Milton Keynes Office - 01908 880498
Aardwolf Security
  • Security Testing
    • Web Application Penetration Test
    • API Penetration Testing
    • Network Penetration Testing
      • Internal Network Penetration Testing
      • External Network Penetration Testing
    • Mobile Application Penetration Testing
      • Android Penetration Testing
      • iOS Application Penetration Testing
    • Vulnerability Scanning Services
    • Firewall Configuration Review
    • Red Team Assessment
    • Server Build Review
    • Social Engineering
    • Secure Code Review
    • Database Configuration Review
    • Automotive Penetration Testing
    • ATM Penetration Testing
    • Cyber Essentials Services
    • WiFi Penetration Testing
  • Cloud Testing
    • Azure Penetration Testing
    • AWS Secure Cloud Config Review
    • Google Secure Cloud Review
  • Contact Us
  • About Us
  • Articles
  • News
Category:

News

  • News

    MFA Bypass Phishing: What the Kratos Takedown Teaches Every Microsoft 365 User

    by Rebecca Sutton July 23, 2026
    by Rebecca Sutton July 23, 2026

    The Kratos phishing kit stole Microsoft 365 session cookies to bypass MFA entirely. Here’s exactly how that attack works, and the practical steps that actually reduce the risk.

    FacebookTwitterLinkedinEmail
  • News

    GlobalProtect Authentication Bypass: A Checklist While Qilin Ransomware Still Exploits It

    by Rebecca Sutton July 22, 2026
    by Rebecca Sutton July 22, 2026

    A May 2026 GlobalProtect authentication bypass is still being used by Qilin ransomware affiliates. Here’s how to confirm you’re patched, mitigate if you’re not, and spot signs of prior compromise.

    FacebookTwitterLinkedinEmail
  • News

    AI Agent Cyberattack at Hugging Face: What Your Business Should Check Now

    by Rebecca Sutton July 21, 2026
    by Rebecca Sutton July 21, 2026

    Hugging Face was breached by an autonomous AI agent that logged 17,000 actions in a weekend. Here’s the practical checklist any business can run against the same weaknesses.

    FacebookTwitterLinkedinEmail
  • News

    F5 Calls It “Major”. A Researcher Says It Bypasses ASLR. Who’s Right About NGINX?

    by Rebecca Sutton July 20, 2026
    by Rebecca Sutton July 20, 2026

    F5’s nginx severity rating for CVE-2026-42533 is ‘Major’, but a researcher argues it enables an ASLR bypass. Vendor labels aren’t the last word on risk.

    FacebookTwitterLinkedinEmail
  • News

    SharePoint’s Zero-Day Pattern Is a Warning UK Businesses Keep Ignoring

    by Rebecca Sutton July 18, 2026
    by Rebecca Sutton July 18, 2026

    The new SharePoint zero-day vulnerability follows a pattern that patching alone won’t fix: a chained attack that steals server keys before the update ever lands.

    FacebookTwitterLinkedinEmail
  • News

    Zoom Account Takeover Flaw: Are You Affected, and What to Patch Now

    by Rebecca Sutton July 17, 2026
    by Rebecca Sutton July 17, 2026

    A step-by-step guide to Zoom’s critical Windows account takeover vulnerability: which products are affected, whether it’s being exploited, and what to patch first.

    FacebookTwitterLinkedinEmail
  • News

    SonicWall SMA 1000 Zero-Days Are Being Exploited Right Now

    by Rebecca Sutton July 16, 2026
    by Rebecca Sutton July 16, 2026

    Two SonicWall SMA 1000 zero-days are under active attack. Here is what CVE-2026-15409 and CVE-2026-15410 let an attacker do, and what to patch first.

    FacebookTwitterLinkedinEmail
  • News

    Microsoft Rated Its Own Exploited Flaw ‘Medium’. Stop Trusting Vendor Severity Scores

    by Rebecca Sutton July 15, 2026
    by Rebecca Sutton July 15, 2026

    A SharePoint bug rated 5.3 by Microsoft and 9.8 by NVD is already under active attack. Vendor severity ratings are falling behind AI-accelerated exploits.

