day CVE-2025-53770</li><li>Why the &#39;ToolShell&#39; exploit chain bypasses all authentication and enables remote code execution</li><li>Real business impact: multi-day connectivity outages affecting customer portals, voice systems, and network management</li><li>Emergency supplier risk assessment and redundant connectivity implementation strategies</li><li>Chinese threat group coordination targeting telecommunications infrastructure across multiple countries</li></ul><p><br></p><p><strong>Critical Statistics Mentioned</strong></p><ul><li><strong>1 million documents</strong> allegedly stolen from COLT, offered for £147,500 ransom</li><li><strong>30 countries</strong> where COLT operates critical telecommunications infrastructure</li><li><strong>900 data centres</strong> connected by COLT&#39;s 75,000km fibre network</li><li><strong>8+ days</strong> of ongoing service disruptions affecting UK business operations</li><li><strong>424 vulnerable SharePoint servers</strong> still exposed globally according to Shadowserver Foundation</li><li><strong>9,665 SharePoint devices</strong> exposed to internet as of August 2025</li><li><strong>CVSS 9.8</strong> critical severity rating for CVE-2025-53770 SharePoint vulnerability</li><li><strong>3 Chinese APT groups</strong> confirmed exploiting same SharePoint vulnerabilities for ransomware and espionage</li></ul><p><br></p><p><strong>Key Sources &amp; References</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/colt-telecom-attack-claimed-by-warlock-ransomware-data-up-for-sale/">BleepingComputer: COLT WarLock ransomware attack confirmation and data theft claims</a></li><li><a href="https://www.theregister.com/2025/08/15/london_telco_colts_services_disrupted/">The Register: Technical timeline and service disruption details</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/">Microsoft Security Blog: CVE-2025-53770 vulnerability analysis and threat actor attribution</a></li><li><a href="https://www.cisa.gov/news-events/alerts/2025/07/20/update-microsoft-releases-guidance-exploitation-sharepoint-vulnerabilities/">CISA Alert: Government response and mitigation guidance for SharePoint vulnerabilities</a></li><li><a href="https://www.computerweekly.com/news/366629219/Warlock-claims-ransomware-attack-on-network-services-firm-Colt">Computer Weekly: UK business impact analysis and expert commentary</a></li><li><a href="https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/">Palo Alto Unit 42: ToolShell exploit chain technical analysis</a></li><li><a href="https://blog.checkpoint.com/research/sharepoint-zero-day-cve-2025-53770-actively-exploited-what-security-teams-need-to-know/">Check Point Research: Exploitation campaign timeline and affected sectors</a></li><li><a href="https://socradar.io/toolshell-sharepoint-zero-day-cve-2025-53770/">SOCRadar: Global threat intelligence and vulnerable server identification</a></li></ul><p><br></p><p><strong>Episode Sponsor</strong></p><p>Equate Group - Comprehensive cybersecurity and IT services specialising in network resilience planning, business continuity management, and supplier risk assessment. </p><p>Visit <a href="https://www.equategroup.com" target="_blank" rel="noopener noreferer">www.equategroup.com</a> </p><p><br></p><p><strong>Your Next Steps</strong></p><p><u><strong>URGENT ACTION REQUIRED: </strong></u></p><ul><li>Audit all critical IT suppliers immediately to identify single points of failure. </li><li>Implement redundant connectivity and verify SharePoint patch status if using on-premises systems. </li><li>Seek professional help for comprehensive supplier risk assessment and business continuity planning.</li></ul><p><strong>Source Verification Standards</strong></p><p>All sources cited in this episode have been fact-checked and verified through multiple authoritative channels. </p><p>Microsoft Security Blog serves as the primary source for technical details on vulnerabilities.</p><p> Financial figures are cross-referenced through cybersecurity threat intelligence platforms. UK-specific impact data prioritises telecommunications industry publications and government cybersecurity guidance.</p><p><strong>Disclaimer</strong></p><p>This episode provides general guidance only. Always consult qualified cybersecurity professionals before making critical infrastructure changes. Content is based on independent research and industry best practices.</p><p>🎧 Subscribe for daily cybersecurity updates</p><p>👍 Like this episode if it helped you prepare</p><p><br></p><p><strong>Production: </strong> Small Business Cyber Security Guy Production</p><p><strong>Host:</strong> Lucy Harper</p><p>All rights reserved</p>

