570 Microsoft patches. A Windows zero-day PoC published hours later. A building automation protocol now on the CISA KEV list. This week is not one to ignore.
Hello, Mauven here. The Upper Tribunal dismissed the ICO's Experian appeal in April 2024. Here is what the outcome signals about UK data broker regulation.
Three stories today that UK SMBs cannot afford to ignore: SharePoint flaws being actively exploited, a sophisticated AiTM phishing operation, and a poisoned npm supply chain.
The NCSC has joined a Nine-Eyes advisory on Russian state actors targeting poorly configured routers. Meanwhile, Progress ShareFile has ordered an emergency server shutdown over an undisclosed threat.
Next week Mauven MacLeod joins to break down the social engineering chain. How attackers turn a public profile into a targeted attack before sending anything.
Companies House is a mandatory, public, searchable director database that attackers use daily. The government built it, mandates it, and shrugs at what follows.
What do UK data brokers actually hold on a small business director? Lucy Harper investigates using public records, enforcement history, and ICO documentation.
Three stories today that together explain exactly how UK SMBs get compromised in 2026. One is a patched vulnerability nobody patched. One is a £3,900-a-month RAT. One is a CC field.
A Defender zero-day with public exploit code, a Vidar infostealer surge hitting developer toolchains, and a quiet but significant change to Cyber Essentials Plus certification.
CVSS 9.8. No authentication required. A WordPress plugin flaw published yesterday lets attackers run arbitrary code on your server. Here is what it means.
Two max-severity vulnerabilities are being actively exploited right now. If your office runs Ubiquiti kit or any ColdFusion-backed web infrastructure, read this first.