Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Hardware Shortages Are Driving Up IT Costs: What Leaders Should Do Now

If your organisation has felt the sting of higher prices or longer lead times on servers, storage, memory or end-user devices over the past year, you are not imagining it. The AI build-out is reshaping the global hardware market in ways that go well beyond a short-term price spike. The key point for IT and business leaders is this: what began as a temporary shock now looks more like a multi-year supply and pricing cycle.

How to Protect Your Repositories from Open-Source Supply Chain Attacks

The open-source trust model is broken. Not strained, not under review—broken. For years, your team has pulled third-party code into your repositories on the reasonable assumption that a widely used dependency is safe. Popularity looked like a proof. Millions of downloads looked like a security review. TeamPCP has proven otherwise.

TISAX vs ISO 27001: What German Automotive Suppliers Need to Know

TISAX and ISO 27001 are related but not interchangeable. ISO 27001 is a general-purpose information security certification accepted across any industry; TISAX is the automotive industry’s mandatory, shared assessment framework, built on ISO 27001’s structure but adding prototype protection and data protection requirements that OEMs specifically demand. Most automotive suppliers need TISAX, and an existing ISO 27001 program is the fastest route to get there.

Apple Warns Users to be Wary of Unsolicited FaceTime Calls

Apple is warning users to be wary of unsolicited FaceTime calls amidst a wave of scams impersonating Apple Support, Malwarebytes reports. The scammers inform the user that there’s been fraudulent activity or a technical problem associated with their account, and trick the victim into handing over payment card details, banking credentials or Apple ID logins.

Everyone's a Builder Now. That Changes Security Training.

I've spent my career figuring out what makes content stick, from early work for brands like Apple and onward across two decades across film, animation and generative AI. Different tools every few years, same question underneath. What makes someone lean in instead of tuning out? Turns out that question sits at the center of a problem the security industry has wrestled with for 15 years. How do you build a culture where people actually change how they behave? Not comply. Not click "complete." Change.

New Phishing Kits Use Open-Source Tools to Bypass MFA

Researchers at Lexfo are tracking three sophisticated phishing kits that were built using open-source components, primarily based on the publicly available adversary-in-the-middle (AiTM) attack framework “Evilginx.” The phishing kits are designed to proxy “live Microsoft 365 authentication sessions to capture session cookies and OAuth tokens in real time, bypassing MFA entirely.” The kits also use AI to generate personalized phishing lures with a variety of different delivery metho

Beyond Remote Access: The Next High-Growth MSP Service

The workplace has fundamentally changed. Employees work from home, customer locations, airports, coffee shops, hotels, and virtually anywhere with an internet connection. At the same time, the applications they depend on are spread across Microsoft 365, SaaS platforms, private cloud environments, corporate data centers, and on-premises business applications. For managed service providers (MSPs), this represents one of the largest recurring revenue opportunities available today.

An API for MoQ: provision your own isolated relays

Last year, we enabled Media over QUIC (MoQ) on every Cloudflare server and opened the network for anyone to test. It provided a global MoQ endpoint, but not the isolation and access controls needed to run an application. Today, we’re adding those isolation and access controls. The new MoQ provisioning API lets you create an isolated relay for your application and issue separate credentials for publishers and subscribers.

The Hugging Face Incident: A CISO Wake-Up Call for the Agentic Era

Earlier this month, Hugging Face, an AI and machine learning platform company, revealed that an autonomous AI system had breached part of its production environment. The intrusion began in the platform’s dataset-processing environment and eventually involved higher-level access, credential exposure, and movement into internal clusters.

The UK Has a Foreign Vendor Problem. The Case Studies Are Piling Up.

The NHS, MoD, and Metropolitan Police have each built deep operational dependency on Palantir through contracts largely awarded without competitive tender. Parliament has called it "an unacceptable point of weakness," Sadiq Khan blocked a £50 million Met Police deal, and the pattern keeps repeating: enter below scrutiny thresholds, build dependency, make exit expensive.