Security Notices
When a website vulnerability is serious enough to matter to a small business, this is where it gets explained without the jargon: what it actually does, whether it affects your site, and the one thing worth doing about it this week.
Translation, not commentary
There are people who find these vulnerabilities and people who track who is exploiting them. I'm neither, and these notices never pretend otherwise. Every claim here traces back to the vendor who published the fix, to the researcher who reported it, or to CISA, and the links are in the articles so you can check any of it yourself.
What's missing from that chain is the translation. A security advisory is written for engineers, and the question a business owner actually has is simpler: does this affect me, and what do I do today. That gap is what these notices fill.
They also won't tell you to panic. Most weeks nothing qualifies, and plenty of the ones that do turn out to be already handled by an update your site installed on its own. Where that's true, it says so.
Published when something earns it
Is your WordPress site patched against CVE-2026-87902?
WordPress patched a critical flaw on 22 September and CISA added it to the actively exploited list three days later. Many sites installed the fix on their own. Here's how to confirm yours did.
Read the noticeIs your Magento or Adobe Commerce store patched against CVE-2026-71362?
Adobe fixed this on 11 August and said at the time it knew of no exploitation. Six weeks later CISA listed it as actively exploited. The stores being hit now are the ones that never applied it.
Read the noticeIs your All-in-One WP Migration plugin patched against CVE-2026-19949?
A migration plugin gets used once and then sits there for years. This one has a serious flaw fixed in August, it's on over five million sites, and nothing about your day tells you it's installed.
Read the noticeWebsite Growth Insights
The longer-form articles on websites, local search, AEO and how sites are built sit in the insights hub.
Not sure who looks after your updates?
That's the question underneath most of these notices. If you can't name the person, it's worth sorting out before the next one lands.