Compliance Week Done: What to Action This Weekend Before the GRC Finale
Compliance week is done. Here's what to action this weekend, and what's coming when we wrap the whole GRC series.
Read more →650 articles · Page 3 of 33
Compliance week is done. Here's what to action this weekend, and what's coming when we wrap the whole GRC series.
Read more →
Three threats, no comfortable answers. PaperCut is being exploited right now, your helpdesk impersonators have a new backdoor, and your office router may already be compromised.
Read more →
Three vulnerabilities confirmed actively exploited in 48 hours. One lets attackers read, modify, or delete any file without a password. The data speaks for itself.
Read more →
The NCSC is warning about internet-exposed systems again. Manchester Airports Group has lost 8.7 million customer records. And Teams vishing is now a structured initial access business.
Read more →
Active exploitation confirmed. Microsoft SQL Server, WordPress Avada, and Gitea are all under attack right now. Here is what UK small businesses need to do before Friday.
Read more →
CVSS 10.0. No user interaction required. Adobe Campaign Classic is being ripped apart this week, and WordPress sites are under active attack.
Read more →
The NCSC dealt with 204 nationally significant attacks last year. Richard Horne says the rate hasn't slowed down.
Read more →
Ubiquiti and Gitea vulnerabilities confirmed exploitable today. If your network runs UniFi or self-hosted Git, this is not one to park for next week.
Read more →
CVSS 9.8. Pre-authentication. Remote code execution as root. Your network hardware is the problem this week, and the data is brutal.
Read more →
24% of UK businesses have all five Cyber Essentials controls. Only 5% hold the certificate. Here's why that gap matters.
Read more →
Three active threats converging today: ClickFix malware delivery, a Check Point firewall bypass being exploited in the wild, and a Zimbra RCE campaign that has already claimed 270 servers.
Read more →
Four CVSS 9.8 vulnerabilities landed this week in libraries your web tools probably use. Corrine breaks down what the intelligence says and what to do by Friday.
Read more →
Two actively exploited vulnerabilities and a sophisticated vishing campaign targeting Microsoft 365. Today's briefing covers what the advisories are not telling you.
Read more →
A Teams-based phishing loader and a coordinated Rust supply chain attack are active today. Both have direct exposure paths for UK small businesses.
Read more →
TrueConf is being actively exploited right now. Microsoft dropped four CVSS 10.0 flaws in Azure and Exchange. Your business needs to act today, not next week.
Read more →
Three distinct threats landed today. One is CISA-confirmed actively exploited. One is knocking on Europe's door via Android. None of them care how small your business is.
Read more →
Your MSP uses software that can control every machine you own. This week, attackers proved they know it too.
Read more →
Three threats converging today: a CISA-confirmed Windows RCE being exploited right now, Clop back with purpose-built data-theft tooling, and a phishing-as-a-service platform with over 4,000 confirmed victims.
Read more →
Three actively exploited vulnerabilities landed on CISA's confirmed list overnight. Here is what they mean for your business and what to do before Friday.
Read more →
CISA has confirmed ransomware gangs are exploiting a Windows Task Host flaw. Separately, Microsoft Copilot has a command injection vulnerability that can leak your data. Both affect UK SMBs today.
Read more →