This website uses cookies

Read our Privacy policy and Terms of use for more information.

Hey. Hope you had a great week! I’m Kathleen, and every week I dig through the noise to find the AI updates that are most relevant to small business owners.

Let’s jump in.

AI Scams Are Getting Better — Which Means Your Security Needs To Get Better Too

Google announced a major initiative this week aimed at fighting AI-powered scams. The company is targeting cybercriminals who are using generative AI to create highly convincing phishing emails, text messages, and fake websites that look nearly identical to legitimate businesses.

The problem for small businesses is that AI has removed many of the warning signs people used to rely on. Scam messages no longer contain obvious spelling mistakes or awkward wording. Fraudsters can now generate professional-looking communications that appear to come from banks, vendors, software providers, and even government agencies.

Why This Matters

Small businesses are often targeted because they typically don't have dedicated cybersecurity teams.

As you know, one employee clicking a convincing fake invoice, vendor request, or banking alert can lead to stolen login credentials, compromised business accounts, fraudulent payments and customer data exposure.

How To Protect Your Business:

  • Develop a company policy for handling unexpected payment or login requests

  • Implement employee awareness training

  • Use multi-factor authentication (MFA) on critical accounts and a password manager

Implement a Two-Minute Safety Rule

Share this with your employees: Never click a link inside an urgent text message claiming to be from a vendor, bank, accountant, or software company.

Instead:

  1. Open a new browser tab.

  2. Type the company's website address manually.

  3. Log in through the official site.

These extra steps can prevent a very expensive mistake.

Now You Can Now Build a Customer Portal or App!

Wix recently acquired Base44, and Base44 is quickly becoming one of the biggest names in the growing "vibe coding" movement.

The latest update introduces what Base44 calls "Super Agents." Instead of simply generating a website or app layout, the platform can now build much of the operational infrastructure automatically.

In practical terms, a business owner can describe what they want, and Base44 can create:

  • the application

  • the database

  • user accounts and logins

  • payment processing

  • automated emails

  • PDF workflows

Much of this can be completed in a week instead of months.

Historically, building a customer portal, member site, internal business tool, or online storefront often required a developer, a designer, payment integration, and thousands of dollars.

AI is dramatically lowering those barriers. And for small businesses, this means it's becoming much easier to test ideas before investing heavily in custom software.

What you need:

  • A Base44 account

  • A business idea or workflow you want to build

  • Stripe account (if accepting payments)

  • Basic understanding of your customer process

How it works:

  • Describe what you want in plain English

  • AI generates the application

  • The system creates databases and workflows automatically

  • User authentication and payments can be added automatically

  • Publish and test the application

But, The Warning Every Vibe Coder Needs to Read

However, before you rush off to build apps, there is an important cautionary tale.

Security researchers recently scanned approximately 380,000 AI-generated applications across multiple vibe-coding platforms, including Base44, Replit, Netlify, and Lovable.

They found more than 5,000 live applications were exposing sensitive information.

In many cases, customer data, financial information, and internal business records were publicly accessible because the app creator didn't properly configure user permissions.

The issue wasn't malicious intent. The issue was that the software was built faster than the security was reviewed.

Before launching any AI-built application:

  • Test user permissions

  • Create separate user accounts and verify access levels

  • Review payment processing settings

  • Verify customer data cannot be accessed publicly

  • Have someone else test the application before launch

That’s it for this week — hopefully this gives you a clearer picture of how AI is becoming an integral part of everyday small business operations and inspires a few ideas that could make your work a little easier. See you next week with more practical AI updates.

Yours in success,
Kathleen

P.S. Forward this to one business-owner friend who’s still “figuring out AI.” You’ll look like the smart one. 😊

Keep Reading