Windows Hello for Business Key Abuse Enables Token Theft
Entra ID researcher Dirk-jan Mollema has uncovered a technique that allows malware already running on a compromised Windows machine to silently use a victi...
Expert analysis, threat intelligence, and practical guidance from Red Secure Tech's security specialists — covering penetration testing, vulnerability assessment, incident response, and secure development for UK businesses.
Entra ID researcher Dirk-jan Mollema has uncovered a technique that allows malware already running on a compromised Windows machine to silently use a victim's Windows Hello for Business key. The attac...
Read Full ArticleEntra ID researcher Dirk-jan Mollema has uncovered a technique that allows malware already running on a compromised Windows machine to silently use a victi...
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-a...
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software. The patches are part of a...
A weak random number generator in a popular JavaScript cryptography library has led to the theft of millions of dollars in cryptocurrency. The vulnerabilit...
Apple's iCloud Private Relay is supposed to protect your privacy. But researchers have found a way to expose your real IP address even when the feature is...
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application. Then they installed a post-exploita...
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distrib...
You find a great prompt on GitHub. Someone has shared a brilliant way to make your AI agent analyze code, generate documentation, or even write tests. You...
Our blog insights are backed by hands-on service delivery. Whether you need a penetration test, vulnerability assessment, emergency website recovery, or secure web development — our UK cybersecurity specialists are ready to help.
Emergency malware removal, backdoor elimination, blacklist delisting, and full post-incident hardening for compromised websites.
Authorised simulated attacks exposing real vulnerabilities in your web applications, networks, and infrastructure before attackers do.
Systematic identification and prioritisation of security weaknesses across your digital estate — with actionable remediation guidance.
OWASP-aligned web application development with security engineered in from architecture through to penetration-tested deployment.
Advanced adversary simulation testing your organisation's detection and response capabilities against real-world threat actor behaviour.
Actionable intelligence on threat actors, attack vectors, and emerging risks targeting your sector — enabling proactive defensive decisions.
© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067