A critical GitLab GraphQL vulnerability let unauthenticated attackers delete public repositories, and researchers saw real exploitation attempts within two days of the patch shipping.
News
-
-
TikTok’s $400 million COPPA settlement points to specific, checkable failures. Here’s how UK businesses can audit their own child data compliance before a regulator asks.
-
Have I Been Pwned onboarded Sri Lanka CERT as its 48th free government subscriber. For UK businesses, the story is about who watches your exposed staff logins, and what they …
-
Five WordPress plugins and themes were hit by critical, no-login-required flaws this week. Here is a plain checklist for checking your own site, whether you run any of them or …
-
A PaperCut vulnerability chain let attackers bypass login and run code on print servers, and the vendor needed a second emergency patch after the first one was bypassed.
-
Two quotes, two different labels: one for “ethical hacking”, one for a “penetration test”. Here’s how to tell what you’re actually buying before you sign.
-
The NCSC has warned about internet-exposed edge devices three times since April. The failures are basic. The problem is nobody owns fixing them.
-
CVE-2026-21962 scores a perfect 10 on the CVSS scale and has been under active, automated attack since January. Here’s what it does and how to check if you’re exposed.
-
A critical Keycloak password reset flaw let unauthenticated attackers seize any account, admins included. Here is what happened and what to patch now.
-
WilmerHale paid at least $18 million and Goodwin Procter around $10 million to the Luna Moth extortion group, which broke in using phone calls and fake IT visits rather than …