International Cyber Expo International Cyber Expo

Data Protection

Hacker Claims Millions of Records Stolen From Azure Tenants

A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns that the information could be used to launch targeted phishing, impersonation, and privilege escalation attacks. The threat actor, known as "TheHatman," has reportedly posted internal employee directories belonging to companies including McDonald's, Vodafone, Kyndryl, Tata Consultancy Services (TCS), HCL Technologies, InterContinental Hotels Group, Gap, Hexaware Technologies, and Wyndham Hotels for sale on...

Read moreDetails
data-cloud-security

Generative AI can now produce sophisticated business documents in seconds, which means work that once required considerable professional time can increasingly begin with a machine-generated draft that looks much like something prepared by a person. The same capability is making fraud harder to recognise because producing a convincing document is no longer a meaningful barrier for an attacker. Entrust discovered that the number of digital document forgeries had increased by 244% from the previous year...

Read moreDetails
zero-trust-technology

Zero trust arrived as an enterprise product category and stayed one for a decade. It was priced for organisations with a security budget, staffed by teams running a security operations centre, and pitched to buyers already fluent in identity providers and policy engines. Smaller firms read the same headlines, nodded along at the same conferences, and went back to a flat network and a legacy VPN, because nobody was forcing the issue. Something specific changed...

Read moreDetails
data-security

Identity checks once sat at the front door of an online service. A user entered a password, passed verification and gained access. That model now looks limited. Stolen credentials, compromised devices and hijacked sessions can place an online casino account in the wrong hands without producing an obvious failed login. Access to a new casino online may involve mobile play, personal records, payment methods and several account-recovery routes. Protecting the login screen remains important, but casino operators...

Read moreDetails
scott-alldridge

The cybersecurity requirements facing defence manufacturers are becoming harder to treat as a paperwork exercise. For companies that handle controlled information or support government contracts, having a written policy is only one part of demonstrating that security requirements are being met. That distinction matters as the Cybersecurity Maturity Model Certification (CMMC) framework continues to evolve. Changes to the timing or mechanics of implementation can create uncertainty for manufacturers, but they do not necessarily remove the...

Read moreDetails
laptop-working

Bring your own device (BYOD) arrangements can help organisations work with contractors, staff who travel, and employees who prefer their own hardware. The tradeoff is straightforward. Company systems are accessed from machines that IT did not buy, configure, or repair. Some will be patched late. Others may be shared at home or used on networks the organisation cannot see. The risk is not limited to the laptop. Vulnerability exploitation now accounts for 31% of breaches,...

Read moreDetails
cyber-software

Annual audits used to define ISO 27001 compliance. A company would scramble for weeks, pull together evidence binders, pass the audit, and forget about the ISMS until the next surveillance visit. That cycle is collapsing. The ICO's enforcement appetite is growing. As UK procurement contracts increasingly mandate current certification, the October 2025 deadline for transitioning from the 2013 standard to ISO 27001:2022 has already passed. That means many organisations still running outdated controls face uncomfortable...

Read moreDetails
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

Certes has released new research showing that many organizations remain unprepared for the security risks posed by quantum computing, despite growing awareness of the threat. According to the company’s Emerging PQC Imperative report, 78% of organizations believe legacy systems represent their biggest quantum security risk. The findings highlight growing concerns that outdated infrastructure and applications could leave sensitive data exposed as quantum computing capabilities advance. The study, conducted by Freeform Dynamics and commissioned by Certes,...

Read moreDetails
cybersecurity-protection

Cost talk around servers tends to rot into slogans. “Cloud is cheaper.” “Dedicated is safer.” “Shared is fine.” None of that pays a bill. A business saves money on a VPS only when someone counts the boring parts: the monthly plan, storage add-ons, bandwidth overages, time spent on updates, outages that eat revenue and developer hours lost. "Is the cloud slow today?” Annual savings live in those details. One clean comparison across twelve months can...

Read moreDetails
data-cloud-security

In January 2026, Martin Kuchar, one of the organisers of BTC Prague, received a message on Telegram. A familiar contact, a compromised account, a familiar context, an invitation to jump on a call. The link led to a page visually identical to Zoom. What followed was the standard script: audio issues, a prompt to install an update. That was all it took. This is not phishing in the classical sense. There is no suspicious email...

Read moreDetails
Page 1 of 13 1 2 … 13