Latest

28
Jan
Worldleaks Ransomware Group Behind Nike & Tata - Image shows files leaking to a dark void

Who Is WorldLeaks? The Ransomware Group Behind the Nike and Tata Electronics Breaches

July 2026 WorldLeaks is a data extortion group that has claimed well over 150 victims since January 2025, including Nike,
9 min read
24
Jan
Threat Actor Tools

Threat Actor Tools: The Complete Guide for Defenders

Eighty-four percent of high-severity cyberattacks in 2024 leveraged legitimate system tools rather than custom malware (Vectra AI). Cobalt
12 min read
17
Jan
AI Learning Assistant

Connect Your AI to a Cybersecurity MCP Server

The learning assistant grew up. It is now an open MCP server your AI client can call directly. Here is what it does and why it exists.
2 min read
01
Jan
Feature image for the article: the word "ClickFix" beside a stylised cursor selecting a dotted-outline UI element, representing the click-driven nature of the attack technique.

ClickFix in 2026: Trust-Flow Patterns, Named Variants, and What Stops Them

Updated April 2026 - The trust-flow patterns behind ClickFix, the variants and vectors carrying it, and the defences that work
31 min read
01
Jan
Vibe coding

Public Code Pushes on GitHub Grew 78% in a Year

July 2026 GitHub's own data shows public code pushes growing 78 per cent in the year to March
10 min read
28
Dec
Hacktivist DDoS Attacks: A Defender's Guide

Hacktivist DDoS Attacks: A Defender's Guide

NoName057(16) has targeted 3,700+ hosts in thirteen months. Their playbook is predictable: strike during elections, holidays, and geopolitical flashpoints. Here's what the La Poste attack reveals about defending against hacktivist DDoS.
8 min read
27
Dec
14 Crypto Scams to Watch For in 2026

14 Crypto Scams to Watch For in 2026

Cryptocurrency scam losses reached $9.3 billion in the United States alone in 2024, a 66% increase from the previous
20 min read
27
Dec
MongoBleed Exploit CVE-2025-14847

MongoBleed Exploit: The MongoDB Memory Leak Hitting 87,000 Servers

Updated January 10, 2026: CISA's remediation deadline for federal agencies is January 19. Ubuntu has retracted its claim
10 min read
22
Dec
Prompt Injection Attacks

Prompt Injection Attacks: Examples, Techniques, and Defence

Updated July 2026: Added Unit 42 and Google telemetry on web-based injection observed in the wild, plus a prompt
25 min read
21
Dec
Building a Second Brain for Cybersecurity Work

Building a Second Brain for Cybersecurity Work

Sixty-five percent of security professionals report their job has become harder in the past two years (ISSA/ESG, 2024)
6 min read