• Two answers now fail Cyber Essentials outright · Security

    Since April 2026, missing multi-factor authentication on any cloud service, or missing the 14-day window for high-risk updates, fails the whole Cyber Essentials assessment automatically. Here is what else changed, and why a stricter certificate is good news for the business holding one.

  • Test your backups before an attacker does · Security

    Nine in 10 organisations are confident they could recover from an attack. Fewer than one in three ransomware victims actually got all their data back. The difference is testing, and a restore test costs an afternoon.

  • Nobody knew whose job the patching was · Security Commentary

    Ask your IT provider who watches for security updates on your website, then ask yourself the same question. If the two answers do not match, you have the gap that the ICO has just reprimanded a national police unit for. Its website ran the same unpatched version for three and a half years because each side thought the other was looking.

  • The people attackers pick are not the ones you protect · Security Commentary

    Security spending goes on the accounts with technical power: administrators, IT, the server logins. New research into who actually gets compromised at the start of a ransomware attack found three quarters of victims worked in finance, sales, operations, HR, or marketing. What made them worth picking was signing authority, not system access.

  • The plugin that changed without changing · Security Infrastructure

    Seven WordPress plugins were used to create hidden administrator accounts on live sites without a single plugin file being altered. Every update check passed, every version number was correct, and the sites were still compromised. Here is why checking for updates was never going to catch it.

  • Ransomware went back up in July · Security

    After a quiet spring, ransomware attacks rose 19% in July. The interesting part is not the total but which sectors moved, and the fact that two gangs now account for a third of everything recorded.

  • The call that comes from your own IT desk · Security

    A group tracked as UNC6671 rings staff on their personal mobiles, says it is the IT help desk, and walks them through a security upgrade that is really a login page it controls. It works on businesses that have done everything they were told to do. Here is the rule that stops it.

  • The dashboard tool with your database password · Security Infrastructure

    Somebody in your business set up a reporting dashboard once. To draw those charts it holds a login to your live database. A flaw scored 10 out of 10 in Metabase was used to walk in and take those logins, and real companies lost customer data through it.

  • Before you switch on staff monitoring · Security Commentary

    A third of UK organisations now monitor staff digital activity, up from a fifth two years ago. The government is consulting on whether employers should have to consult workers first. Whatever the outcome, the questions in the consultation are the ones to ask yourself now.

  • The router nobody chose is phoning home · Security Infrastructure

    Researchers found a factory-fitted backdoor in every firmware image a Chinese router maker publishes, across at least 20 models. It dials out every 35 seconds and hands whoever answers a root shell. There is no fixed firmware, the same hardware is sold under other brand names, and your firewall does not stop it.

  • Who is recording your meetings, and who else can read them · Security AI

    A researcher found that any free account on a popular AI meeting recorder could list every meeting on the platform: 181,874 records, 84,312 users, and around 1,000 live calls joinable at any moment. He reported it in January. Six months later it was still open and the CTO had never replied.

  • Passkeys are still right, here is the small print · Security

    New research shows malware already running on a Windows machine can hijack Google-synced passkeys, sign in silently, and extract the keys. Passkeys are still the best login you can give your staff. This is what changes, and what does not.

  • The signature was valid and the package was poisoned · Security Infrastructure

    Last week's npm worm reached more than 400 packages, and the poisoned releases carried valid, cryptographically correct build provenance. The check everyone has been told to rely on passed. Here is what signed provenance actually proves, and what it does not.

  • The vulnerability that gets you is nine months old · Security Deep dive

    We measured the gap between a vulnerability being published and being confirmed as exploited. The median is 272 days, and nearly half take more than a year. Watching only the new ones misses most of what matters.

  • Your IT provider's remote access is the way in · Security

    Whoever looks after your computers almost certainly has software installed that can take control of them remotely. Attackers have just been caught abusing exactly that, and the access survived after the original hole was closed. Here is the question to put to your provider.

