What to look out for today
Three themes SMEs should pay attention to today:
- Self-hosted developer tools under attack: reports say attackers are exploiting a critical flaw in Gitea (a self-hosted Git service). If you run Gitea in-house or via a supplier, treat this as urgent.
- Website/video library risk: CERT/CC has disclosed unpatched issues in Kaltura’s mwEmbed HTML5 video player library that could allow remote file access and code execution on a server. This matters if your website (or your web agency/platform) uses it.
- Fraud and impersonation pressure: INTERPOL’s Operation Jackal IV highlights the scale of organised cyber-enabled fraud linked to West African crime groups. Crackdowns don’t remove the risk—often they shift tactics toward more impersonation and payment redirection attempts.
Why this matters to smaller businesses
- Developer tools are a supply-chain gateway: if attackers get into your code repository or build environment, they can steal secrets (API keys), tamper with code, or move on to cloud services and customer data.
- Your website is part of your operations: a compromised site can be used to steal enquiries, redirect payments, distribute malware, or damage trust—especially for charities, schools, and professional services.
- Breach “ripple effects” drive scams: when organisations disclose breaches (e.g., LACMA), criminals often reuse the story as cover for phishing (“verify your details”, “update payroll/bank info”, “download documents”). Even if you weren’t involved, your staff can be targeted.
Warning signs
- Unexpected password resets, new admin users, or unfamiliar login locations on developer/admin systems.
- Website behaviour changes: new pop-ups, redirects, strange pages, or sudden SEO/Google warnings.
- Unusual outbound traffic from servers, or alerts about suspicious processes on web hosts.
- Email/phone requests to change bank details, “reconfirm” invoices, or urgently approve payments—especially with pressure and secrecy.
- Messages referencing a recent breach headline to make the request sound legitimate.
How attackers may exploit the situation
- Compromise self-hosted services (like Gitea) to access source code, tokens, deployment keys, and internal documentation—then pivot to cloud services and finance systems.
- Exploit exposed website components (such as embedded player libraries) to get a foothold on web servers and then alter content, steal form submissions, or plant further malware.
- Run impersonation and payment diversion scams using “supplier change” emails, fake invoice chasers, or CEO/Headteacher-style urgent requests, often timed around busy finance cycles.
What to do today
- Confirm whether you run Gitea anywhere (in-house, at an MSP, or as part of a dev supplier). If yes, escalate to your IT/provider today.
- Ask your website provider whether Kaltura mwEmbed is used on your site(s) or embedded pages, and what mitigations they are applying given the issues are reported as unpatched.
- Re-brief finance staff on payment-change controls: never accept bank detail changes by email alone; always call a known number from your records.
- Check admin access: review who has admin on code repos, website hosting, DNS, and M365/Google Workspace; remove old accounts and enforce MFA where possible.
Ask your IT provider
- Do we operate Gitea anywhere? If yes, are we seeing any signs of exploitation and what extra monitoring is in place this week?
- Do any of our websites or client portals use Kaltura mwEmbed (directly or via a third-party theme/plugin)? If yes, what’s the risk decision and mitigation plan given the disclosure is unpatched?
- Can you confirm MFA coverage for: website hosting, DNS registrar, cloud admin accounts, and developer/admin tools?
- What’s our fastest isolation plan if a web server or dev system is suspected compromised (who to call, what gets turned off, how we keep trading)?
Patch watch - only one short paragraph, and only if relevant
If you (or your supplier) run self-hosted platforms like Gitea, treat “actively exploited” reports as a prompt for same-day review and remediation. Separately, the reported unpatched Kaltura mwEmbed issues mean you should focus on exposure management (where it’s used, what can be isolated/disabled, and what monitoring is in place) rather than waiting for a routine cycle.
One action today
Today, have IT (or your web/MSP supplier) confirm whether you use Gitea or Kaltura mwEmbed anywhere, and if yes, agree a same-day risk response (monitoring, isolation steps, and remediation plan).
Related Actions On Cyber resource
Actions On Cyber checklist: Payment change (invoice redirection) verification process for SMEs
Sources
- Hackers now exploit critical Gitea flaw in code injection attacks (BleepingComputer)
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code (The Hacker News)
- INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown (The Hacker News)
- LACMA data breach last year exposed social security and medical data (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.