CISA has added five actively exploited vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS to its watch list this week.
Rebecca Sutton
Rebecca Sutton
Rebecca is a dedicated cybersecurity writer who specialises in transforming complex technical concepts into clear, accessible content. With a strong background in IT and a passion for digital security, she produces insightful articles, guides, and thought-pieces that bridge the gap between technical experts and wider audiences.
-
-
An insider threat comes from someone who already has legitimate access to your systems. Here’s what the main types are, what they cost, and how to reduce your risk.
-
Banning shadow IT rarely works. Here’s why the NCSC recommends a no-blame approach, what actually reduces unsanctioned tech, and how it changes what your penetration test should cover.
-
A maximum-severity path traversal flaw in GitLab’s repository commits API is being scanned within hours of disclosure. Here’s what happened and what self-managed users need to check.
-
IT teams drown in critical CVSS scores every month. Here’s what the score actually measures, how to read the severity bands, and how to prioritise patching when everything looks urgent.
-
PSTI compliance bans default passwords and demands update transparency, but government testing shows compliant devices can still fail badly under real testing.
-
Thinking about commissioning container penetration testing? What it covers, how it compares to a cloud pentest, what drives cost, and what to ask a provider first.
-
New firewall and VPN vulnerabilities in Cisco, Citrix and Fortinet gear are under active attack. A step-by-step checklist for IT managers without a dedicated security team.
-
Two pentest quotes, three times the price difference. Here’s how to tell a genuine manual penetration test from an automated scan with a PDF wrapper.
-
Blog & Articles
Attack Surface Management Won’t Replace Your Penetration Test, Whatever the Sales Pitch Says
Attack surface management shows you what you expose. Penetration testing shows you what an attacker can do with it. Here is why one cannot substitute for the other.