Cyber security and governance checks in plain English — grc-scan
Latest briefings
updated 18 Sept 2026 · next MondayCybersecurity news
Everything significant this week turned on proving you belong: a login check bypassed on an appliance, a remote-support session used against its owner, and a phone call from a fake IT help desk. - Tell staff plainly that IT will never ring and ask them to re-register MFA or a passkey — hang up, call back on a known number. - Patch anything that authenticates people or handles email in the week a fix lands, not the month. - Ask your IT provider and your web host, in writing, which of this week's fixes they have applied.
- 01A Flaw in Remote-Support Software Lets an Attacker Push Files Onto Every Machine in a Session
- 02A Single Crafted Email Can Take Over Cisco's Email Security Appliance
- 03Cisco Rushed Out an Emergency Patch for a Login System Attackers Were Already Inside
ICO fines & breaches
None of this week's cases began with a hacked system — each one started with a routine process, from answering an official request to sharing data with an advertising partner, that nobody had ever checked. - Verify any request to hand over personal data by calling back on a number you looked up yourself, never one in the message. - List every third party your website sends visitor data to, and delete the ones you cannot justify. - Name one person for data requests from customers and diary them at three weeks — the legal deadline is one month.
- 01Revolut handed 680 customers' passports, selfies and transaction histories to a fraudster — because the email passed every authentication check
- 02Grindr to pay £26m to settle a UK group claim over data allegedly shared with advertising partners
- 03ICO opens an investigation into Police Scotland over how it handles subject access requests
What to patch now
This week's list is dominated by the tools working behind the scenes on your behalf — remote-support and IT-management software, firewalls and routers, developer platforms — rather than anything you'd notice yourself. - Ask your IT provider or help desk whether they use N-able N-central or ConnectWise ScreenConnect, and whether it's patched. - Running a Citrix, Fortinet or Cisco firewall/VPN, or a MikroTik router? Several fix-by dates have already passed — check today. - If a developer runs GitLab or Artifactory for you, ask when it was last updated — Artifactory's now three weeks running.
- 01Adobe Commerce and Magento — a booby-trapped page template can run an attacker's code (CVE-2026-75650)
- 02Microsoft Windows — two bugs that hand an attacker who's already in your PC full control (CVE-2026-81963, CVE-2026-85880)
- 03N-able N-central — a flaw in the software many IT providers use to manage your computers, no login required (CVE-2026-86218)
Reading about a breach — could it happen to you?
Most of these stories start with something visible from the outside — an exposed service, a spoofable domain, weak TLS. Check your own domain in about a minute. Free, nothing intrusive.
run the posture scan→UK small business? Start from the UK page → · How we test & why you can trust it