Adblock for YouTube has a dormant script injection capability that its owners could activate with one server change. Here is what it means for your organisation and what to do …
News
-
-
Operation Endgame disrupted Amadey and StealC infrastructure on a significant scale. But with no arrests, the operators survive intact. Here is what that means for UK businesses building their security …
-
Two members of Scattered Spider have pleaded guilty over the 2024 TfL breach. The techniques they used are low-tech and still active. Here is what organisations can do to make …
-
Three ShapedPlugin Pro plugins served malware via official updates for three weeks. Updating the plugin is not enough — here is what site owners need to do.
-
The Squidbleed vulnerability in Squid Proxy leaks HTTP credentials from heap memory in every default installation. Here is how to check whether you are affected and what to do while …
-
The Gravity SMTP vulnerability (CVE-2026-4020) is being exploited at mass scale. But the real issue is structural: email plugins holding API keys create a risk that one permission bug can …
-
The Gentlemen ransomware gang ships an EDR killer framework to every affiliate, targeting 48 security products before encryption begins. Here are three practical checks every IT team should make this …
-
The FortiBleed Fortinet VPN breach compromised 74,000 firewalls, many running current firmware. The real failures were exposed management interfaces, legacy password hashing, and no MFA. Here is the harder lesson.
-
Three-quarters of UK critical infrastructure incidents last year were state-sponsored. Here is what the NCSC recommends and why most businesses are in the threat picture.
-
Three critical Fortinet FortiSandbox vulnerabilities are being actively exploited. Here is what your team needs to check, patch and verify before attackers get there first.