Your Security Kit Is the Way In The things you bought to keep attackers out are how they’re getting in. Citrix, Fortinet, forgotten WordPress backups, fake ChatGPT adverts, and the AI in your business that nobody owns. Some time in early September, somebody found a way through a door that thousands of businesses use to let their staff in from home. The owners didn’t know. Then the emergency fix arrived, patched boxes started rebooting, and that turned out to be another hole attackers were already using. This week Noel Bradford, Lucy Harper, and Graham Falkner follow one thread through every story: something was trusted, and nobody was in charge of checking that trust. Citrix NetScaler zero-days exploited for weeks before disclosure. A FortiMail flaw with fixes still pending, and Noel’s long-running grievance with Fortinet’s track record. Forgotten WordPress backups handing over email and cloud passwords. Microsoft’s Digital Defense Report showing phishing back as the front door. And fake ChatGPT adverts on Google that walk staff straight into installing a remote access tool. Then the conversation turns to the AI in your business that nobody owns. Prompted by John Wernfeldt’s LinkedIn post on AI teams and governance teams talking past each other, the hosts translate the problem for Gary Mott’s twelve-person building firm and land on three conditions that take twenty minutes to agree. Noel also announces GRCBolt, his own AI policy pack for UK small businesses, now taking waitlist sign-ups. What to do this week Email your IT provider and anyone who holds your data. Ask whether they run Citrix NetScaler or Fortinet FortiMail, and whether they’ve patched and checked for signs of compromise. For Citrix, ask whether they’ve applied the second fix released on Sunday 4 October. Find out who looks after your website. Ask them to clear old backup files out of public folders, update WordPress, and change the email password stored in your contact form plugin. Turn on passkeys for the accounts that matter most: whoever runs Microsoft 365 or Google Workspace, and whoever approves payments. Both platforms include passkeys at no extra charge. Forcing everyone to use them needs an extra licence on some Microsoft plans. Tell everyone one rule. No genuine website will ever ask you to press the Windows key and R, then paste something in. Agree three things about AI: which tools are allowed, which data never goes in, and who checks the output before a client sees it. Put a name next to each. Chapters 00:00 Cold open 00:56 Welcome 01:33 The doors you don’t own: Citrix NetScaler and Fortinet FortiMail 10:15 The back door you forgot: WordPress backups leaking passwords 13:36 Borrowed trust: Microsoft’s report and fake ChatGPT adverts 19:13 The AI nobody owns 23:00 Introducing GRCBolt 25:03 Your Monday morning actions 26:57 Close Sources Citrix NetScaler NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway Citrix security bulletin for CVE-2026-88771 to CVE-2026-88778, including indicators of compromise Sophos: Citrix NetScaler vulnerabilities in active exploitation The Hacker News: Mandiant and Google Threat Intelligence on the NetScaler campaign Cyber Security News: NetScaler appliances rebooting after the zero-day patch BleepingComputer: Citrix patches NetScaler SAML zero-day exploited in attacks Fortinet FortiMail Help Net Security: Critical FortiMail zero-day exploited in the wild watchTowr: FortiMail CVE-2026-104286 FAQ Radical Notion: Fortinet CVE report card (third-party aggregator) MazeHQ: 2025 known exploited vulnerabilities by vendor WordPress backups Cyber Security News: Exposed WordPress backups leaking cloud and email credentials Microsoft Digital Defense Report 2026 Microsoft Digital Defense Report 2026 Microsoft’s figures come from its own customer and incident response data, so treat them as vendor telemetry. Fake ChatGPT adverts and ClickFix Huntress: Attackers abuse ChatGPT Custom GPTs to deliver a RAT via ClickFix Island: How attackers use sponsored search and Custom GPTs in malware delivery Passkeys CoreView: Enabling and enforcing passkeys in Microsoft Entra ID Google Workspace Updates: Passkeys for Workspace users AI and governance The governance discussion was prompted by a LinkedIn post from John Wernfeldt on why AI teams and governance teams need to be in the same room. John writes about data governance, analytics, and AI in his newsletter, Data Governance Field Library. GRCBolt GRCBolt is Noel’s own product, and this episode has no sponsor. It’s an AI policy pack for UK small businesses: four documents written around your business, a one-off price under £100, no subscription, and editable Word files. It’s guidance only, and it doesn’t replace legal advice or certify you against any standard. Join the waitlist and see the partial sample pack at grcbolt.co.uk. Related episodes Mentioned in this episode: The Firewall Fallacy: Fortinet, KEVs and the Cost of Complacency When AI Finds the Switch You Forgot: Attacks for Pocket Change When Laws Lag and Attacks Sprint: The 10-Hour Cyber Reckoning Why a 0% Phishing Click Rate Might Be Lying to You When AI Could Make You Speak: Trust, Consent, and Synthetic Voices We Found the Admin Password in the Dark Web: A GRC Wake-Up Call Passkeys Aren’t Dead: What a Week of Panic Taught Us About Risk Further listening: Shadow AI Is Just Shadow IT Wearing a Cape If Your MSP Says ‘All Good’, Can They Prove It? Listen, subscribe, and join in All episodes Join our Skool community Questions or stories: Hello@TheSmallBusinessCyberSecurityGuy.co.uk If this episode was useful, share it with someone who needs to hear it. Especially whoever looks after your website.