Powerful tools for your cyber journey
Free tools to test, protect and improve your security.
Latest Articles
Reading a CVE: CVSS, EPSS and KEV explained
Key takeaways A CVE record is an identifier and a description. It is not, on its own, a judgement about how urgent the vulnerability is for you. CVSS answers how bad exploitation would be, EPSS answers how likely exploitation is in the next 30 days, and CISA's KEV catalog answers whether exploitation has actually been observed. Since 15…
MFA for Business Leaders: What You Need to Know
Key takeaways MFA is the single highest-value security control most businesses can deploy, and it is usually low-cost or free. Microsoft reports it blocks more than 99% of automated account-compromise attacks, the kind that make up the vast majority of what hits your business daily. Not all MFA is equal. SMS codes are the weakest form and are…
HackOnChat WhatsApp Scam: How to Protect Your Account from Hijackers
Key takeaways: HackOnChat is a global scam, uncovered by security firm CTM360, that hijacks WhatsApp accounts using fake login pages. It works two ways: hijacking your WhatsApp Web session, or tricking you into handing over a verification code. The scam spreads through trust. Once an account is taken over, it messages that person's contacts asking for money or…
How to Spot a Phishing Email in 30 Seconds
Key takeaways: Most phishing emails can be spotted in under a minute with a few quick checks. The strongest signals are the real sender address, hidden link destinations, and pressure to act fast. Hover over links to see where they really go, and never open unexpected attachments. Polished writing no longer proves an email is safe, so judge…
October is National Cybersecurity Awareness Month: Stay Safe Online!
Key takeaways: Every October, Cybersecurity Awareness Month is a reminder to check your online habits and tighten them. You are not too small to be a target. Everyday users and small businesses are hit just as often as large ones. Four habits cover most of the risk: strong unique passwords, multi-factor authentication, phishing awareness, and keeping software updated.…
The Power of Strong, Unique Passwords — Your Digital Fortress
Key takeaways: Your password is the first line of defence for almost everything you do online, more important than any software. The biggest risk is reuse. If one site is breached, attackers try that same password everywhere else you use it. Length beats complexity. A long passphrase made of several random, unrelated words is both stronger and easier…
Cybersecurity Isn’t Just for Techies: Why It Matters to Everyone
Key takeaways: Cybersecurity isn't only for IT teams. If you use email, online banking, or social media, you are already part of it. Most online harm starts with an ordinary, avoidable mistake, like a reused password or a convincing scam message. You are not too small to be a target. Most attacks are automated and simply look for…
No articles match those filters.
Top Stories This Week
- Hotel Wi-Fi Gateways Hijacked to Steal Microsoft 365 Logins Attackers have been taking administrative control of the Wi-Fi gateways that hotels…
- NVIDIA and Rivals Form Open Secure AI Alliance to Defend AI Agents NVIDIA and 36 other companies launched the Open Secure AI Alliance on…
- EY Data Breach: What Was Exposed and What to Do Ernst & Young (EY), one of the Big Four accounting and advisory…
- Microsoft’s November 2025 Security Update: What You Need to Know Microsoft's November 2025 Patch Tuesday fixes 63 security flaws across Windows, Office,…
Threat Intelligence
View full dashboard
Threat Intelligence Center
Medium
Jul 29
Cisco Secure Firewall Management Center (FMC)
CiscoHard-Coded Password
CVSS 5.3
- Weakness
- Hard-Coded Password (CWE-259)
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N- Added to catalog
- 29 Jul 2026
- Federal remediation deadline
- 1 Aug 2026
Indexed from CISA KEV. Read the full description at the source.
Medium
Jul 27
Fortinet FortiOS
FortinetInformation Disclosure
CVSS 5.9 EPSS 1%
- Weakness
- Information Disclosure (CWE-200)
- CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N- Exploitation forecast
- 1% within 30 days (EPSS, FIRST.org)
- Added to catalog
- 27 Jul 2026
- Federal remediation deadline
- 10 Aug 2026
Indexed from CISA KEV. Read the full description at the source.
Critical
Jul 27
Arista VeloCloud Orchestrator
AristaOS Command Injection
CVSS 10 EPSS 1%
- Weakness
- OS Command Injection (CWE-78)
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Exploitation forecast
- 1% within 30 days (EPSS, FIRST.org)
- Added to catalog
- 27 Jul 2026
- Federal remediation deadline
- 30 Jul 2026
Indexed from CISA KEV. Read the full description at the source.
Critical
Jul 22
Check Point SmartConsole
Check PointImproper Authentication
CVSS 9.1 EPSS 70%
- Weakness
- Improper Authentication (CWE-287)
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N- Exploitation forecast
- 70% within 30 days (EPSS, FIRST.org)
- Added to catalog
- 22 Jul 2026
- Federal remediation deadline
- 25 Jul 2026
Indexed from CISA KEV. Read the full description at the source.
Critical
Jul 22
Microsoft SharePoint
MicrosoftDeserialization of Untrusted Data
CVSS 9.8 EPSS 57%
- Weakness
- Deserialization of Untrusted Data (CWE-502)
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Exploitation forecast
- 57% within 30 days (EPSS, FIRST.org)
- Added to catalog
- 22 Jul 2026
- Federal remediation deadline
- 25 Jul 2026
Indexed from CISA KEV. Read the full description at the source.
Medium
Jul 21
WordPress Core
WordPressSQL Injection
CVSS 5.9 EPSS 78%
- Weakness
- SQL Injection (CWE-89)
- CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N- Exploitation forecast
- 78% within 30 days (EPSS, FIRST.org)
- Added to catalog
- 21 Jul 2026
- Federal remediation deadline
- 4 Aug 2026
Indexed from CISA KEV. Read the full description at the source.
