Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

ASOS Cyber Incident: CYJAX on the Third-Party Risk Facing UK Retailers.

On 6 October 2026, ASOS customers received an extortion message through the retailer's own app claiming its Snowflake instance had been compromised. CYJAX looks at what happened, why third-party and cloud platform risk sits at the centre of the incident, and how organisations can monitor their extended supply chain before attackers do. By now, most people in the UK will have heard about the cyber incident that hit ASOS on 6 October 2026.

What to Look for in a Threat Intelligence Tool

Most security teams aren't short of data. The harder problem is turning that data into intelligence they can act on. This guide sets out the seven criteria that separate an effective threat intelligence tool from another unused dashboard: dark web coverage, relevance, human analysis, speed, multi-audience outputs, integration and provider trust. It also covers the red flags to watch for during procurement and gives ten questions to ask every vendor.

Cybersecurity Awareness Month 2026: Why Awareness Needs to Be Intelligence-Led

Cybersecurity Awareness Month has encouraged safer online behaviour every October since 2004, but AI-enabled attacks are changing what awareness needs to look like. This article looks at the campaign's history, the latest UK threat data, and why organisations should ground their awareness efforts in real threat intelligence.

Threat Intelligence Roundup: The OpenAI-Hugging Face Incident and ZeroBytes

OpenAI agents exploited internal infrastructure to reach Hugging Face's production systems, while cybercriminal group ZeroBytes, which has exclusively targeted France, has gone quiet following two arrests. CYJAX rounds up what happened and what it means for defenders. OpenAI agents exploited internal infrastructure to reach Hugging Face's production systems, while cybercriminal group ZeroBytes, which has exclusively targeted France, has gone quiet following two arrests.

Cineworld Glitch Purportedly Allows Users To See Member Card Details

On 17 September 2026, users on X (formerly Twitter) posted that payment details belonging to other individuals had appeared on the Cineworld app under their personal accounts. On 17 September 2026, users on X (formerly Twitter) posted that payment details belonging to other individuals had appeared on the Cineworld app under their personal accounts.

The Cybersecurity Visibility Gap: What You Can't See Can Still Hurt You

Most security programmes are built to watch the inside of the network, but the threats that do the most damage often start outside it: leaked credentials, impersonated domains, dark web chatter, and vulnerabilities under active discussion. This post looks at why the visibility gap exists, what the data says about it, and what closing it involves.

CYJAX Joins the UK Cyber Security Council

CYJAX joins the UK's professional body for cyber security, reinforcing its commitment to developing cyber talent, upholding the highest ethical standards and helping strengthen the future of the profession. CYJAX is proud to announce that we have become a corporate member of the UK Cyber Security Council, the independent professional body dedicated to advancing the cyber security profession across the UK.