Cyber Essentials Has Record Year but Takeup Remains Low
New government figures reveal a 20% annual increase in certifications
20 articles
New government figures reveal a 20% annual increase in certifications
An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media person...
Users of the GPT4Free hosted platform might believe they are directly interacting with the selected artificial intelligence model in its web interface. Howev...
Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agen...
A new CVE drops. Your scanner finds it.
The FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running “booter” operations in existence. ...
The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. ...
The U.S.
The Internet Systems Consortium (ISC) has released BIND 9.20.
Cisco urged ISE customers to apply a software update, as well as check for signs of exploitation
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
China-aligned advanced persistent threat group FamousSparrow has replaced its long-running SparrowDoor implant with a new modular C++ backdoor, SparroWocky, ...
The U.S.
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon ...
A post-exploitation technique that lets attackers with root-level access to a Kubernetes node steal workload identities issued through SPIFFE/SPIRE and imper...
Quick Answer: DSPM has the scariest pricing curve in security bills track data volume, and data only grows. Microsoft Purview publishes pay-as-you-go rates (...
Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an au...
AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came a...
Cisco has issued an urgent security advisory regarding a critical authentication-bypass vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE P...
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in atta...