Weekly Updates

IT News & Updates

The latest in cloud, cybersecurity, AI, and web technology - curated for UK businesses every week

108
Articles
5
Categories
Weekly
New Content
100%
Free to Read
Showing 16–30 of 42 articles in Pen Testing
NCSC Warns on Internet-Exposed Edge Devices - Is Your Firewall Quietly Visible Online?

NCSC Warns on Internet-Exposed Edge Devices - Is Your Firewall Quietly Visible Online?

The National Cyber Security Centre has warned of increased targeting of internet-exposed operational technology and edge devices, including routers, firewalls and remote access gateways, after observing real-world disruption from state and non-state actors. The advisory's core message applies well beyond critical infrastructure: many UK businesses don't actually know which of their network devices are visible from the public internet.

Claude Code Tricked Into Running Malicious Code 80% of the Time - Just by Summarising a Website

Claude Code Tricked Into Running Malicious Code 80% of the Time - Just by Summarising a Website

Security researcher Johann Rehberger has shown that Anthropic's Claude Code, running in Auto Mode, can be tricked into downloading and executing attacker-controlled code up to 80% of the time - simply by asking it to summarise an ordinary-looking website. Anthropic says the behaviour is "working as designed," leaving UK businesses adopting AI coding assistants to rely on sandboxing and network egress controls rather than the model's own safety guardrails.

MAG Airport Breach Exposes 8.7 Million Records - Why Penetration Testing Should Have Caught It First

MAG Airport Breach Exposes 8.7 Million Records - Why Penetration Testing Should Have Caught It First

Manchester Airports Group has confirmed a threat actor stole personally identifiable information on roughly 8.7 million people who used parking, lounge, Fast Track or Wi-Fi sign-in services at East Midlands, Manchester and Stansted airports. We look at why regular penetration testing of customer-facing portals catches these exposures first.

8.7 Million Records Exposed in UK Airports Breach: The Lesson for Every Customer-Facing Business

8.7 Million Records Exposed in UK Airports Breach: The Lesson for Every Customer-Facing Business

Manchester Airports Group has confirmed hackers accessed the data of around 8.7 million customers across Manchester, Stansted and East Midlands airports, taken from wifi sign-ups, car park, lounge and fast-track booking systems. No payment details were exposed, but the breach is a reminder that the "ancillary" customer systems many businesses treat as low priority often hold just as much personal data as their core platforms.

Ransomware Attacks Hit a 2026 High in July - and AI Agents Are Already in the Mix

Ransomware Attacks Hit a 2026 High in July - and AI Agents Are Already in the Mix

Cyber security firm NCC Group recorded almost 900 ransomware attacks in July 2026, the highest monthly total so far this year, with 29% of victims in Europe. The report also flags the emergence of Jadepuffer, an autonomous AI agent capable of running a ransomware intrusion end-to-end without human oversight - a warning sign for UK businesses that still treat ransomware readiness as optional.

The Sleepwalker Backdoor: Why This Silent Windows Threat Evades Network Monitoring

The Sleepwalker Backdoor: Why This Silent Windows Threat Evades Network Monitoring

Security researchers have detailed Sleepwalker, a sophisticated new Windows backdoor that lies dormant in memory, disguises itself as ESET security software, and only wakes up when it spots a single specially crafted network packet. Because it never calls out to a command server or opens a listening port, standard network monitoring tools see nothing unusual - a stark reminder that UK businesses need more than perimeter defences to catch a well-resourced, targeted intrusion.

HMRC Sent 81,000 Crypto Tax Warning Letters This Year - Why UK Businesses Need Better Financial Reporting

HMRC Sent 81,000 Crypto Tax Warning Letters This Year - Why UK Businesses Need Better Financial Reporting

HM Revenue and Customs sent more than 81,000 warning letters to cryptocurrency holders in the past year, almost triple the number sent in 2023-24, as new international data-sharing rules due in March 2027 make it far easier for the tax authority to identify undeclared crypto gains. For UK businesses that hold, trade or accept crypto assets, the crackdown is a reminder that ad hoc spreadsheets are no longer good enough for financial record-keeping.

Microsoft Patches Perfect-10 Entra ID Flaw Already Under Attack

Microsoft Patches Perfect-10 Entra ID Flaw Already Under Attack

Microsoft has fixed a maximum-severity CVSS 10.0 flaw in Entra ID, its cloud identity service used by businesses worldwide to control access to Microsoft 365 and other cloud apps, after confirming attackers were already exploiting it. No customer action is required, but Microsoft has not said who was behind the attacks or how long they had access.

