This website uses cookies

Read our Privacy policy and Terms of use for more information.

PHISH & TELL™ –
The Cyber & AI Risk Triage Desk

So your business doesn’t break while you’re busy running it.
A 5-minute weekly brief that tells you what to ignore, what to fix, and what can wait.

This week is about the connections your business already trusts.

Not every security problem starts with a strange email. Sometimes it starts with a website theme, a self-hosted code tool, an email server, a trusted package mirror, or an AI assistant that is allowed to read a webpage for you.

The good news: you do not have to fix everything today. You need to know which connections belong to you, which ones belong to a provider, and which ones can be ignored or shut down because you do not use them.

THIS WEEK’S 10-MINUTE WIN
Make a one-page list of your public-facing tools.

This is not a full asset inventory. It is a quick "could someone reach us from the internet?" list. Start with your website, email system, customer portal, booking system, code repository, remote access tool, and any server your IT provider might manage.

Why? Attackers are actively exploiting a number of issues that can let an unauthenticated attacker access vulnerable websites and other tools.

Should you care? Only if you use one of these tools, or if a provider uses one on your behalf. If you are on Google Workspace, Microsoft 365, Shopify, Squarespace, Wix, or a managed website plan, your job is mostly to ask the owner of the system one specific question and document the answer.

Tool or connection

Ask this

Website

What platform are you using? What theme or templates, plugins, and admin users are active?

Email server

Are we using Microsoft 365, Google Workspace, or something else?

Remote access

What else can be reached from the internet?

Do this now:

  • Write down the tool name, owner, provider, login URL, and "internet-facing: yes/no."

  • Ask your IT or web provider: "Are any of these tools affected by current issues?"

  • Save the list in the same secure place you keep insurance, vendor, or website records. (Not on a file on your computer or in the cloud.)

  • If the answer is vague, ask for specifics — version numbers and the date they were last updated.

What can wait: a perfect inventory. Today, just find the publicly accessible connections.

AI REALITY CHECK
AI assistants are starting to behave more like browsers, interns, and automation tools at the same time

AI assistants are starting to behave more like browsers, interns, and automation tools at the same time. That is useful, but it changes what "read this webpage for me" means.

A webpage can contain instructions that are meant for the AI, not for you. If the AI has tools, browsing access, memory, files, or private conversation context, the risk is not just "bad answer." The risk is "the assistant may act on hidden instructions."

Practical steps:

  • Use a fresh chat for unknown webpages, especially if the page came from an email, ad, comment, or forum.

  • Do not paste client data, passwords, contract terms, bank details, health information, or private employee details into the same chat where you ask an AI tool to inspect unknown websites.

  • If an AI tool asks to open a link, send data, connect an app, download a file, or run code, stop and read the exact action before approving.

  • For business use, keep a short list of which AI tools are allowed to use browser access, file access, email access, calendar access, or payment data.

This is not a reason to stop using AI. It is a reason to separate "help me think" from "act on my business systems."

READER QUESTION OF THE WEEK
My website is managed by someone else. Do I still need to care about plugin and theme security alerts?

Short answer: yes, but you do not need to become the web developer.

Why it matters: In a recent case, vulnerable pieces were a WordPress theme and its required builder plugin, and successful exploitation could fully compromise a website, including database access, malicious redirects, rogue admin accounts, or malware installation (BleepingComputer). If a customer lands on your site and gets redirected to a fake login page or malware download, they will remember your business name, not the plugin name.

What to do first:

  • Ask your website provider or developer: "Do we use Avada, Fusion Builder, or any premium WordPress theme that requires a separate builder plugin?"

  • Ask: "Are automatic updates enabled, and who checks after updates to make sure the site still works?"

  • Ask: "Who are the current WordPress admin users, and can you remove anyone who no longer needs access?"

  • Ask for the latest backup date and the last successful restore test date.

What evidence to keep:

  • The provider's answer.

  • A screenshot or export showing the theme and plugin versions.

  • A list of current admin users.

  • A backup or restore confirmation with a date.

What can wait: learning every plugin name on your site. Start with the ones that control design, forms, checkout, accounts, redirects, and file uploads.

