Nation-State Attacks on UK Critical Infrastructure
Hostile states are behind three-quarters of attacks on Britain's critical national infrastructure, according to NCSC CEO Richard Horne.
The traditional model of finding and patching vulnerabilities is no longer effective, prompting a shift towards risk-based disclosure and prioritization.
Hostile states are behind three-quarters of attacks on Britain's critical national infrastructure, according to NCSC CEO Richard Horne.
Google will start using IP addresses for ad measurement and personalization in the EU, UK, and Switzerland on or after August 3, 2026, requiring user consent under UK and EU law.
Account takeover attacks are increasing due to complexity in managing identities, with 22% of breaches in 2025 resulting from credential abuse.
A data leak known as FortiBleed has exposed Fortinet and FortiGate VPN credentials for 73,932 devices worldwide, potentially allowing attackers to access internal networks.
Researchers found dozens of security vulnerabilities in Anthropic's Claude Code, highlighting the challenges of securing AI models with rapid update cycles.
The U.S. Federal Trade Commission (FTC) reports that Americans lost $3.5 billion to imposter scams in 2025, with social media being the most cost-effective attack vector.
Artificial intelligence is being used across the security landscape, with both benefits and risks, and its misuse by insiders and exploitation by cyber adversaries is a growing concern.
India temporarily blocked Telegram to prevent cheating in the nationwide medical entrance exam, affecting millions of users, amid allegations of leaked question papers.
A critical vulnerability in SimpleHelp remote management software, tracked as CVE-2026-48558, allows unauthenticated attackers to create privileged technician accounts on servers using OpenID Connect authentication.