Episode thumbnail for When AI Turns Against You

August 22, 2025

When AI Turns Against You

<p><strong>Episode Summary</strong></p><p>AI-powered cybercriminals are now targeting UK small businesses with unprecedented sophistication, making artificial intelligence threats the top security concern for 35% of SMEs in 2025. Host Lucy Harper breaks down how criminals weaponise machine learning against businesses and provides a five-step action plan to defend against deepfakes, AI-generated phishing, and automated attacks that traditional security cannot detect.</p><p><strong>What You'll Learn</strong></p><p><strong>AI-Powered Cyber Attacks:</strong> How criminals use machine learning to create personalised, sophisticated attacks that bypass traditional security measures and target UK SMEs specifically.</p><p><strong>Technical Threat Landscape:</strong> The mechanics behind AI-generated phishing, deepfake technology, and automated attack systems that can launch thousands of customised attacks simultaneously.</p><p><strong>Business Impact Assessment:</strong> Why AI cybercrime contributes to the 27 billion pounds annual cost to the UK economy and how skills shortages leave SMEs vulnerable to advanced threats.</p><p><strong>Practical Defence Strategy:</strong> Five immediate actions including AI-aware email security, enhanced verification protocols, and employee training specifically designed for AI threat recognition.</p><p><strong>Regulatory Compliance Preparation:</strong> New UK AI Cyber Security Code requirements, upcoming Cyber Security and Resilience Bill implications, and GDPR changes affecting AI-powered data processing.</p><p>Key Sources &amp; References</p><p><a href="https://securitybrief.co.uk/story/ai-threats-top-concern-for-uk-smes-cybersecurity-in-2025" rel="ugc noopener noreferrer" target="_blank">Six Degrees Research Study</a>: "Mapping the UK SME Cyber Security Landscape in 2025" </p><p><a href="https://www.gov.uk/government/publications/ai-cyber-security-code-of-practice" rel="ugc noopener noreferrer" target="_blank">UK Government DSIT &amp; NCSC</a>: AI Cyber Security Code of Practice published January 31, 2025</p><p><a href="https://defcon.org/" rel="ugc noopener noreferrer" target="_blank">DefCon 33 Official Information</a>: Premier cybersecurity conference featuring DARPA AI Cyber Challenge and emerging threat research</p><p><a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025" rel="ugc noopener noreferrer" target="_blank">UK Cyber Security Breaches Survey 2025</a>: Government analysis of cybersecurity threat landscape and business impacts</p><p><a href="https://www.nist.gov/news-events/news/2024/01/nist-identifies-types-cyberattacks-manipulate-behavior-ai-systems" rel="ugc noopener noreferrer" target="_blank">NIST AI Security Framework</a>: Technical standards for identifying and defending against AI-powered cyber attacks</p><p><a href="https://www.weforum.org/stories/2025/02/deepfake-ai-cybercrime-arup/" rel="ugc noopener noreferrer" target="_blank">World Economic Forum Case Study</a>: Analysis of 25 million dollar deepfake attack demonstrating advanced AI threat capabilities</p><p><strong>Episode Sponsor</strong></p><p><strong>Equate Group</strong>. Visit <a href="https://equategroup.com" rel="ugc noopener noreferrer" target="_blank">equategroup.com</a></p><p><strong>Your Next Steps</strong></p><p><strong>Immediate Action Required:</strong> Assess your current email security systems against AI-generated phishing threats and implement enhanced verification protocols for all financial transactions exceeding £ 1,000. </p><p><strong>Professional Help Recommended:</strong> For businesses requiring sophisticated AI threat monitoring and rapid response capabilities, consider partnering with managed security providers who offer AI-powered threat detection services.</p><p><strong>Source Verification Standards</strong></p><p>All sources cited in this episode have been fact-checked and verified through multiple authoritative channels. UK Government research serves as the primary source for cybersecurity statistics and regulatory requirements. Financial figures are cross-referenced through official government surveys and established cybersecurity research organisations.</p><p><strong>Disclaimer</strong></p><p>This episode provides general guidance only. Always consult qualified cybersecurity professionals before making critical infrastructure changes. Content is based on independent research and industry best practices.</p><p>🎧 <strong>Subscribe for daily cybersecurity updates</strong><br />👍 <strong>Like this episode if it helped you prepare</strong></p><p><br /></p><p><strong>Production:</strong> <a href="https://thesmallbusinesscybersecurityguy.co.uk" target="_blank" rel="ugc noopener noreferrer">The Small Business Cyber Security Guy Production</a><br /><strong>Hosts:</strong> Lucy Harper &amp; Graham<br />All rights reserved</p><p>#Cybersecurity #AISecurity #UKBusiness #SMESecurity #CyberThreats #BusinessSecurity #Deepfakes #PhishingAttacks #CyberDefense #TechSecurity</p>