    FacebookTwitterLinkedinEmail
  • News

    CISA’s GitHub Leak Wasn’t the Real Failure. Nine Ignored Alerts Were

    by Rebecca Sutton July 14, 2026
    by Rebecca Sutton July 14, 2026

    A contractor exposing CISA’s credentials on GitHub is the easy story. The nine ignored security alerts that followed reveal the failure worth fixing.

    FacebookTwitterLinkedinEmail
  • News

    Critical Zimbra Webmail Flaw Lets a Single Email Hijack a User’s Session

    by Rebecca Sutton July 13, 2026
    by Rebecca Sutton July 13, 2026

    Google’s Threat Analysis Group found a critical Zimbra XSS vulnerability in the Classic Web Client that lets a crafted email hijack a live session. Zimbra has patched it in version …

    FacebookTwitterLinkedinEmail
Newer Posts
Older Posts

Penetration Testing Services

Services Offered

  • Android Penetration Testing
  • ATM Penetration Testing
  • Cloud Penetration Testing
    • AWS Secure Cloud Config Review
    • Azure Penetration Testing
    • Google Secure Cloud Review
  • Cyber Essentials Services
  • Database Configuration Review
  • Mobile Application Penetration Testing
    • iOS Application Penetration Testing
  • Newsletter
  • Security Testing
    • API Penetration Testing
    • Automotive Penetration Testing
    • Firewall Configuration Review
    • Network Penetration Testing
      • External Network Penetration Testing
      • Internal Network Penetration Testing
    • Red Team Assessment
    • Secure Code Review
    • Server Build Review
    • Social Engineering
    • Vulnerability Scanning Services
    • Web Application Penetration Test
  • Sign Up To Our Newsletter
  • Terms and Conditions
  • WiFi Penetration Testing

Address & Telephone Number

Aardwolf Security Ltd

Suite 20
548-550 Elder House
Elder Gate
Milton Keynes
MK9 1LR

Tel – 01908 880498
Email – contact@aardwolfsecurity.com

 

Aardwolf Security Ltd are registered in England and Wales.

Company number: 09464876

VAT registration No: GB-300106778

 

Penetration testing services

Recent Posts

  • MFA Bypass Phishing: What the Kratos Takedown Teaches Every Microsoft 365 User
  • GlobalProtect Authentication Bypass: A Checklist While Qilin Ransomware Still Exploits It
  • AI Agent Cyberattack at Hugging Face: What Your Business Should Check Now
  • F5 Calls It “Major”. A Researcher Says It Bypasses ASLR. Who’s Right About NGINX?
  • SharePoint’s Zero-Day Pattern Is a Warning UK Businesses Keep Ignoring
  • Zoom Account Takeover Flaw: Are You Affected, and What to Patch Now

Services Offered

  • Web Application Penetration Test
  • API Penetration Testing
  • Network Penetration Testing
  • Vulnerability Scanning Services
  • Cloud Penetration Testing
  • Mobile Application Penetration Testing
  • Red Team Assessment
  • Vulnerability Scanning Services
  • Facebook
  • Twitter
  • Linkedin
  • Youtube
  • Github

© Aardwolf Security 2026. All rights reserved. | Privacy Policy | Terms and Conditions

Aardwolf Security
  • Security Testing
    • Web Application Penetration Test
    • API Penetration Testing
    • Network Penetration Testing
      • Internal Network Penetration Testing
      • External Network Penetration Testing
    • Mobile Application Penetration Testing
      • Android Penetration Testing
      • iOS Application Penetration Testing
    • Vulnerability Scanning Services
    • Firewall Configuration Review
    • Red Team Assessment
    • Server Build Review
    • Social Engineering
    • Secure Code Review
    • Database Configuration Review
    • Automotive Penetration Testing
    • ATM Penetration Testing
    • Cyber Essentials Services
    • WiFi Penetration Testing
  • Cloud Testing
    • Azure Penetration Testing
    • AWS Secure Cloud Config Review
    • Google Secure Cloud Review
  • Contact Us
  • About Us
  • Articles
  • News