Three threats, no comfortable answers. PaperCut is being exploited right now, your helpdesk impersonators have a new backdoor, and your office router may already be compromised.
Three vulnerabilities confirmed actively exploited in 48 hours. One lets attackers read, modify, or delete any file without a password. The data speaks for itself.
The NCSC is warning about internet-exposed systems again. Manchester Airports Group has lost 8.7 million customer records. And Teams vishing is now a structured initial access business.
Active exploitation confirmed. Microsoft SQL Server, WordPress Avada, and Gitea are all under attack right now. Here is what UK small businesses need to do before Friday.
Three active threats converging today: ClickFix malware delivery, a Check Point firewall bypass being exploited in the wild, and a Zimbra RCE campaign that has already claimed 270 servers.
Four CVSS 9.8 vulnerabilities landed this week in libraries your web tools probably use. Corrine breaks down what the intelligence says and what to do by Friday.
Two actively exploited vulnerabilities and a sophisticated vishing campaign targeting Microsoft 365. Today's briefing covers what the advisories are not telling you.
TrueConf is being actively exploited right now. Microsoft dropped four CVSS 10.0 flaws in Azure and Exchange. Your business needs to act today, not next week.
Three distinct threats landed today. One is CISA-confirmed actively exploited. One is knocking on Europe's door via Android. None of them care how small your business is.
Three threats converging today: a CISA-confirmed Windows RCE being exploited right now, Clop back with purpose-built data-theft tooling, and a phishing-as-a-service platform with over 4,000 confirmed victims.
Three actively exploited vulnerabilities landed on CISA's confirmed list overnight. Here is what they mean for your business and what to do before Friday.
CISA has confirmed ransomware gangs are exploiting a Windows Task Host flaw. Separately, Microsoft Copilot has a command injection vulnerability that can leak your data. Both affect UK SMBs today.
600,000 WordPress sites are vulnerable to unauthenticated remote code execution. A new botnet is turning unpatched routers into criminal infrastructure. This week's brief.