RISK RADAR
Also happening this week

Gitea servers are being exploited

Gitea is a self-hosted Git service, usually used by software teams or developers, and CISA added CVE-2026-60004 to its exploited-vulnerability list after active exploitation was reported (BleepingComputer). The important small-business lesson is that "we only use it internally" is not enough if the login page is reachable from the internet or self-registration is open.

Fix: If you or your developer host Gitea, update to version 1.27.1, disable public self-registration unless it is truly needed, and ask whether any unknown accounts or repositories were created.

Zimbra email servers need urgent attention

Zimbra fixed CVE-2026-73570 in version 10.1.20, and BleepingComputer reported that CISA ordered federal agencies to secure affected systems after active exploitation was added to the Known Exploited Vulnerabilities catalog (BleepingComputer). Most small businesses are on Microsoft 365 or Google Workspace, but some providers still run Zimbra behind the scenes.

Fix: Ask your email provider what platform your mailbox runs on. If the answer is Zimbra, ask for version 10.1.20 or later and confirmation that logs were reviewed.

Avada and Fusion Builder need updates

The Avada WordPress theme and Fusion Builder plugin had a critical vulnerability chain tracked as CVE-2026-18431, with fixed versions listed as Avada 7.16.1 and Fusion Builder 3.16.1 (BleepingComputer). This matters because many small businesses do not know what theme their site uses until a problem appears.

Fix: Ask your web person for your WordPress theme and builder plugin names today. If Avada or Fusion Builder is present, confirm the fixed versions.

Phishing pages are hiding on trusted developer domains

BleepingComputer reported that attackers are abusing npm and npm mirrors to host malicious HTML pages that look like Cloudflare verification pages and redirect visitors to attacker-controlled sites (BleepingComputer). The packages did not infect developers by being installed, but the mirror domains can make a malicious page look more trustworthy than a random phishing domain (BleepingComputer).

Fix: Do not log in from a page just because the domain looks technical or familiar. If a page asks you to prove you are human and then sends you to a login, close it and open the service directly.

AI voice calls are becoming part of stolen-phone scams

BleepingComputer reported that AnonyMousKIT used voice AI agents in stolen-iPhone phishing workflows, including calls where a persona such as "Alice from Apple Support" asked victims to confirm ownership by dictating the device passcode (BleepingComputer). The platform was connected to 506 domains and 168 reseller storefront brands, according to the same report (BleepingComputer).

Fix: Never give a device passcode, one-time code, or Apple Account password to someone who calls, texts, emails, or WhatsApps you. Open Find My or apple.com yourself.

"Veterans Savings Program" that does not exist

The FTC warned this week about postcards targeting veterans with a fake "Veterans Savings Program" that does not exist (FTC Consumer Advice). The FTC says the mailer is a scam to collect personal or financial information and advises people not to respond, to contact the VA directly using a trusted number, and to report the scam to the FTC and VA (FTC Consumer Advice).

Why include this in a business newsletter? Because owners are people first. A family scam can become a business problem when the same phone, email, password manager, or cloud account is used for both personal and work life.

One simple family rule: if a letter, postcard, call, or text promises money and asks for personal information, do not use the contact details in the message. Look up the agency or company yourself.

Before you go

Security gets easier when the question changes from "are we safe?" to "which doors do we own, and who is checking them?"

This week, pick one public-facing system and get a written answer. Website. Email. Remote access. Code. Customer portal. One answer is progress.

My weekly question to you: What security question or weird email caught your attention this week?

Reply and tell me. I read every response.

~Alexia

P.S. If one of these checks raises a question, bring it to office hours — free and private, Fridays at 1pm ET. Sometimes a quick 8-minute conversation is enough to figure out what matters and what can wait. Add office hours to your calendar and drop in when you have a question. (Some folks have asked whether ro.am drops you right in with me, face to face. No, don’t worry, you enter a lobby on a web site (or app) called Ro.am, and I let you in. No surprises for either of us. 🙂)

P.P.S. Remember, if you are a small supplier or vendor and you are looking to qualify for bigger contracts, check out our sister newsletter, Quote and Qualify™️, at newsletter.brightleafreadiness.com.

You’re subscribed to Phish & Tell™️ because your business is worth protecting.

🩷