An insider threat comes from anyone with legitimate access to your systems, whether they mean harm or not. Here’s how to spot one and reduce your risk.
Rebecca Sutton
Rebecca Sutton
Rebecca is a dedicated cybersecurity writer who specialises in transforming complex technical concepts into clear, accessible content. With a strong background in IT and a passion for digital security, she produces insightful articles, guides, and thought-pieces that bridge the gap between technical experts and wider audiences.
-
-
A shrinking red number on a scanner dashboard is not vulnerability management. Here is what the process actually requires, and NCSC’s own patch deadlines.
-
A critical Keycloak password reset flaw let unauthenticated attackers seize any account, admins included. Here is what happened and what to patch now.
-
WilmerHale paid at least $18 million and Goodwin Procter around $10 million to the Luna Moth extortion group, which broke in using phone calls and fake IT visits rather than …
-
A chain of five vulnerabilities in the Markdown Preview Enhanced VS Code extension let a crafted markdown file write to files on a developer’s machine. All five are now patched.
-
A critical Forminator plugin vulnerability lets attackers upload malicious files without logging in. Here is a quick checklist to find out if your site is exposed.
-
A single attacker has spent 17 months scraping Salesforce and ServiceNow customer portals worldwide, not by exploiting a flaw but by using guest user permissions exactly as they were configured.
-
The critical NetScaler authentication bypass, CVE-2026-19490, was routine to fix. The pattern behind it, of gateway appliances patched on a normal cycle, is the real risk.
-
A researcher-recovered toolkit shows how one operator compromised over 14,500 Dahua cameras in five weeks using credential attacks, a decade-old auth bypass, and abuse of the vendor’s own cloud relay.
-
Blog & Articles
Is Penetration Testing Legal in the UK? Why Authorisation Is the Only Thing That Makes It So
Strip away the tooling and the reputation, and a penetration test technically matches the definition of a crime under the Computer Misuse Act. Here is why authorisation is the only …