Fixing what a pen test found is only half the job. Here’s how to prioritise remediation, and why retesting is what actually proves the fix worked.
vulnerability management
-
-
The Cisco ISE patch for CVE-2026-76460 isn’t optional. A step-by-step plan for checking versions, patching, and spotting prior compromise.
-
Penetration testing as a service and traditional pen testing solve different problems. A practical comparison to help UK businesses pick the right one.
-
A critical Cisco email gateway vulnerability shows why perimeter security appliances need the same scrutiny and testing as the applications they protect.
-
What a software supply chain attack actually looks like, why the numbers are rising fast, and a priority-ordered checklist UK businesses can act on this quarter.
-
CISA has added five actively exploited vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS to its watch list this week.
-
A maximum-severity path traversal flaw in GitLab’s repository commits API is being scanned within hours of disclosure. Here’s what happened and what self-managed users need to check.
-
IT teams drown in critical CVSS scores every month. Here’s what the score actually measures, how to read the severity bands, and how to prioritise patching when everything looks urgent.
-
A practical order for tackling this month’s 974 Patch Tuesday vulnerabilities, from the two already-exploited bugs to your e-commerce platform.
-
A zero-day vulnerability is a flaw attackers exploit before a fix exists. Here is what that means in practice and how UK businesses should respond.