Citrix called CVE-2026-8452 a memory overflow. It turned out to be an unauthenticated root exploit, and that gap says something about how patch priority gets set.
Risk Management
-
-
The 2025 OWASP Top 10 is a solid, data-driven baseline for web application risk. Here’s what changed since 2021, and why it should be a floor, not a ceiling.
-
Threat modelling is how you work out where a system could be attacked before it’s built or tested. Here’s how it works, the main methodologies, and how it relates to …
-
A shrinking red number on a scanner dashboard is not vulnerability management. Here is what the process actually requires, and NCSC’s own patch deadlines.
-
Attackers weaponised a VMware vCenter flaw within five days of disclosure. That speed should change how businesses think about critical patching.
-
A 16-year-old hypervisor escape vulnerability in Linux KVM shows guest isolation is an assumption, not a fact. Here’s why that should change how you scope security testing.
-
As technology advances and digital transformation becomes more critical for businesses, cybersecurity threats are on the rise which highlights the importance of annual penetration testing. Companies must protect their data, …
-
Blog & Articles
Planning for a Penetration Test: A Guide for Prospective Clients
by Williamby WilliamIn today’s digital landscape, businesses of all sizes are facing increasing cybersecurity threats. Conducting a penetration test (or pen test) is an essential measure to assess and improve your organisation’s …