CISA has flagged a Fortinet FortiOS patch bypass as actively exploited. If your firewall ran a vulnerable version, patching alone may not be the whole story. Here is what to check.
September 13, 2026
Security Updates & Threats
CVE-2026-34486 is actively exploited by an AI-automated attack campaign targeting Apache Tomcat servers. Find out if your business is at risk and what to patch immediately.
September 12, 2026
Security Updates & Threats
A critical unpatched vulnerability (CVE-2026-57807, CVSS 9.8) in the miniOrange WordPress OAuth SSO plugin lets attackers log in as administrator with no password. Here is what site owners need to do immediately.
September 6, 2026
Security Updates & Threats
A deliberate backdoor in version 10.8.7 of the popular ARVE WordPress plugin lets attackers log in as an administrator without a password. Here is what to check and what to do.
September 5, 2026
Security Updates & Threats
Microsoft 365 went down for 12 hours on 31 August, the third outage of 2026. Here is what to do when it happens, and how to keep your business running next time.
September 1, 2026
Blog
A critical unauthenticated vulnerability in WordPress Core, nicknamed wp2shell, is being actively exploited. If you run a WordPress site, check and update to version 6.9.5 or 7.0.2 immediately.
August 30, 2026
Security Updates & Threats
A critical SharePoint Server vulnerability patched in May 2026 is now being used in active ransomware campaigns. Here is what happened, who is at risk, and how to check your patch status now.
August 29, 2026
Security Updates & Threats
A practical guide to building a business continuity plan for your UK business: BIA, RTO/RPO and minimum viable operations, dependency mapping, recovery strategies, testing, plus a free editable BCP and BIA toolkit.
August 26, 2026
Security Updates & Threats