Know what's exposed. Know what you'd be asked.
Cyber security and governance, in plain English — free scans, readiness checks and a weekly briefing, written for the curious, not just the pros. No sign-up, nothing kept beyond a short grace window.
This week's briefings
updated 3 Aug 2026What to patch now
Look at what's actually being targeted this fortnight: a firewall management console (Cisco), a security-appliance console (Check Point), and the box that controls an entire multi-site network (Arista's SD-WAN orchestrator). These aren't the servers or websites a business worries about day to day — they're the tools that manage the tools, the single console an IT provider logs into to control everything downstream. That's exactly why they're valuable to attackers: breaking into one management console can be worth more than breaking into any individual device it oversees, because it hands over the keys to all of them at once. The second pattern sits in the SharePoint entries: two separate, confirmed-exploited bugs in the same product within about two weeks. If your business (or your IT provider) told you "SharePoint's patched" after the first one, that sentence was already out of date by the time the second one was confirmed. The lesson from both patterns is the same: ask which specific fix was applied and when, especially for whatever tool manages your other security tools — that's the one worth checking first, not last.
- 01Cisco Secure Firewall Management Center — a built-in password lets anyone log in (CVE-2026-20316)
- 02Fortinet FortiOS — a way back in even after you've been patched (CVE-2025-68686)
- 03Arista VeloCloud Orchestrator — one flaw takes over the box managing your whole SD-WAN (CVE-2026-16812)
Cybersecurity news
This week's biggest breaches didn't exploit clever code — they exploited a person on the phone or in a chat window who was trying to be helpful, and a vendor or domain-registrar account nobody had asked hard questions about. - Tell every employee, out loud, that IT support never asks them to approve a login or install software over an unsolicited call or chat. - Put offline, tested backups and multi-factor authentication on your domain registrar account in place before you need them, not after. - Never action a payment or bank-detail change from an email alone — always confirm by phone on a number you already know.
- 01A Home-Security Giant Was Breached With Nothing More Than a Phone Call
- 02A Fake "IT Helpdesk" Video Call Led to Ransomware in Under 17 Hours
- 03A Billing Company's Breach From Last September Only Reached 1.26 Million Patients This Week
ICO fines & breaches
Not one of this week's cases needed a sophisticated attacker: a call list nobody screened, a password reused from a personal account, a response nobody had planned. The basics existed — they just weren't turned on. - Screen every outbound call and text list against the TPS register before a campaign; that is where six-figure fines start. - Turn on multi-factor authentication everywhere, and never reuse a password between personal and work accounts. - Write down now who you call and what you say first, so criminals' unverified claims can't set your response later.
- 01Two home-improvement marketing firms fined £370,000 for nuisance calls targeting vulnerable people
- 02Craneware update: an extortion group now claims responsibility — treat the claim with caution
- 03accesso Technology Group named by an extortion group using stolen "infostealer" logins, not hacking
Reading about a breach — could it happen to you?
Most of these stories start with something visible from the outside — an exposed service, a spoofable domain, weak TLS. Check your own domain in about a minute. Free, nothing intrusive.
run the posture scan→UK small business? Start from the UK page → · How we test & why you can trust it