Companies House is a mandatory, public, searchable director database that attackers use daily. The government built it, mandates it, and shrugs at what follows.
What do UK data brokers actually hold on a small business director? Lucy Harper investigates using public records, enforcement history, and ICO documentation.
Three stories today that together explain exactly how UK SMBs get compromised in 2026. One is a patched vulnerability nobody patched. One is a £3,900-a-month RAT. One is a CC field.
A Defender zero-day with public exploit code, a Vidar infostealer surge hitting developer toolchains, and a quiet but significant change to Cyber Essentials Plus certification.
CVSS 9.8. No authentication required. A WordPress plugin flaw published yesterday lets attackers run arbitrary code on your server. Here is what it means.
Two max-severity vulnerabilities are being actively exploited right now. If your office runs Ubiquiti kit or any ColdFusion-backed web infrastructure, read this first.
CVE-2026-48282 is being exploited in the wild. Meanwhile, a criminal group called Pink is ringing your staff and talking their way past MFA. Here is what both mean for your business.
Three active campaigns with direct UK SMB exposure: a sophisticated M365 phishing platform, a legal-lure ransomware framework, and a residential proxy botnet the FBI just cracked open.
A SharePoint vulnerability is being actively exploited right now. CISA confirmed it. Microsoft sat on the disclosure for weeks. Here is what you need to know.
The ICO is not hiding in a hedge outside your office. The real danger is inside your business: missing breach processes and data nobody can account for.
SharePoint has a confirmed, actively-exploited code execution flaw. CISA added it to the KEV list yesterday. If your business uses SharePoint, read this now.
A maximum-severity flaw in SimpleHelp RMM is being actively exploited. Attackers are walking straight through your MSP's front door. Here is what that means for your business.
Ransomware gangs are now exploiting a Windows Defender privilege escalation flaw confirmed by CISA. If your MSP uses SimpleHelp, you have a second problem to deal with today.
The Data Use and Access Act 2025 clarifies that direct marketing can be a legitimate interest. The data broker industry is delighted. You should pay attention.