Skip to content

Blog

The evolution of social engineering in 2026: How attackers are exploiting human trust

For years, social engineering has been one of the most effective techniques in a threat actor's arsenal. Rather than...

WinSxS: The 6,000-binary blind spot in your EDR

Every Windows 10 and 11 machine ships with thousands of Microsoft-signed executables in “C:\Windows\WinSxS” that can be...

CSA Cyber signs the UK's Cyber Resilience Pledge: What it means and why it matters

CSA Cyber has signed the UK Government's Cyber Resilience Pledge, joining the first wave of organisations supporting a...

Responsive FileManager Version 9.14.0 Multiple Vulnerabilities – CVE-2026-37266

TL;DR CSA Cyber identified a Local File Inclusion (LFI) and arbitrary file creation issue within Responsive FileManager...

Claude Mythos: The fact and the fiction

What is Claude Mythos? Anthropic announced Claude Mythos and project Glasswing on April 7th 2026.

osTicket timing vulnerability: Understanding the risk

osTicket password reset endpoint timing side‑channel enables user enumeration – CVE‑2026‑26895 Summary: CSA Cyber...

Hybrid identity, fragmented security: How identity estates fuel modern breaches

In this article, I will cover why hybrid identities can lead to fragmented security and reduced visibility when strong...

Preparing for the quantum shift: Why post-quantum readiness cannot wait

The debate around quantum risk is gathering momentum, and rightly so. Research such as Mastercard’s recent exploration...

CVE-2026-21509 Analysis: The ghost in the document

In January 2026, Microsoft confirmed active exploitation of a high-severity zero-day, CVE-2026-21509, targeting the...

Cyber Security and Resilience Bill: What it means for UK businesses

On 12 November 2025, the Government introduced the Cyber Security and Resilience (Network and Information Systems) Bill...

How does cyber security enhance IT security?

With cyber threats achieving increasing complexity, organisations can no longer rely solely on IT security to protect...

CAF 4.0 Explained: What's new and why it matters

The NCSC have recently released version 4.0 of the Cyber Assessment Framework (CAF), a common framework to enable...