CVE-2026-9586 shows how a mundane coding mistake in Sangoma’s Switchvox platform exposed thousands of businesses that never patch their phone systems.
Rebecca Sutton
Rebecca Sutton
Rebecca is a dedicated cybersecurity writer who specialises in transforming complex technical concepts into clear, accessible content. With a strong background in IT and a passion for digital security, she produces insightful articles, guides, and thought-pieces that bridge the gap between technical experts and wider audiences.
-
-
Vendors sell badges, but no accredited penetration testing certificate exists. What a proper report and attestation letter contain, and why the distinction matters at audit time.
-
Cyber Essentials is a self-signed questionnaire. Cyber Essentials Plus is what happens when someone actually checks it. An honest look at what each proves, what CE+ tests, and who really …
-
SonicWall’s second exploited SMA zero-day chain this year is a reminder that perimeter VPN appliances need testing and hardening, not just a patch cycle.
-
CBEST and STAR-FS grab the headlines, but most FCA-regulated firms need a different answer. Here is what operational resilience testing actually requires if you’re not a systemically important bank.
-
The 2025 OWASP Top 10 is a solid, data-driven baseline for web application risk. Here’s what changed since 2021, and why it should be a floor, not a ceiling.
-
Why framing in-house vs outsourced penetration testing as an either-or choice misses the point, and the hybrid model most UK businesses should actually run.
-
A critical GitLab GraphQL vulnerability let unauthenticated attackers delete public repositories, and researchers saw real exploitation attempts within two days of the patch shipping.
-
A practical guide to choosing between SAST, DAST and penetration testing, based on what you actually run, what you need to prove, and where to spend your first pound of …
-
TikTok’s $400 million COPPA settlement points to specific, checkable failures. Here’s how UK businesses can audit their own child data compliance before a regulator asks.