1. Why the PeopleSoft Victims Were Scanned and Not Chosen

    ShinyHunters found exploitable PeopleSoft servers by scanning the internet for reachable instances. With no fix available until after the attacks began, exposure determined the victims.

  2. Reading the 2026 DBIR Beyond the Patching Headline

    Everyone is quoting the DBIR's headline stat about vulnerability exploitation. The findings that should change how you prioritise are further in.

  3. CISA's New Patching Directive and Why It Matters

    CISA's BOD 26-04 ditches CVSS-based patching for a risk-based model. Here's what it means if CISA doesn't govern you.

  4. How to Outwit Attackers with Cyber Deception

    What a magician's toolkit can teach you about keeping attackers away from what matters.

  5. My Rules for Work

    Things that I find make things better when working with colleagues

  6. Back to Blogging

    After a long break, I'm back!

  7. Private Key Compromise

    Private Key Compromise

  8. Confessions of a Public Speaker - Scott Berkun

    Confessions of a Public Speaker - Scott Berkun

  9. Server Gate Cryptography secrets

    Certification Authorities (CAs) offer two types of SSL certificate, but which should you use?

  10. Invasion of the Not Quite Dead Trailer released!

    IndywoodFILMS presents 'Invasion Of The NOT QUITE Dead' teaser promo...

  11. Time Travellers

    Time Travellers

  12. DDOS on Twitter - happening now!

    Twitter.com is currently down. Status.twitter.com reports that they are currently fighting a DDOS attack.

  13. Blogging in the real world

    Blogging in the real world

  14. Invasion of the Not Quite Dead

    Filmmaker Antony Lane is attempting to revolutionize the way films are funded here in the UK, by putting some life back into an almost dead film industry.

  15. Edinburgh's Graveyard Disgrace

    I'm sometimes ashamed to walk through Edinburgh's graveyards because of the state of disrepair they have fallen in to over the past few years.