Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Featured Post

Data centres and the changing hybrid threat

The UK is in the middle of a data centre building boom. Government forecasts put AI capable capacity needs at 6GW by 2030, three times what exists today, while electricity demand from the sector is also expected to rise significantly.

When an in-house QA team stops scaling with the product

Engineering don't tend to decide on outsourcing QA. They arrive at it instead, usually a few months after release when cadence has quietly outrun the size of the testing team. A two-person QA function may have comfortably dealt with a monthly release but soon starts falling behind a weekly one. The first response is usually to hire.

CDN Streaming Showdown: Fastly vs. Akamai vs. Cloudflare vs. CloudFront

When you hit play on a video, you don't think about the army of servers that rush to deliver it. But for anyone running a streaming platform, choosing a CDN (Content Delivery Network) is crucial. Latency, throughput, and cache-hit ratio can be the difference between smooth streaming and angry users smashing the refresh button. Here's a practical, human-friendly look at four heavyweights in the streaming space: Fastly, Akamai, Cloudflare, and AWS CloudFront.

How Technology Is Changing the Future of Cybersecurity

The digital world is growing faster than ever before. The security of sensitive information becomes increasingly critical as reliance on digital systems increases in business and daily life. Cybersecurity should not be a matter of merely deploying home-grown simple firewalls or installing basic antivirus. Security continues to be an arms race as attackers grow more sophisticated in their techniques, and more intelligent in their defense. The way you protect data has been radically changed by advanced technology today. Here is a closer look at how modern engineering is shaping the future of digital security.

Session Tokens Are the Real Target

For most of the past decade, security advice on credential attacks reduced to a single instruction. Turn on multi-factor authentication. That instruction was correct and it worked, which is precisely why attackers stopped attacking the thing it protects. The current generation of credential campaigns does not try to defeat MFA. It waits for the victim to complete it, then steals what the authentication produced. The password was never the prize. The session was.

ManageEngine Listed on the UK Government's G-Cloud 15 Framework

For public sector organisations, digital change is rarely just a question of new tech. It is also about finding solutions that are secure, effective, sustainable, and just as importantly, straightforward to procure. That is why we are delighted to announce that ManageEngine has been awarded a place on the UK Government’s G-Cloud 15 framework, with our cloud applications listed under Lot 2b: Software as a Service (SaaS).
Featured Post

AEBA: Why Behavioural Analytics Has to Expand Beyond Humans

For years, security teams have built behavioural models around people. We learned that valid credentials only tell so much. A user can have legitimate access to a system and still behave in a way that deserves attention, which is why User and Entity Behaviour Analytics (UEBA) became such an important part of modern security operations today - intersecting data from multiple sources over extended periods of time to build a story indicating risk has become an essential tool to identify malicious actors, both insiders and outsiders.

Agent Sprawl is the New Shadow IT

As you’re reading this, it’s possible an agent you’ve never heard of is reading your files. But where did it come from? What systems can it access? And who’s responsible for its oversight? Today, employees are using AI and agents to expand what they can accomplish and how work gets done. And the barriers to innovation have never been lower — with natural language and no-code tools, anyone in your organization can build a new agent in the span of an afternoon.

UPDATE: Active Exploitation CVE-2026-32996 of Veeam Agent

On September 14, 2026, public technical details and proof-of-concept (PoC) exploit code were released for CVE-2026-32996, increasing the likelihood of exploitation attempts against affected Veeam Agent for Microsoft Windows deployments. CVE-2026-32996 is a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows version 13.0.1.2067 and affects all earlier version 13 builds.