Active exploitation of Drupal's SQL injection flaw began within 48 hours of disclosure. If your website or your supplier's runs Drupal, this is not a drill.
A social engineering phone call. A password reset. £300 million in losses. The M&S DragonForce attack is the most expensive lesson in UK retail cyber security history.
A malware-signing service is making ransomware harder to detect. npm packages with millions of downloads are compromised. And Cisco just patched a perfect-10 vulnerability.
TPM plus PIN BitLocker is one Group Policy change, one command per device, and a Tuesday of user communication. The whole job fits in two weeks. Here is how.
A days-old NGINX vulnerability is already being probed and exploited. Grafana's source code was stolen via a single access token. Two stories, one theme: patch windows are collapsing.
Two weeks ago we swallowed the 43% headline whole. Today, having read every page of the CSBS 2025/2026, here is what we should have told you the first time.
BitLocker is on, so we're fine. Five days after YellowKey dropped, that sentence has become a confession. Here is what the default actually protects against.
Every business owner who chose the cheaper IT quote just made an insurance decision. They did not know that. Most of them still do not. That is the whole problem.
Three active threats converge today: an exploited Exchange zero-day, a surge in device code phishing targeting Microsoft 365, and a supply chain attack that caught OpenAI. All three have direct implications for UK SMBs.
Three critical flaws landed overnight. WordPress sites, Microsoft Authenticator, and on-premises email are all in the frame. Here is the data, without the spin.