Episode thumbnail for PayPal's 16 Million User NIGHTMARE - Your Business Is Next

August 21, 2025

PayPal's 16 Million User NIGHTMARE - Your Business Is Next

<p><strong>Episode Summary</strong></p><p>Cybercriminals are selling alleged PayPal credentials for nearly 16 million users on dark web forums, highlighting the devastating reality of credential stuffing attacks targeting UK businesses daily. Hosts Lucy Harper and Graham break down why this threat represents far more than just another data breach and provide an emergency action plan for protecting your business from automated credential attacks.</p><p><strong>What You&#39;ll Learn</strong></p><ul><li>Why the alleged PayPal credential dump likely comes from infostealer malware rather than a company breach</li><li>How credential stuffing attacks work and why they&#39;re particularly dangerous for UK SMEs</li><li>The devastating financial impact - £4.8 million average breach costs and 67% of small businesses facing financial difficulties within six months</li><li>Three immediate emergency actions: credential audits, MFA implementation, and password management</li><li>Forward-looking insights about AI-powered attacks becoming SMEs&#39; top cybersecurity concern in 2025</li></ul><p><br></p><p><strong>Critical Statistics Mentioned</strong></p><ul><li><strong>15.8 million</strong> PayPal credentials are allegedly being sold for just £750 on dark web forums</li><li><strong>52%</strong> of users utilise identical or very similar passwords across multiple accounts</li><li><strong>43%</strong> of UK businesses experienced cybersecurity breaches in the last 12 months</li><li><strong>84%</strong> of UK businesses faced phishing attacks in 2024</li><li><strong>67%</strong> of small businesses that experienced cyber attacks reported financial difficulties within six months</li><li><strong>£4.8 million</strong> average cost of breaches caused by credential stuffing attacks</li><li><strong>80%</strong> of successful hacking incidents involve compromised credentials or passwords</li></ul><p><br></p><p><strong>Key Sources &amp; References</strong></p><ul><li><a href="https://cybernews.com/security/paypal-credential-dump-hacker-claims/">Cybernews: PayPal credential dump investigation and company denial</a></li><li><a href="https://www.tomsguide.com/computing/online-security/over-16-million-paypal-accounts-exposed-on-a-hacking-forum-including-passwords">Tom&#39;s Guide: 16 million PayPal accounts exposed analysis</a></li><li><a href="https://hackread.com/threat-actor-selling-plain-text-paypal-credentials/">Hackread: Threat actor selling PayPal credentials investigation</a></li><li><a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025">UK Government: Cyber Security Breaches Survey 2025</a></li><li><a href="https://optimisingit.co.uk/blog/top-8-cyber-attack-threats-facing-uk-businesses-in-2025-and-how-to-stay-protected/">Optimising IT: Top cyber attack threats facing UK businesses</a></li><li><a href="https://www.iddataweb.com/credential-stuffing-attacks/">ID Dataweb: Credential stuffing attack analysis and costs</a></li><li><a href="https://eclarity.co.uk/cybersecurity-for-uk-smes-the-complete-2025-guide/">Eclarity: UK SME cybersecurity statistics and threats</a></li><li><a href="https://drlogic.com/article/cyber-attacks-on-uk-businesses-why-smes-are-at-greater-risk-in-2025/">Dr Logic: SME cyber attack risks and business impact</a></li><li><a href="https://cybersecuritynews.com/paypal-email-and-passwords-leak/">Cybersecurity News: PayPal