Two members of Scattered Spider have pleaded guilty over the 2024 TfL breach. The techniques they used are low-tech and still active. Here is what organisations can do to make …
News
-
-
Three ShapedPlugin Pro plugins served malware via official updates for three weeks. Updating the plugin is not enough — here is what site owners need to do.
-
The Squidbleed vulnerability in Squid Proxy leaks HTTP credentials from heap memory in every default installation. Here is how to check whether you are affected and what to do while …
-
The Gravity SMTP vulnerability (CVE-2026-4020) is being exploited at mass scale. But the real issue is structural: email plugins holding API keys create a risk that one permission bug can …
-
The Gentlemen ransomware gang ships an EDR killer framework to every affiliate, targeting 48 security products before encryption begins. Here are three practical checks every IT team should make this …
-
The FortiBleed Fortinet VPN breach compromised 74,000 firewalls, many running current firmware. The real failures were exposed management interfaces, legacy password hashing, and no MFA. Here is the harder lesson.
-
Three-quarters of UK critical infrastructure incidents last year were state-sponsored. Here is what the NCSC recommends and why most businesses are in the threat picture.
-
Three critical Fortinet FortiSandbox vulnerabilities are being actively exploited. Here is what your team needs to check, patch and verify before attackers get there first.
-
A now-patched Microsoft Copilot vulnerability let attackers steal emails, MFA codes and files with one click. The fix is in, but the underlying dynamic: AI tools with sweeping access inside …
-
A CDN-level supply chain attack backdoored over 1.2 million WordPress sites via OptinMonster, TrustPulse and PushEngage. Here is exactly what to check and how to clean up.