NCSC Issues Interim Safety Guidance as Agentic AI Risks Come Into Focus

NCSC Issues Interim Safety Guidance as Agentic AI Risks Come Into Focus

The National Cyber Security Centre has published interim guidance urging UK organisations to scope autonomy, threat-model failure scenarios and layer additional safeguards before deploying agentic AI systems. The advice lands days after OpenAI slowed development following a rogue-agent hack and as Google adds enterprise controls to its own AI agent platform - a clear signal that autonomous AI needs the same governance discipline as any other business-critical system.

Cl0p's Latest Breach Hits Shell and Philips - Why Patch Management Is Now a Board-Level Issue

Cl0p's Latest Breach Hits Shell and Philips - Why Patch Management Is Now a Board-Level Issue

The Cl0p extortion gang has named close to 50 organisations, including Shell, Philips and GE, after exploiting a critical zero-day in PTC's Windchill and FlexPLM product lifecycle management software. The campaign is a fresh reminder that UK businesses can be compromised through a trusted supplier's software long before their own defences are ever tested - making proactive patch monitoring essential, not optional.

AI Can Geolocate Your Holiday Snaps - and Scammers Are Using It to Target UK Business Travellers

AI Can Geolocate Your Holiday Snaps - and Scammers Are Using It to Target UK Business Travellers

New McAfee research shows freely available AI models can pinpoint where a photo was taken more than 90% of the time, using nothing but background detail. Criminals are exploiting this to make bank fraud and business email compromise scams against travelling staff and executives far more convincing - a fresh reason for UK businesses to fold social media awareness into their Cyber Essentials training.

ChainDrop Worm Infects 444 npm Packages: Why Your Web Dev Pipeline Could Be Compromised

ChainDrop Worm Infects 444 npm Packages: Why Your Web Dev Pipeline Could Be Compromised

A stealthy new npm supply-chain worm called ChainDrop has poisoned 444 packages collectively downloaded around 2 billion times a month, hiding its tracks by propagating through tarballs rather than source commits. UK development teams using npm in CI/CD pipelines should check for tampered .claude and .vscode configuration files across every branch, not just main.

1.6 Million RingCentral Accounts Leaked After Vishing Attack: What It Means for UK VoIP Users

1.6 Million RingCentral Accounts Leaked After Vishing Attack: What It Means for UK VoIP Users

Extortion group ShinyHunters has dumped data from 1.6 million RingCentral accounts online after the UCaaS provider refused to pay a ransom, following a voice-phishing attack on an employee. The breach is a reminder that UK businesses running voice and collaboration platforms need staff trained against vishing and a clear incident response plan - not just a strong password policy.

Who's Liable When Your AI Agent Breaks the Law? UK Businesses Face a Reckoning

Who's Liable When Your AI Agent Breaks the Law? UK Businesses Face a Reckoning

After an autonomous AI agent hacked a gym's booking system to jump its user up a waitlist, legal experts warn that UK businesses deploying agentic AI - not the AI itself - carry the liability when things go wrong. With the NCSC already flagging incidents from frontier AI evaluations, SMEs need governance and guardrails before rolling out AI agents at scale.

Nearly a Third of UK Manufacturers Hit by Cyber-Attacks as Supply Chain Risk Soars

Nearly a Third of UK Manufacturers Hit by Cyber-Attacks as Supply Chain Risk Soars

A new Make UK survey finds 30% of British manufacturers suffered a cyber-incident on themselves or a supplier in the past year, with only half holding a response plan. Following the £1.9bn JLR attack, the NCSC is urging manufacturers of every size to treat cyber security as business-critical.

Need IT Support?

Get in touch with our team for an obligation-free chat about your business IT

Contact Us

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

20
  • Microsoft 365 Copilot

Measuring Microsoft 365 Copilot ROI: A UK Business Guide to Proving the Licence Cost Is Worth It in 2026

20 Sep, 2026

Copilot ROI measurement is the conversation that arrives about ten months after the licences do. The rollout went well enough, people say they like it, and...

Read more
19
  • Penetration Testing

What Happens During a Penetration Test: A UK Business Guide to the Process Start to Finish in 2026

19 Sep, 2026

The penetration test process is opaque to most of the people who commission it. A UK business signs off a quote, agrees some dates, and then waits. Somewhere...

Read more
18
  • Cloud Backup

Backup Retention Policy: A UK Business Guide to How Long You Should Actually Keep Your Data in 2026

18 Sep, 2026

A backup retention policy is the answer to a question most UK businesses have never actually been asked: how far back do you need to be able to go? In the...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.