  • Counting vulnerabilities tells you almost nothing about risk · Security Infrastructure Deep dive

    The Linux kernel has 8,053 recorded vulnerabilities and almost none get exploited. FortiOS has 113 and one in five does. Sorting software by how many flaws it has had is close to sorting it backwards.

  • The code on your website you did not write · Security Infrastructure

    Your website almost certainly loads scripts from other companies: analytics, advertising, chat widgets, payment forms. Each one is code you did not write, running in your visitors' browsers, that a supplier can change at any time without telling you. Last week one of them was changed by somebody else.

  • 97% of critical vulnerabilities are never exploited by anyone · Security Deep dive

    Of 20,491 vulnerabilities scored 9.0 or higher, 570 show any evidence of being used in an attack. Meanwhile one in eight confirmed-exploited flaws was scored below 7, and 141 had no score at all.

  • The sandbox nobody checked · AI Security

    Two AI labs have now admitted their test agents got out and attacked real companies. Neither was a rogue AI. Both were a boundary somebody assumed existed and nobody validated, which is the same assumption most businesses are making about the agents they have just switched on.

  • The patching rule that beats "just do the criticals" · Security Deep dive

    We analysed 248,176 public vulnerability records against the list of flaws confirmed as exploited. Sorting by CVSS severity gives you 89,697 things to patch. A different rule gives you 3,513 and catches nearly as many of the ones that matter.

  • 14,000 charities lost online banking to someone else's flaw · Security

    CAF Bank pulled its online banking on 24 July over a vulnerability in third-party software, and it is still down. Some charities could not run payroll. Nobody's own security failed. The question this raises about your continuity plan is uncomfortable.

  • NCSC has written down how to recover, and the hard part is not the plan · Security

    New NCSC guidance walks through a serious incident in three stages: the first hours, getting back to minimum viable operations, and the longer rebuild. The most useful idea in it has nothing to do with technology, and most firms are skipping it.

  • The phishing page that screenshots your own website · Security

    The advice to look out for a dodgy-looking login page has quietly stopped working. A phishing kit now builds a fresh page for each victim, taking a live screenshot of that person's real company website to use as the background. What still defeats it.

  • They didn't hack the Department for Education, they rang the helpdesk · Security

    More than 600,000 records went out of the Department for Education through its helpdesk, not through a vulnerability. The people who answer your phone can hand over more than your firewall ever will, and almost nobody has written down what they are allowed to do.

  • The malware your browser builds for itself · Security

    The old advice was simple: block the bad download and you are safe. A malvertising campaign has just retired it. There is no bad file to block, because the malware does not exist as a file until your own browser assembles it, piece by piece, in memory. Here is how it dodges the defences that scan for known-bad downloads, and what still stops it.

  • The post-quantum deadline that applies to you is 2028, and it only asks you to make a list · Security

    Everyone quotes 2035 as the post-quantum deadline. The NCSC's first UK milestone is 2028, and it does not ask you to replace any encryption. It asks you to know where yours is. New survey data suggests that is exactly the part organisations are stuck on.

  • The phishing email that needs no click · Security

    Every phishing lesson you have given your staff ends with the same rule: don't click. A new attack the NCSC and its Five Eyes partners have just flagged breaks it. Simply opening the email is enough. Here is what zero-click really means, why staff training alone no longer covers you, and the one thing that does.

  • Hotel Wi-Fi is quietly stealing your staff's Microsoft 365 logins · Security

    Your colleague checks into a hotel, connects to the guest Wi-Fi, and signs into Microsoft 365. No dodgy link, no attachment, nothing to click. The venue's router has been tampered with, and their password is now someone else's. Here is how the attack works and the two settings that stop it.

  • Is a selfie a safe key to your business Google account? · Security

    Google now lets you record a video of your face as a backup way to get back into a locked-out account. It is aimed at a real problem, but it hands a decision to any business running Google Workspace: is a selfie an acceptable last-resort key to your company's email and files, and should staff turn it on? Here is what it does, where it is weaker than it sounds, and how to decide.