email and password leak analysis</a></li></ul><p><br></p><p><strong>Your Next Steps</strong></p><p>Conduct an immediate credential audit across all business accounts and enable multi-factor authentication everywhere today. The alleged PayPal credentials may already be circulating in criminal networks, which are being tested against UK business platforms. </p><p>For businesses lacking internal cybersecurity expertise, professional monitoring services can detect and prevent credential stuffing attacks before they cause devastating financial damage.</p><p><strong>Source Verification Standards</strong></p><p>All sources cited in this episode have been fact-checked and verified through multiple authoritative channels. Cybersecurity research firms and threat intelligence platforms serve as primary sources for attack methodology and statistics. Financial impact figures are cross-referenced through various industry sources. UK-specific data prioritises government cybersecurity surveys and established UK technology security publications.</p><p><strong>Disclaimer</strong></p><p>This episode provides general guidance only. Always consult qualified cybersecurity professionals before making critical infrastructure changes. Content is based on independent research and industry best practices.</p><p>🎧 Subscribe for daily cybersecurity updates👍 Like this episode if it helped you prepare</p><p>Production: <a href="https://thesmallbusinesscybersecurityguy.co.uk" target="_blank" rel="noopener noreferer">Small Business Cyber Security Guy Production</a></p><p>Hosts: Lucy Harper and Graham Falkner</p><p>Sponsor: <a href="https://www.equategroup.com" target="_blank" rel="noopener noreferer">Equate Group Ltd</a></p><p>All rights reserved</p><p>#CyberSecurity #PayPalBreach #CredentialStuffing #DataBreach #CyberThreats #PasswordSecurity #MFA #TwoFactorAuthentication #UKCyberSecurity #SmallBusiness #BusinessSecurity #DarkWeb #Cybercrime #InfoStealerMalware #CyberIntelligence #ThreatIntelligence #CyberSecurityPodcast #TechPodcast #BusinessPodcast #UKPodcast #CyberNews #SecurityNews #TechNews #BusinessNews #DailyTech #CyberEducation #PasswordManager</p><p><br></p>

16 total episodes available

Deep-dive analytics for The 10 Minute Cyber Fix

Frequently asked questions

Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.

What is The 10 Minute Cyber Fix?

Your daily cybersecurity briefing for UK small businesses and tech enthusiasts. Every weekday morning, cybersecurity consultant Lucy Harper delivers the cyber intelligence you need to protect your business in just ten minutes.

No jargon, no fear-mongering, just practical advice about current threats targeting UK SMEs.

From ransomware attacks hitting local businesses to new phishing campaigns, each episode explains what's happening, why it matters, and exactly what you can do about it.

Perfect for your morning commute or coffee break.

Every M-F

Listen Notes

How often does this podcast release new episodes?

This podcast updates daily.

Where can I listen to this podcast?

This podcast is available on 4 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.

Does this podcast accept guests?

Information about guest appearances is not available.

Legal Disclaimer

Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.

All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.

We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.

While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.

By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.