Human Security 'Your bank is calling' — vishing and caller-ID spoofing
A call from the bank's number, a calm 'consultant' and a supposed break-in on your account. We break down the fake-bank-employee scam and how to stop it.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Human Security A call from the bank's number, a calm 'consultant' and a supposed break-in on your account. We break down the fake-bank-employee scam and how to stop it.
Governance and Compliance DORA has applied since January 2025 and covers far more than banks. The five pillars, mandatory resilience testing and ICT supplier duties.
Penetration Testing and AppSec APIs are now the most common target for application attacks. We cover the key OWASP API Top 10 flaws — led by BOLA — and how to avoid them.
Human Security Phishing still accounts for most successful breaches. We explain why employee education alone isn't enough and what to add to your defences.
Human Security Fake shops, spoofed payments and intercepted cards. A practical guide to spotting a fraudulent store and paying safely online.
Supply Chain Security Your security ends at your weakest supplier. How to assess contractor risk, what to put in contracts and how to monitor suppliers efficiently.
Threats and Incidents Your passwords and data are almost certainly in some breach. How to check it safely, what a leak really means and what steps to take.
Governance and Compliance Employees use several times more applications than IT has approved. Where shadow IT comes from, what it risks and how to control it without bans.
Human Security A fake parcel-fee text leads to card or banking phishing. Learn how to inspect the domain, authorisation prompt and incident response.
Penetration Testing and AppSec A guide to the OWASP Top 10 for teams that want to understand real risks — from broken access control, through injection, to SSRF.
Vulnerabilities and CVEs The scanner is the easy part. How to build the full process: inventory, risk-based prioritisation, remediation SLAs and metrics that matter.
Supply Chain Security Pickle, SafeTensors, ONNX, and AI checkpoints explained: prevent code execution and build a controlled, verifiable model supply-chain pipeline.
Cloud, Infrastructure and DevSecOps Most cloud breaches don't come from the provider's flaws, but from the customer's misconfiguration. Here are the five most common traps.
Supply Chain Security In May 2026 the Mini Shai-Hulud worm hit npm and PyPI at once, stealing CI/CD secrets. We analyse the attack and how to harden your pipeline.
Human Security Your phone knows more about you than your computer. Twelve practical settings and habits that genuinely protect your data, accounts and privacy.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.