Content Paint

Security

NCSC tests national-scale tripwires and honeypots in the UK

Underused honeypot, tripwire tools a "missed opportunity" says UK centre.

A fisherman throws a large net into the ocean. Microsoft's new bug bounty scheme will cover all online services

The "In Scope by Default" initiative casts a wide net covering bugs in all its online services.

December's Patch Tuesday brings an 0day - and prompt injection warnings

Microsoft patched 1,139 vulnerabilities in 2025. This month, look out for...

Remember Jeep? Porsches got remote-bricked too, in Russia

GPS-linked security systems are probably panicking due to jamming, but sanctions mean there is no post mortem coming.

React2Shell: FUD, loathing and mass exploitation

"A clean ‘this was a successful exploit’ signal isn’t really possible here. The only reliable detection is post-exploitation activity on the box..."

45-day certificates from May, says Let's Encrypt after dismantling OCSP

With 700 million websites affected, a TLS certificate monitoring service is a really good idea, Let's Encrypt tells us.

We'll protect security researchers against ancient cyber laws, UK minister says

Statutory defence – previously rejected as a loophole – is coming for 35-year-old law that chills vulnerability disclosure, says Dan Jarvis.

CVSS 10 bug in React, Next.js triggers security klaxons

Pre-auth RCE, trivial exploitation, a massive blast radius...

CrowdStrike acquiring its way to a unified security platform

Agentic era "demands" a unified platform says CEO as he touts AWS partnership, new acquisitions.

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.