Critical WordPress Vulnerability Under Active Attack

A critical WordPress vulnerability is being actively exploited to take over websites, and if you run a WordPress site it needs your...

August 13, 2026

Security Updates & Threats
Critical WordPress Vulnerability Under Active Attack
Law Firm Cyber Security: Lessons From the NCSC Report

The National Cyber Security Centre (NCSC) has published a cyber threat report aimed specifically at UK law firms, and it is relevant...

August 9, 2026

Security Updates & Threats
Law Firm Cyber Security: Lessons From the NCSC Report
Critical WordPress Plugin Lets Hackers In as Admin

A critical flaw in the miniOrange OAuth SSO plugin (CVSS 9.8) lets unauthenticated attackers log in as WordPress administrator with no password. No official patch has been released. Here is what to do right now.

August 8, 2026

Security Updates & Threats
Critical WordPress Plugin Lets Hackers In as Admin
CISA Flags Actively Exploited N-able N-central Flaw: What MSPs and RMM Users Need to Know

CISA has added CVE-2026-18577, an actively exploited auth bypass in N-able N-central, to its Known Exploited Vulnerabilities catalog. Here's what happened and why it matters even if you don't use N-central.

August 6, 2026

Blog
CISA Flags Actively Exploited N-able N-central Flaw: What MSPs and RMM Users Need to Know
Beacon CRM Breach: What UK Charities (and Any Organisation Using a Third-Party CRM) Need to Do Now

Beacon CRM, used by over 1,500 UK charities, has confirmed a breach where database backups were likely downloaded by an unauthorised third party. Here's what happened and how to defend against this kind of supply-chain attack.

August 5, 2026

Blog
Beacon CRM Breach: What UK Charities (and Any Organisation Using a Third-Party CRM) Need to Do Now
AI Scams: Deepfakes, Voice Clones and Smarter Phishing

For years, the standard advice for spotting a scam was to look for the tell-tale signs: clumsy grammar, an odd email address,...

August 4, 2026

Security Updates & Threats
AI Scams: Deepfakes, Voice Clones and Smarter Phishing
NCSC Alert: State Hackers Stealing Email Without Any Clicks

The NCSC has joined agencies from 14 partner nations to warn of a Russian state-backed group called LAUNDRY BEAR, which steals business emails using a zero-click attack in Zimbra webmail. Here is what UK businesses need to know and do.

August 2, 2026

Security Updates & Threats
NCSC Alert: State Hackers Stealing Email Without Any Clicks
July Patch Tuesday: 570 Fixes and Two Zero-Days

Microsoft's July 2026 Patch Tuesday is the largest security update in the company's history, fixing more than 570 vulnerabilities including two actively exploited zero-days affecting Windows systems used across the UK.

August 1, 2026

Security Updates & Threats
July Patch Tuesday: 570 Fixes and Two Zero-Days