  • The address your kit still phones home to may belong to someone else now · Security Infrastructure

    A researcher rented cloud IP addresses that Synology and Amplitude had given back, and real customer traffic arrived without any hacking at all. Old NAS boxes handed over tokens and network details. Analytics proxies forwarded personal data without checking who they were talking to. Here is what stale DNS means for your business, and what to check.

  • The app you trust is now the thing carrying the malware · Security

    Two findings this week show attackers skipping the vulnerability entirely and hiding malware inside apps your staff already trust. A real, clean copy of Notepad++ delivered a malicious plugin. A macOS flaw lets an attacker swap a trusted app's insides without a single warning. Here is why 'it's a program I recognise' is no longer a safe signal, and what to check.

  • The take-home interview test that hires your laptop instead of you · Security

    A developer picked apart a take-home test from a LinkedIn recruiter and found malware wired into the project's git hooks, set to run the moment he committed code. Fake recruitment is now a standard delivery route for malware, and your hiring process, and your job-hunting staff, are the way in.

  • An AI agent broke into a real company on its own. Here's what to check before you connect yours · Security AI

    OpenAI has admitted its own AI models found a zero-day, escaped a test environment, and used it to breach Hugging Face, entirely on their own initiative. Separate research on ChatGPT and Claude's third-party connectors found the risk grows the moment you plug an AI agent into your actual tools. What to check before you do the same.

  • SharePoint's third actively-exploited flaw this month: patching isn't enough · Security

    CVE-2026-50522 is the third on-premises SharePoint Server vulnerability under active exploitation in July 2026, CVSS 9.8. Attackers are stealing SharePoint's machine keys for persistence, meaning patching alone will not remove them. Only on-premises SharePoint is affected, not SharePoint Online.

  • wp2shell: check your WordPress site today, patched or not · Security

    Two chained WordPress core vulnerabilities, codenamed wp2shell, let an anonymous attacker take over a stock WordPress install with a single request. No plugins needed. Mass scanning is under way. Here is what to check, patched or not.

  • What's your answer to the patch tsunami? · Security Commentary

    AI is finding and weaponising vulnerabilities faster than any manual process can triage them. Around 900 new CVEs a day, and only a handful that actually matter. This is a genuine question to other teams: what are you doing about it? Here are the things we do, and where you can tell us yours.

  • The Cyber Resilience Pledge is really about your suppliers · Security Commentary

    A voluntary pledge for big firms sounds like it isn't your problem. But one of its three asks is Cyber Essentials across the supply chain, and that supply chain is you. Here's what to do, and why a certificate is not the same as security.

  • What decides a .uk domain dispute: the story, not the paperwork · Deep dive Security

    Typosquatters lose 98% of .uk disputes. Holders of ordinary dictionary words usually keep them. Three-letter domains are a coin flip. What 5,525 decisions reveal about how domain cases are actually won and lost.

  • If your website runs this plugin, it could be the thing attacking your staff · Security Infrastructure

    A critical flaw in W3 Total Cache, a caching plugin on over 900,000 WordPress sites, lets an attacker run code on the server with no login. The real danger is not your site going down. It is your own site being turned into the thing that attacks everyone who visits it, including your staff. Update to 2.10.0.

  • Chrome is the keys to your castle, and it just shipped 382 fixes. Update it. · Security Commentary

    Chrome 150 fixes 382 security flaws, 15 critical, including sandbox escapes and remote code execution. None are being exploited yet, and there is no public proof of concept, which is exactly the window to patch in. For most businesses the browser holds every login that matters, so update it before that window closes.

  • The website your AI invents, and the attacker waiting to register it · AI Security

    AI assistants confidently hand back web addresses that do not exist. Attackers register those invented domains and host phishing pages on them. New Unit 42 research found roughly 250,000 unregistered phantom domains, and real kits stealing card and bank details. Here is how the attack works and what to tell your team.

  • The average attacker is inside your network for two and a half weeks before you notice · Security Commentary

    New research shows attackers now sit undetected on a network for an average of two and a half weeks, and nearly half of firms only find out once data has been stolen. Set against fresh UK police figures on ransomware losses, the lesson is that detection, not just prevention, is where most SMEs are exposed.

