A shrinking red number on a scanner dashboard is not vulnerability management. Here is what the process actually requires, and NCSC’s own patch deadlines.
Rebecca Sutton
Rebecca Sutton
Rebecca is a dedicated cybersecurity writer who specialises in transforming complex technical concepts into clear, accessible content. With a strong background in IT and a passion for digital security, she produces insightful articles, guides, and thought-pieces that bridge the gap between technical experts and wider audiences.
-
-
A critical Keycloak password reset flaw let unauthenticated attackers seize any account, admins included. Here is what happened and what to patch now.
-
WilmerHale paid at least $18 million and Goodwin Procter around $10 million to the Luna Moth extortion group, which broke in using phone calls and fake IT visits rather than …
-
A chain of five vulnerabilities in the Markdown Preview Enhanced VS Code extension let a crafted markdown file write to files on a developer’s machine. All five are now patched.
-
A critical Forminator plugin vulnerability lets attackers upload malicious files without logging in. Here is a quick checklist to find out if your site is exposed.
-
A single attacker has spent 17 months scraping Salesforce and ServiceNow customer portals worldwide, not by exploiting a flaw but by using guest user permissions exactly as they were configured.
-
The critical NetScaler authentication bypass, CVE-2026-19490, was routine to fix. The pattern behind it, of gateway appliances patched on a normal cycle, is the real risk.
-
A researcher-recovered toolkit shows how one operator compromised over 14,500 Dahua cameras in five weeks using credential attacks, a decade-old auth bypass, and abuse of the vendor’s own cloud relay.
-
Blog & Articles
Is Penetration Testing Legal in the UK? Why Authorisation Is the Only Thing That Makes It So
Strip away the tooling and the reputation, and a penetration test technically matches the definition of a crime under the Computer Misuse Act. Here is why authorisation is the only …
-
A record 93 active ransomware groups sounds alarming, but Q2 2026 data suggests ransomware market fragmentation is a sign of pressure, not strength.