Static articles for cyber security, vulnerability management, investigation, and
governance topics.
CVE-2026-14382: Why Your Browser Is a High-Value Target
A $250,000 graphics bug in Android browsers can silently compromise devices
when a user visits a webpage. Cyber Essentials requires browsers to be patched
— here is exactly why that requirement exists.
FortiBleed: Thousands of FortiGate Credentials Circulating on Criminal Forums
A credential harvesting operation is selling thousands of valid FortiGate VPN
credentials on criminal forums. Here is what happened, who is affected, and
what to do now.
What Happens in the Weeks Before a Ransomware Attack
Most ransomware incidents begin weeks before any files are encrypted.
Understanding dwell time — and where attackers can be stopped — changes how
you approach defence.
Red teaming and penetration testing answer different questions. Understand the
key differences, the SOC requirement, and when a pen test should come first.
Continuous Penetration Testing: What It Delivers and Where It Has Limits
Annual point-in-time testing misses eleven months of change. Here is what a
continuous testing programme delivers, where it has limits, and how it works
in practice.
Unpatched remote access gateways, exposed management interfaces, forgotten
assets, and email authentication gaps are the most common critical findings
on external network tests.
What We Find on Internal Network Penetration Tests
Flat networks, legacy Windows protocols, Active Directory attack paths, and
credential exposure are the recurring findings on internal network assessments.
Broken access control, authentication weaknesses, business logic flaws, and
injection vulnerabilities are the most consistent critical findings on web
application assessments.
Exposed storage, overpermissive IAM, metadata service access, logging gaps,
and secrets in pipelines are the most common findings on cloud security
assessments.
What We Find on Mobile Application Penetration Tests
Insecure local storage, weak API backends, hardcoded credentials, and
certificate validation failures are the most consistent findings on mobile
application assessments.
Tailgating, unlocked workstations, sensitive information left unsecured, open
network access, and social engineering of staff are the most common findings
on physical security assessments.