  • When the attacker doesn't want a ransom · Security Commentary

    Most continuity plans quietly assume a ransomware attacker wants paying, which gives you something to negotiate. The Jaguar Land Rover attribution shows an attack dressed as ransomware that wanted no money at all, just the company on the floor. That changes what recovery has to plan for.

  • Why UK ransomware victims stay silent, and what it costs the rest of us · Security Commentary

    UK Report Fraud figures show only 323 organisations reported a ransomware attack in a year, with £270,000 in losses between them. The real number is far higher. Most victims stay quiet because being named feels like an admission of failure. That silence skews the threat picture everyone relies on, and it is worth deciding your reporting path before an incident, not during one.

  • You can't blame the AI · AI Security Commentary

    If your business publishes anything an AI wrote, a chatbot answer, a summarised quote, advice to a customer, you own what it says. 'The AI got it wrong' is not turning out to be a defence, and a German court has just said so about Google.

  • Five Eyes says the AI timeline is months, not years · Security AI

    On 22 June the intelligence chiefs of the UK, US, Canada, Australia, and New Zealand issued a joint warning that frontier AI is changing the threat in months, not years. The actions they ask for are not new. They are now urgent.

  • The HTTPS padlock is about to need renewing eight times a year · Infrastructure Security

    The certificate behind your website's padlock used to last a year. By 2029 it lasts 47 days, renewed eight times a year. Websites cope automatically. The systems you still renew by hand are the problem.

  • The US just put a 2030 deadline on post-quantum, and it is worth having on your radar · Security Commentary

    On 22 June a US executive order set hard deadlines for federal agencies and their contractors to move to post-quantum cryptography. The interesting part is not the deadline. It is the one task it forces everyone to do first.

  • UK museums ignored the British Library warning, and the lesson is not about museums · Security Commentary

    The Public Accounts Committee says UK cultural institutions have failed to learn from the British Library attack and remain highly vulnerable. The interesting failure is not technical. It is the belief that being low-profile is a form of protection.

  • What Lloyds Bank actually does when it deploys an AI agent · AI Security

    Lloyds Banking Group's security director shared at Infosecurity Europe how the bank actually deploys agentic AI in production. Eleven 'AI bets', a twelfth dedicated to security. Signed tools the agents cannot create. An internal agent marketplace. The world's first production red-team environment using OWASP Top 10 for agentic AI. They saw agent hijack.

  • Attackers are using Claude as the bait · Security AI

    Microsoft's threat intelligence team has tracked phishing campaigns built around ChatGPT, Claude, DeepSeek, and Copilot. A South African ChatGPT-themed wave hit 100,000 mailboxes a day. A Claude-themed wave reached 2,000 organisations across the US, UK, and India. The brand is the lure, the payload is the same old stealer.

  • The FBI counted $20 billion of internet crime. Look where it actually was. · Security Commentary

    The FBI's 2025 internet crime report logged $20.9 billion of reported losses, a 26% rise on 2024. Investment fraud is the largest category at $8.6 billion. Business email compromise is the largest enterprise threat at $3 billion. Ransomware, by reported loss, is smaller than either. The shape of the numbers is the story.

  • 68% of UK firms will spend more on cyber. Fewer than 30% feel ready. · Security Commentary

    Barclays surveyed 1,000 UK business leaders in April. Sixty-eight per cent plan to spend more on cyber security in the next year. Twenty-six per cent say AI brings new risks they cannot answer. Average spend hits £505,000, but a micro business spends £15,000 and a large one spends £1.3 million. The numbers underneath the headline are the more useful ones.

  • The Computer Misuse Act fix that isn't · Security Commentary

    The government finally announced a statutory defence for security researchers under the Computer Misuse Act. The defence covers around 300 people. The UK has 70,000 cybersecurity professionals. The number you remember from this filing is 0.4%.

