A practitioner’s view on setting third party penetration testing requirements: what to ask suppliers and vendors for, how to tier them by risk, and where GDPR, ISO 27001 and PCI …
supply chain security
-
-
What a software supply chain attack actually looks like, why the numbers are rising fast, and a priority-ordered checklist UK businesses can act on this quarter.
-
A maximum-severity path traversal flaw in GitLab’s repository commits API is being scanned within hours of disclosure. Here’s what happened and what self-managed users need to check.
-
A practical action plan for UK businesses that have spotted NIS2 in an EU customer contract: what Article 21 expects from testing, how often, and what evidence to keep ready.
-
A critical GitLab GraphQL vulnerability let unauthenticated attackers delete public repositories, and researchers saw real exploitation attempts within two days of the patch shipping.
-
A chain of five vulnerabilities in the Markdown Preview Enhanced VS Code extension let a crafted markdown file write to files on a developer’s machine. All five are now patched.
-
The OWASP Top 10 was rebuilt for 2025. Here is what moved, what is new, and the questions worth asking before your next web application penetration test.
-
The Gentlemen ransomware group has claimed 478 victims — including a UK business used to breach a client — by exploiting unpatched VPN appliances and spending weeks inside networks before …