Filings tagged: Infrastructure
Hosting choices, cloud costs, resilience, and the platform decisions that keep your business running.
-
The plugin that changed without changing
· Security Infrastructure
Seven WordPress plugins were used to create hidden administrator accounts on live sites without a single plugin file being altered. Every update check passed, every version number was correct, and the sites were still compromised. Here is why checking for updates was never going to catch it.
-
The dashboard tool with your database password
· Security Infrastructure
Somebody in your business set up a reporting dashboard once. To draw those charts it holds a login to your live database. A flaw scored 10 out of 10 in Metabase was used to walk in and take those logins, and real companies lost customer data through it.
-
The router nobody chose is phoning home
· Security Infrastructure
Researchers found a factory-fitted backdoor in every firmware image a Chinese router maker publishes, across at least 20 models. It dials out every 35 seconds and hands whoever answers a root shell. There is no fixed firmware, the same hardware is sold under other brand names, and your firewall does not stop it.
-
The signature was valid and the package was poisoned
· Security Infrastructure
Last week's npm worm reached more than 400 packages, and the poisoned releases carried valid, cryptographically correct build provenance. The check everyone has been told to rely on passed. Here is what signed provenance actually proves, and what it does not.
-
Counting vulnerabilities tells you almost nothing about risk
· Security Infrastructure Deep dive
The Linux kernel has 8,053 recorded vulnerabilities and almost none get exploited. FortiOS has 113 and one in five does. Sorting software by how many flaws it has had is close to sorting it backwards.
-
The code on your website you did not write
· Security Infrastructure
Your website almost certainly loads scripts from other companies: analytics, advertising, chat widgets, payment forms. Each one is code you did not write, running in your visitors' browsers, that a supplier can change at any time without telling you. Last week one of them was changed by somebody else.
-
The address your kit still phones home to may belong to someone else now
· Security Infrastructure
A researcher rented cloud IP addresses that Synology and Amplitude had given back, and real customer traffic arrived without any hacking at all. Old NAS boxes handed over tokens and network details. Analytics proxies forwarded personal data without checking who they were talking to. Here is what stale DNS means for your business, and what to check.
-
AWS's own alarms saw the problem coming, and still didn't stop it
· Infrastructure Commentary
A configuration error sent some AWS customers billing estimates in the quadrillions. AWS's own anomaly alarms detected the problem within minutes and still failed to halt it, only reacting after customer complaints piled up. If your biggest supplier's own alerting can silently fail for hours, what happens when yours does?
-
The UK just named its cloud concentration risk
· Infrastructure Commentary
The Treasury has designated four cloud and technology providers as Critical Third Parties to UK finance: Amazon, Google, Microsoft, and Oracle. The same four that dominate the market. The state has effectively named the concentration risk, and that changes the questions your customers ask about lock-in.
-
The .uk domain dispute service changes hands on Tuesday
· Deep dive Infrastructure
From 7 July 2026, disputes over .uk domain names are filed with WIPO in Geneva, not Nominet. What changes for anyone who owns a .uk domain, what stays the same, and the one deadline before the switch.
-
The .uk land-grab happened twice, and the second one was scheduled
· Deep dive Infrastructure
When Nominet opened direct .uk names in 2014, the obvious ones were reserved for their .co.uk holders for five years. The month that protection lapsed, disputes surged, and they were overwhelmingly naked brand grabs.
-
If your website runs this plugin, it could be the thing attacking your staff
· Security Infrastructure
A critical flaw in W3 Total Cache, a caching plugin on over 900,000 WordPress sites, lets an attacker run code on the server with no login. The real danger is not your site going down. It is your own site being turned into the thing that attacks everyone who visits it, including your staff. Update to 2.10.0.
-
The sovereignty tax: why UK firms want off US cloud and cannot move
· Infrastructure Commentary
A new Civo study finds two-thirds of UK businesses could ditch US cloud providers over sovereignty concerns, yet only 15% have actually moved. The gap is a lock-in problem, and the practical lesson for smaller firms is to make switching possible before you ever need to switch.
-
The HTTPS padlock is about to need renewing eight times a year
· Infrastructure Security
The certificate behind your website's padlock used to last a year. By 2029 it lasts 47 days, renewed eight times a year. Websites cope automatically. The systems you still renew by hand are the problem.
-
When the source goes quiet: a side project, a free feed, and one bad week
· Infrastructure Commentary
A side project that grew into a million requests a day sits on one free Companies House feed. When that feed paused this month, it was a lesson in supply-chain dependency, and in what good engineering does about it.
-
Zero-copy data, and the bank spending €2 million a year on moving data around
· Infrastructure Commentary
BNP Paribas spent up to €2 million a year on data copying, transformation, and reconciliation across 64 countries. Adding a new data source took more than a year. The fix, announced this month, was to stop copying the data and let consumers query it where it lives. The principle scales down to any SME with more than one system.
-
Killing the card: what UKPI means for UK SMEs
· Infrastructure Commentary
On 2 June the UK launched its first new payment scheme since Faster Payments in 2008. Thirty-one founding members, the big nine banks, GoCardless, TrueLayer, Token.io, Yapily. The target is the £1.5 billion a year that UK merchants pay Visa and Mastercard. Wave one is utilities, government, and charities. Wave two is the rest of e-commerce.
-
Cloud bill shock and the quiet return of on-prem
· Infrastructure Commentary
Railway, a developer platform spending $24 million a year on Google Cloud, was switched off without warning for eight hours. Uber burned through its 2026 AI budget by mid-April. One Dell employee racked up $3,400 of token costs in a day. The numbers behind 'post-cloud' are real, even if the term is over-marketed.
-
Gov.uk Pay swapped Stripe for Adyen. Read the exit clause.
· Infrastructure Commentary
Gov.uk Pay is switching its payment processor from Stripe to Adyen for around 1,000 services. The interesting thing is not which provider won. It is that £9 billion of public-sector payments can be moved across at all, because the contract was designed for it.
-
The VS Code extension that emptied GitHub's repos
· Security Infrastructure
A single GitHub employee installed a trojanised Nx Console extension and around 3,800 internal repositories walked out. The interesting question isn't what GitHub will do next. It's what your editor and browser extensions can already reach.
-
The stuff you stopped using is still attacking you
· Security Infrastructure
The NCSC has published guidance on decommissioning assets. The headline is simple: things you no longer use stop being assets and start being liabilities. The boring work of switching them off is one of the highest-value security jobs most businesses skip.
-
GoDaddy handed out a 27-year-old domain to a stranger in four minutes
· Security Infrastructure
Two-step verification on. Domain ownership protection on. GoDaddy transferred a non-profit's 27-year-old domain to a stranger in four minutes. The lesson is about the registrar layer most businesses never think about.
-
Sovereign AI is only sovereign if you can actually switch
· AI Infrastructure Commentary
Two-thirds of UK IT leaders say they have an AI exit plan. Nearly half admit switching would seriously disrupt the business. A plan you can't execute is not a plan.
-
AI just claimed your spinning disks too
· Infrastructure Commentary
Western Digital's entire HDD capacity for 2026 is sold out. Cloud is 89% of their revenue. HDD prices are up 46% since September. The window for sensible storage pricing is closing.
-
When your payment processor can't send a valid email
· Infrastructure Commentary
Viva.com sends verification emails missing the Message-ID header. Google Workspace and Zoho reject them. The fix is one line of code.