  • MFA prompt bombing, or when the attacker just asks nicely · Security

    The attacker already has the password. They press the login button. Your phone buzzes. They press it again. It buzzes again. Five times. Twenty. Two hundred. At three in the morning. Eventually somebody taps approve, just to make it stop. That's how Uber lost its single-sign-on, and it's how a lot of UK firms will lose theirs.

  • The EU Cyber Resilience Act is coming for your software · Security Commentary

    Two-thirds of open-source maintainers do not know the Cyber Resilience Act exists. Most UK firms shipping software into the EU haven't checked whether it applies to them. The deadline is December 2027 and the obligations include something most SMEs do not yet produce: a software bill of materials.

  • Patching by severity is over. Here's what replaces it. · Security

    Vulnerability exploitation is now the leading cause of breaches. AI is finding bugs faster than anyone can triage them. Time-to-exploit has gone from 840 days to under two. CISA has rewritten the federal patching rules. If your patching process still runs off CVSS scores, it is solving last year's problem.

  • What NCSC said this month: agentic AI and zero trust · Security AI

    The NCSC published two pieces of guidance in a fortnight that an SME owner can actually use. One is about agentic AI, the kind that takes actions on your behalf. The other is about zero trust network access. Both share the same underlying advice: the user's location stopped being a security signal a while ago.

  • When the IT guy turns up, and isn't the IT guy · Security

    The FBI has warned that the Silent Ransom Group is now sending people into law firm offices, claiming to be IT, then plugging a USB drive into a partner's machine. The script is short, reception lets them through, and the data leaves the building. The fix is mostly process, not technology.

  • GCHQ's narrowing window and the five-year cyber shield · Security Commentary

    From Bletchley Park on 27 May, the GCHQ director said the UK has a narrowing window to keep its technological edge, and announced a blueprint for an AI-driven national cyber defence. Read between the speech lines: the supply chain into critical infrastructure is the lever they actually have.

  • The VS Code extension that emptied GitHub's repos · Security Infrastructure

    A single GitHub employee installed a trojanised Nx Console extension and around 3,800 internal repositories walked out. The interesting question isn't what GitHub will do next. It's what your editor and browser extensions can already reach.

  • Subscription bombing: the distraction is the attack · Security

    Your inbox fills up with 2,000 newsletter confirmations in an hour. None of them are malicious. That's the point. The attacker is using the noise to hide a password reset, a fraudulent purchase, or a fake IT support call that lands moments later. A new EPFL paper has the data.

  • Your AI policy should say something · AI Security Commentary

    Most AI policies are vendor templates with the company name swapped in. They ban the obvious, permit the vague, and tell you nothing about how the business actually wants AI used. A coherent policy is a short one that takes a position.

  • Computer Misuse Act reform is finally on the bill · Security Commentary

    The 1990 Computer Misuse Act predates the public web. Reform has been promised for six years. The May 2026 King's Speech finally put it in a bill, bundled into the National Security Bill. Here's what's likely to change and what's still vague.

  • No, you don't need a web form for data complaints · Security Commentary

    A lot of guidance is telling UK businesses they need an electronic complaint form by 19 June 2026. The statute doesn't say that. It says facilitate, and gives a form as one example. Here's what's actually required and what isn't.

  • The real bill from the M&S and Co-op attacks · Security Commentary

    A year on from the April 2025 retail attacks, the numbers are in. M&S has posted £101.6 million in direct costs and a 16.4% fall in fashion sales. The Cyber Monitoring Centre put the combined bill at £270 million to £440 million. The useful lessons for an SME are the unglamorous ones.

  • The stuff you stopped using is still attacking you · Security Infrastructure

    The NCSC has published guidance on decommissioning assets. The headline is simple: things you no longer use stop being assets and start being liabilities. The boring work of switching them off is one of the highest-value security jobs most businesses skip.

  • Insider fraud is mostly the people you already hired · Security Commentary

    Cifas surveyed 2,000 UK employees at large companies. Nearly a quarter know someone who has fiddled expenses. One in eight know someone who has sold a login. Insider risk is a culture problem before it is a tooling problem.

