top of page
Search
TrapDoor and the Growing Problem of Trust in Software Supply Chains
One of the most interesting things about the recent TrapDoor malware campaign isn’t the malware itself. It’s the scale of the trust being abused. Researchers identified malicious packages spreading simultaneously across npm, PyPI, and Crates.io, effectively targeting JavaScript, Python, and Rust development ecosystems all at once. That alone tells us something important about the direction cyber attacks are moving. Attackers increasingly see developers and software pipelines
Lucas Daniels
May 284 min read
Shai-Hulud and the Growing Risk of Software Supply Chain Attacks
The Shai-Hulud malware campaign is becoming a pretty brutal case study in why software supply chain security is now a business risk, not just a developer problem. Researchers recently identified four malicious npm packages containing variants of the malware: Chalk-tempalte @deadcode09284814/axios-util Axois-utils color-style-utils And yes, those names are intentionally designed to look legitimate enough that someone moving quickly might not notice. That’s exactly what makes a
Lucas Daniels
May 214 min read
The Canvas Breach and the Importance of Operational Resilience
The recent Canvas breach is a good reminder that third-party integrations are often the fastest route into an organisation. Not because vendors are careless, but because modern businesses are now deeply interconnected. One compromised platform can create a ripple effect across thousands of organisations in hours. For those of us too old or childless to know, Canvas is one of the leading learning management systems used by schools, colleges, and universities. It handles course
Lucas Daniels
May 144 min read
React2Shell: Why This Vulnerability Is a Big Deal for Modern Businesses
What Is React2Shell? React2Shell is a recently disclosed vulnerability that affects applications built with React, one of the most widely used frontend frameworks in the world. At a high level, the issue allows attackers to chain together frontend weaknesses with backend behaviour in a way that can escalate from client-side input to server-side command execution. In other words, something that starts in the browser can end with attackers running code on your servers. That’s w
Lucas Daniels
Dec 18, 20254 min read
When You Can’t Upgrade: The NHS’s Windows 10 Dilemma and What It Teaches Us About Outdated Systems
What’s Going On As Microsoft ends support for Windows 10 in October 2025, the NHS has found itself in a bind. Many hospitals and trusts still rely on medical devices and specialist equipment that can’t yet run Windows 11, simply because suppliers haven’t updated or certified their software for it. According to reports, while most NHS desktops and laptops are now on Windows 11, a small but significant number of clinical and diagnostic machines remain on Windows 10. These devic
Lucas Daniels
Nov 6, 20253 min read
Why the ChatGPT Atlas Browser Exploit Should Make You Rethink How You Roll Out New Tech
Recently, researchers discovered a significant vulnerability in the Atlas browser that allowed malicious actors to inject commands into the browser’s AI agent by disguising them as URLs or using cross-site request forgery (CSRF). For startups and scale-ups, this is more than a headline, it’s a lesson in how you adopt new tools. It’s easy to get excited about cutting-edge tech, especially when it promises efficiency or innovation. But if you’re not assessing the risks, you mi
Lucas Daniels
Oct 30, 20253 min read
What the Asahi Cyber-Attack Teaches Us About Managing Your Attack Surface
What Happened at Asahi What we do know: On September 29, 2025 , Asahi Group Holdings (Japan’s largest brewer) suffered a cyber-attack...
Lucas Daniels
Oct 9, 20253 min read
LockBit 5.0: The New Ransomware Variant That Hunts Your Servers
A Brief History of LockBit LockBit is one of the most persistent and high-impact ransomware families operating today. It began in 2019...
Lucas Daniels
Oct 2, 20254 min read
CVE-2025-10585: What It Is and Why You Must Update Your Browser Now
What CVE-2025-10585 Is Here’s what we know so far (as of mid-September 2025): The vulnerability is a zero-day, meaning attacks are...
Lucas Daniels
Sep 25, 20253 min read
The NX GitHub Attack: What Happened and How Your Business Can Avoid Being Next
A Quick Recap of the Attack On 16 September 2025, attackers exploited a GitHub Actions injection vulnerability to steal Nx’s NPM...
Lucas Daniels
Sep 18, 20252 min read
Cyber Risk Hits Home: How Charities Can Defend Against Breaches
If you're part of a charity team, whether a founder, trustee, or operations lead, you already know how tight budgets and time are. But...
Lucas Daniels
Sep 11, 20253 min read
Clickjacking and Password Managers: What Startups Need to Know
Password managers are a great tool. They help teams avoid reusing weak passwords, keep track of dozens (sometimes hundreds) of logins,...
Lucas Daniels
Sep 4, 20252 min read
2.7 Million Dialysis Patients Had Their Data Stolen, What Startups Can Learn
This is a cautionary tale for founders and GRC leads: DaVita, a major kidney dialysis provider, was hit by a ransomware attack that...
Lucas Daniels
Aug 28, 20253 min read
When Government and Police Email Accounts Are Up for Sale Underground (And What Startups Should Do About It)
Imagine a hacker buying a genuine .gov or .police email account for as little as $40 and using it to trick your team into opening malware...
Lucas Daniels
Aug 21, 20253 min read
How Royal and BlackSuit Ransomware Operated, and How You Can Stop Attacks Like Theirs
You might be familiar with Blacksuit , the successor to royal, who defrauded 450 victims of over $370m since mid 2023 via Ransomware ....
Lucas Daniels
Aug 14, 20253 min read
Thorium by CISA: Why Startups Should Sit Up and Pay Attention
This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released Thorium , a powerful open-source platform for...
Lucas Daniels
Aug 7, 20253 min read
DMARC is coming!
🚨 Heads up: Microsoft is enforcing DMARC policies by 5th May 2025. If you don't want your emails being delivered to the junk folder,...
Dan Steel
Apr 17, 20252 min read
What is a Fractional CISO, and Does Your Business Need One?
If you run a small business or startup, you know that cybersecurity is important—but hiring a full-time Chief Information Security...
Dan Steel
Feb 17, 20253 min read
How Long Does ISO 27001 Certification Take, and What Does It Cost?
The most common questions I'm asked by small business or startups thinking about ISO 27001 certification are of course: how long will it...
Dan Steel
Feb 13, 20253 min read


How to not get scammed! 🦹🏻♂️ A guide to preventing social engineering.
I've recently delivered an awareness session for a client on how to prevent social engineering. Social engineering is one of my all time...
Dan Steel
Feb 11, 20252 min read
bottom of page
-JS-20240807%20PNG.png)