Penetration testing stories

Over 80,000 Microsoft Entra ID accounts hit by major takeover campaign
Today
#
malware
#
cloud security
#
cybersecurity
Over 80,000 Microsoft Entra ID accounts have been targeted in the UNK_SneakyStrike takeover campaign exploiting the TeamFiltration penetration testing tool.

LevelBlue to acquire Aon’s cyber consulting teams in global deal
Today
#
cybersecurity
#
mssp
#
intellectual property
LevelBlue will acquire Aon's Cybersecurity and IP consulting teams, including Stroz Friedberg, adding 300 experts and boosting global cyber defence services.

Exclusive: SquareX's Audrey Adeline on why the browser is 'the new endpoint'
2 days ago
#
devops
#
apm
#
edr
Audrey Adeline of SquareX warns the browser, where 80% of device time is spent, is the new cybersecurity battleground in an evolving threat landscape.

Cobalt unveils platform updates to streamline pentesting workflows
Last week
#
devops
#
rpa
#
apm
Cobalt updates its Offensive Security Platform to streamline pentesting with faster launches, real-time collaboration, clearer risk prioritisation, and workflow automation.

Retail cyber-attacks surge as weak defences lure criminals
Last week
#
devops
#
mfa
#
phishing
Retailers face a surge in cyber-attacks as weak defences and lapses in multi-factor authentication make them prime targets for criminals seeking valuable data.

Outpost24 becomes only European overall leader in ASM report
Last month
#
devops
#
iot
#
advanced persistent threat protection
Outpost24 is named the only European Overall Leader in the 2025 KuppingerCole report, advancing from Challenger to lead in Attack Surface Management.

Ekco acquires Predatech to boost UK cyber security services
Last month
#
devops
#
cloud security
#
advanced persistent threat protection
Ekco has acquired Manchester cyber security firm Predatech, expanding its pen testing services and opening its first northern England office in the UK.

Picus launches tool for real-time validation of exploitable risks
Last month
#
devops
#
advanced persistent threat protection
#
soc
Picus Security launches Exposure Validation, a tool using real-time attack simulations to identify which vulnerabilities are truly exploitable in organisations.

Legal Aid Agency hit by major cyber breach affecting millions
Last month
#
data protection
#
ransomware
#
devops
The Legal Aid Agency has suffered a major cyber-attack, exposing personal data of over two million individuals dating back to 2010 in England and Wales.

The Ransomware Threat: How to respond and protect your organisation
Last month
#
data protection
#
network infrastructure
#
ransomware
Ransomware attacks in Australia surged in 2023–24, costing businesses up to AUD $97,200 on average, urging firms to bolster cyber defences and response plans.

Kaspersky Endpoint Security achieves full marks in tampering test
Last month
#
endpoint protection
#
devops
#
apm
Kaspersky Endpoint Security has achieved 100% tamper protection in AV-Comparatives' April 2025 test, proving its unrivalled resilience on Windows 11 systems.

Emerging AI security risks exposed in Pangea's global study
Last month
#
firewalls
#
devops
#
network security
Pangea's study reveals significant security risks in AI deployment, with one in ten prompt injection attacks bypassing basic defences in corporate systems.

Personal data breach at rights commission triggers new alarm
Last month
#
firewalls
#
data protection
#
devops
The Australian Human Rights Commission has suffered a data breach after sensitive documents were exposed online due to a server misconfiguration, raising security concerns.

e2e-assure & Validato partner to enhance cyber resilience
Last month
#
devops
#
advanced persistent threat protection
#
apm
e2e-assure partners with Validato to offer businesses continuous cyber security validation, enhancing defence against evolving threats using MITRE ATT&CK framework.

CyXcel earns CREST accreditation for cyber incident response
Last month
#
malware
#
ransomware
#
devops
CyXcel, part of Weightmans, has earned CREST accreditation for its Cyber Incident Response Services, affirming its high standards and expertise in cyber resilience.

Survey shows enterprises shift towards software-driven pentesting
Last month
#
devops
#
advanced persistent threat protection
#
apm
Over 50% of enterprises now use software-driven penetration testing as their primary method to identify IT vulnerabilities, reveals Pentera survey.

Bugcrowd Grows Global Reach via AWS ISV Accelerate
Last month
#
devops
#
hyperscale
#
cloud security
Bugcrowd joins AWS ISV Accelerate Program, enhancing global reach and co-selling to offer crowdsourced security services via AWS sales teams worldwide.

Exclusive: Shannon Murphy of Trend Micro on securing AI risks
Last month
#
devops
#
cloud security
#
application security
Shannon Murphy of Trend Micro urges better cross-department collaboration and visibility to manage AI risks and secure generative AI in enterprises.

Cyber attack on M&S exposes UK food supply chain risks
Last month
#
devops
#
mfa
#
advanced persistent threat protection
Marks & Spencer's recent cyber attack exposes vulnerabilities in the UK's food supply chain, prompting urgent calls for stronger cyber security measures.

Reversec launches with offensive approach to cybersecurity
Thu, 1st May 2025
#
devops
#
advanced persistent threat protection
#
apm
Reversec has launched as an independent cybersecurity consultancy, focusing on offensive strategies to help organisations tackle evolving digital threats globally.