Have I Been Pwned onboarded Sri Lanka CERT as its 48th free government subscriber. For UK businesses, the story is about who watches your exposed staff logins, and what they …
data breach
-
-
WilmerHale paid at least $18 million and Goodwin Procter around $10 million to the Luna Moth extortion group, which broke in using phone calls and fake IT visits rather than …
-
A single attacker has spent 17 months scraping Salesforce and ServiceNow customer portals worldwide, not by exploiting a flaw but by using guest user permissions exactly as they were configured.
-
Origin Energy confirmed a data breach affecting millions of customer records, but the company learned of it from a reporter’s call, not its own monitoring. Here’s what that gap means …
-
A contractor exposing CISA’s credentials on GitHub is the easy story. The nine ignored security alerts that followed reveal the failure worth fixing.
-
A US county paid roughly $1 million to a group that never encrypted a single file, exposing how far data-theft extortion has moved beyond classic ransomware.
-
ShinyHunters exploited CVE-2026-35273 for nearly two weeks before Oracle published any advisory. The flaw is serious — but the disclosure gap is the structural failure that put 100 organisations at …
-
Blog & Articles
Why Penetration Testing is Essential Even if You’re ‘Checklist Secure’
by Williamby WilliamThe Illusion of ‘Checklist Secure’ Many organisations believe that adhering to security checklists means their digital assets are fully protected. But the debate of “Checklist Secure vs Penetration Testing” highlights …