CVE-2026-48282 is being exploited in the wild. Meanwhile, a criminal group called Pink is ringing your staff and talking their way past MFA. Here is what both mean for your business.
Three active campaigns with direct UK SMB exposure: a sophisticated M365 phishing platform, a legal-lure ransomware framework, and a residential proxy botnet the FBI just cracked open.
A SharePoint vulnerability is being actively exploited right now. CISA confirmed it. Microsoft sat on the disclosure for weeks. Here is what you need to know.
The ICO is not hiding in a hedge outside your office. The real danger is inside your business: missing breach processes and data nobody can account for.
SharePoint has a confirmed, actively-exploited code execution flaw. CISA added it to the KEV list yesterday. If your business uses SharePoint, read this now.
A maximum-severity flaw in SimpleHelp RMM is being actively exploited. Attackers are walking straight through your MSP's front door. Here is what that means for your business.
Ransomware gangs are now exploiting a Windows Defender privilege escalation flaw confirmed by CISA. If your MSP uses SimpleHelp, you have a second problem to deal with today.
The Data Use and Access Act 2025 clarifies that direct marketing can be a legitimate interest. The data broker industry is delighted. You should pay attention.
Oracle's E-Business Suite is being actively exploited right now. And a new initial access broker is turning legitimate websites into malware delivery points.
Companies House, the open electoral register, and LinkedIn combine into a director profile any attacker can build in under 20 minutes. Here is the full picture.
KEV is not interesting. It is known exploited. Turning the catalogue into a five-minute weekly check is the cheapest security upgrade most SMBs can make.
Green boxes and vibes have become the native language of weak assurance. A dashboard that cannot tell busy from dangerous is not security. It is confetti.