Splunk's 9.8 RCE: What a Logging Tool Vulnerability Means for UK Small Business Supply Chains
Splunk has a 9.8-rated unauthenticated remote code execution flaw. You probably don't run Splunk. Your MSP might. That's the problem.
Read more →582 articles · Page 6 of 30
Splunk has a 9.8-rated unauthenticated remote code execution flaw. You probably don't run Splunk. Your MSP might. That's the problem.
Read more →
AI-powered phishing is scaling faster than organisations can train against it. Three stories today that UK SMBs cannot afford to ignore.
Read more →
A high-volume ransomware operation with Russian-speaking roots and an AI-powered phishing platform impersonating trusted brands. Both are active today.
Read more →
478 victims, worm-like spread, and a BitLocker bypass that works on patched Windows. This week's threats are not theoretical. Here is the brief.
Read more →
No credentials required. A WordPress plugin flaw published yesterday lets unauthenticated attackers create admin accounts. Here is what to do before lunch.
Read more →
Three Windows zero-days, an Exchange Server exploit in the wild, and Ivanti Sentry bugs that score a perfect 10. Today's patches are not optional.
Read more →
Microsoft's biggest-ever Patch Tuesday, a critical Veeam backup flaw, and a WordPress plugin that hands attackers your server. Three stories. One to-do list.
Read more →
Attackers bypassed Check Point VPN passwords in the wild before a patch existed. If your remote access still runs IKEv1, you are already compromised.
Read more →
Cisco SD-WAN and SolarWinds Serv-U are both being actively exploited this week. One has no patch. Here is the data, stripped of vendor spin.
Read more →
Two active campaigns are hitting organisations that look exactly like UK SMBs. One calls your staff pretending to be IT support. The other fakes LinkedIn and Indeed.
Read more →
CISA just added two actively exploited flaws to its KEV catalog. If you run WordPress or Magento, you are in the crosshairs today.
Read more →
Three separate threat streams converging today, and all three have direct exposure for UK SMBs and their IT suppliers.
Read more →
Three active threats converging on UK SMBs today: a mass phishing platform bypassing MFA, a RAT delivered via Microsoft Teams, and two unpatched maximum-severity router vulnerabilities.
Read more →
Two WordPress flaws scored 9.8. An unpatched Windows credential leak has no CVE number. Here is what UK small businesses need to act on this week.
Read more →
Three active threats that UK SMBs need to act on today: a Java RAT delivered via Microsoft Teams, a two-year-old Oracle flaw now on the CISA KEV list, and 33 malicious npm packages stealing cloud credentials.
Read more →
Attackers are actively exploiting a critical Windows Netlogon flaw. No login required. One packet and your domain controller is compromised.
Read more →
Patch windows have closed. Both the Windows Netlogon RCE and Palo Alto GlobalProtect auth bypass are now being exploited in the wild. Here is what that means for your business.
Read more →
Palo Alto's GlobalProtect VPN has a confirmed authentication bypass under active exploitation. If you haven't patched, your network perimeter is already open.
Read more →
Fake Fortinet patches, AI-driven database raids, and a WordPress plugin handing out admin rights to strangers. Three stories that matter this week.
Read more →
Three active threats converge today: a FortiClient EMS zero-day delivering infostealers, a PhaaS kit with MFA bypass, and AI-assisted espionage campaigns lowering the barrier for every attacker downstream.
Read more →