  • The NCSC says brace for a patch wave. The NHS is pulling the curtains. · Security AI Commentary

    The NCSC has told UK organisations to prepare for a wave of urgent patches as AI accelerates vulnerability discovery. The same week, NHS England decided the answer was to make its open source repositories private. Only one of those approaches actually fixes anything.

  • Copy Fail: 732 bytes to root on every Linux server you forgot about · Security

    CVE-2026-31431 lets any local user become root on Ubuntu, RHEL, Debian, SUSE, Amazon Linux, and most other distros. The exploit fits in 732 bytes of Python. The bug has been there since 2017.

  • cPanel auth bypass: ask your host what they've done about it · Security

    CVE-2026-41940 lets an unauthenticated attacker take root on a cPanel or WHM server. It was being exploited for around a month before the patch landed. If your website lives on shared hosting, this affects you.

  • Phishing still works, AI just made it cheaper · Security

    The 2026 UK Cyber Security Breaches Survey says 43% of businesses had an incident in the past year. Phishing was involved in 85% of those. AI hasn't changed what works, it's just lowered the price of doing it at scale.

  • GoDaddy handed out a 27-year-old domain to a stranger in four minutes · Security Infrastructure

    Two-step verification on. Domain ownership protection on. GoDaddy transferred a non-profit's 27-year-old domain to a stranger in four minutes. The lesson is about the registrar layer most businesses never think about.

  • AI agents and the shadow AI you already have · AI Security

    Two thirds of UK organisations cannot account for what staff share with AI tools. Now agentic AI is being deployed faster than anyone can govern it. The two problems are the same problem.

  • NCSC says passkeys first, passwords second · Security Commentary

    The NCSC has flipped its authentication advice at CYBERUK 2026. Passkeys are now the recommended default, and password plus two-step verification is the fallback. The reasoning is worth understanding.

  • The only SOC metric that matters, according to the NCSC · Security Commentary

    Tickets closed. Rules written. Logs ingested. The NCSC's Dave Chismon argues most security operations metrics actively make detection worse. The one that counts is whether you spot attacks in time.

  • The ICO is becoming the Information Commission · Security Commentary

    The UK's data protection regulator is being restructured under the Data (Use and Access) Act 2025. New board, new CEO, new statutory objectives. The name is the least interesting part.

  • What the Cyber Security and Resilience Bill actually means · Security Commentary

    The biggest overhaul of UK security regulation since 2018 is in committee. MSPs are in scope, incident reporting gets a 24-hour clock, and fines go up to £17 million. Here's what it means in practice.

  • The free security awareness campaign you didn't know existed · Security

    The NPSA gives away a complete, professionally designed security awareness campaign kit. Posters, booklets, checklists, and a full starter guide. Most organisations don't know it exists.

  • Chrome's first zero-day of 2026: update now, don't wait · Security Commentary

    CVE-2026-2441 is actively being exploited in the wild. A use-after-free bug in CSS handling means a crafted webpage is all it takes. Push the update now.

  • Prompt injection is not the new SQL injection · AI Security Commentary

    Schneier and co have reframed prompt injection as 'promptware': a full 7-stage kill chain. The uncomfortable truth: LLMs can't distinguish instructions from data. This isn't a bug you can patch.

  • The first five minutes of incident response · Security

    Containment over correctness, reversibility over impact, protecting state before touching services. What your first five minutes should actually look like.

  • Patch your text editors · Security Commentary

    Notepad++ had its update service hijacked by state-sponsored attackers. Windows Notepad got a CVSS 8.8 command injection. Two editors, two attack vectors, same lesson.

  • Insecure defaults have a long half-life · Security Commentary

    Global Telnet scanning dropped overnight in January 2026. Days later, a critical telnetd authentication bypass was disclosed. The protocol is old. The lesson is current.

  • What Cyber Essentials actually involves · Security

    A plain-English walkthrough of the five Cyber Essentials controls, what the assessment looks like, and what it does and doesn't prove about your security.