top of page


đź“°IT News: Microsoft's Passkey Vulnerabilities
A security researcher has recently disclosed flaws affecting Microsoft's passkey implementations across Entra ID and Windows 11. If successfully exploited, these weaknesses could have allowed attackers to gain unauthorised access to accounts using techniques traditionally associated with password-based attacks. Further technical details are expected to be presented at the upcoming Black Hat USA 2026 conference. While this may seem concerning, phishing-resistant authenticatio
Jul 251 min read


IT News: SMS & Voice Authentication Retirement in Microsoft 365
Microsoft has announced a major shift towards phishing-resistant authentication, with native SMS and voice authentication being retired from Microsoft Entra ID on 1 February 2027. This reflects the industry's move towards stronger authentication methods that are more resistant to phishing, credential theft, and social engineering. For organisations still relying on SMS and voice-based authentication, now is the time to start planning your transition: Identify users still usi
Jul 141 min read


Weekly IT Tip: Sign Out and Clear Your Cookies
A simple but often overlooked cybersecurity habit is signing out of applications you're no longer using and periodically clearing your browser cookies. This is because many modern attacks don't focus on stealing your password. Instead, they attempt to abuse an existing signed-in session, allowing access without needing your credentials. This is commonly known as session hijacking. While this habit won't prevent the attack, it can help limit the impact. The fewer applications
Jul 131 min read


Cybersecurity Awareness: Cyber Hygiene
In this next topic in the cybersecurity awareness series, we look at cyber hygiene: the small, regular habits that help keep your personal and work digital life more secure. Quick takeaway Section Key message What it is Cyber hygiene is the routine care of your digital assets, including accounts, devices, apps, and information. Why it matters Small gaps, such as weak authentication or outdated software, combine to create easy opportunities for attackers. What to do Strengthen
Jun 213 min read


Cybersecurity Awareness: Cross-Contamination
Cybersecurity can feel complex. There are many tools, systems, and controls designed to protect information, devices, and people. But one of the most important lines of defence is also one of the most familiar: you, the user. Security training and attack simulations help, but the real goal is awareness. When people understand common risks and build safe everyday habits, they help protect both their workplace and their personal digital lives. That is why we have started this c
May 273 min read


Today’s #1 Cybersecurity Control: Phishing-Resistant Authentication
Despite widespread Multi-Factor Authentication (MFA) adoption, identity-based attacks continue to succeed. The reason is that many authentication methods still rely on mechanisms attackers can bypass. Phishing-resistant authentication addresses this and should now be a top priority for organisations. Quick Takeaways Authentication remains a primary attack path: Attackers target passwords, login prompts, and active sessions because they provide a direct route into business sy
May 254 min read


The Network Firewall’s Role in a Cloud-First Zero Trust World
Today’s security landscape looks very different from the one traditional firewalls were originally built for. Users are no longer always in the office. Devices move between networks. Applications are delivered through SaaS. Workloads run in public cloud platforms. Many business systems are now accessed directly over the internet rather than through a private corporate network. In this world, the firewall is no longer the natural centre of gravity for security. That does not m
May 183 min read


A Critical Risk Reminder: OpenAI’s Security Breach and Shadow AI
OpenAI recently confirmed that two employee devices in its corporate environment were impacted as part of the TanStack npm supply chain attack. According to OpenAI, the security breach involved activity consistent with malware behaviour, including unauthorised access and credential-focused exfiltration activity in a limited subset of internal source code repositories accessible to the impacted employees. Importantly, OpenAI stated that it found no evidence that user data was
May 152 min read


🚨 Active Exploitation of cPanel/WHM Vulnerability (CVE‑2026‑41940)
A recently disclosed security vulnerability affecting cPanel and WHM (CVE‑2026‑41940) is currently under active exploitation. Given that cPanel powers a significant portion of global websites, this critical vulnerability presents a significant risk to organisations and businesses that rely on cPanel‑based hosting. If your organisation uses cPanel or WHM, here’s what you need to know — and the steps you should take to protect your environment. What You Should Do Immediately Re
May 41 min read
bottom of page