
Introducing our EUD Guidance for Android 8
We've just published guidance for Android 8 (Oreo). In it we recommend the best...

EUD Security Guidance: Android 8
This guidance is applicable to Android 8 devices configured in work-managed mode...

CYBERUK In Practice Track 2: Mitigation
With CYBERUK 2018 nearly upon us, I thought I'd plug some of the...

CYBERUK In Practice Track 4: Whole System Security
The NCSC's annual conference, CYBERUK 2018, is almost upon us. I'd like to...

Cloudflare Launches Publicly DNS-Over-HTTPS Service
Clouldflare launches DNS-over-HTTPS service called 1.1.1.1 that it says will be a “privacy-first”...

CYBERUK In Practice Track 1: Vulnerabilities and Bug Hunting
With CYBERUK In Practice fast approaching, I wanted to paint a picture of what you...

Bad Microsoft Meltdown Patch Made Some Windows Systems Less Secure
Researcher finds Microsoft’s January Patch Tuesday release included a fix for the Intel...

Manchester will be hosting our biggest CYBERUK yet
CYBERUK provides an important opportunity for the NCSC to facilitate a national conversation...

Facebook Cracks Down On Data Misuse With Expanded Bug Bounty Program
Facebook announced that in the coming weeks it will expand its bug bounty...

GoScanSSH Malware Targets SSH Servers, But Avoids Military and .GOV Systems
Researchers identify a new malware family called GoScanSSH that avoids servers linked to...

Mozilla Tests DNS over HTTPS: Meets Some Privacy Pushback
Mozilla is testing a method of securing DNS traffic via HTTPS, but is...

Zuckerberg Breaks Silence: ‘We Made Mistakes’ Regarding Cambridge Analytica Debacle
Facebook CEO Mark Zuckerberg broke his silence on the Cambridge Analytica scandal that...

Orbitz Warns 880,000 Payment Cards Suspected Stolen
Orbitz said Tuesday a breach of both its consumer and partner platform...

Telegram Ordered to Hand Over Encryption Keys to Russian Authorities
Popular secure messaging service Telegram loses battle with Russian courts and now must...

Programs Controlling ICS Robotics Are ‘Wide Open’ to Vulnerabilities
Dewan Chowdhury, founder of MalCrawler, talks at SAS about the risks that companies...

Facebook Data Privacy Policies Bashed By Critics After Cambridge Analytica Incident
Facebook is in hot water after acknowledging that a consulting group – that...

Denial of Service guidance
Denial of Service attacks are one of the modern cyber criminal's favourite tools,...

GandCrab Ransomware Crooks Take Agile Development Approach
Despite setbacks hackers behind GandCrab malware are pushing ahead with lucrative new ransomware...

New Web-Based Malware Distribution Channel ‘BlackTDS’ Surfaces
Researchers highlight a privately held traffic distribution system tool for malware called BlackTDS...

Table view of principles and related guidance
This page is intended as a handy summary of the 14 NIS principles and...

Microsoft Patches 15 Critical Bugs in March Patch Tuesday Update
Products receiving the most patches included Microsoft browsers and browser-related technologies such as...

TLS 1.3: better for individuals – harder for enterprises
The Secure Sockets Layer (SSL) protocol was first introduced in 1994 by Netscape....

NCSC IT: Installing software updates without breaking things
Software updates can be a controversial topic. We all know it’s important to...

Olympic Destroyer: A False Flag Confusion Bomb
Researchers say the case of Olympic Destroyer malware show how threat actors can...

Lookout: Dark Caracal Points To APT Actors Moving To Mobile Targets
Lookout researchers discussed Dark Caracal's implications for APT actors in the mobile space...

Fixing all the things
The Department for Digital, Culture, Media and Sport (DCMS) has just published the...

Cryptomining Gold Rush: One Gang Rakes In $7M Over 6 Months
Report outlines lucrative rise of nefarious cyrptoming groups and their complex new business...

In Wake of ‘Biggest-Ever’ DDoS Attack, Experts Say Brace For More
This week's DDoS attack against GitHub is a harbinger of attacks to come...

Bug in HP Remote Management Tool Leaves Servers Open to Attack
Firmware versions of HPE’s remote management hardware iLO3 have an unauthenticated remote denial...

Ad Network Circumvents Ad-Blocking Tools To Run In-Browser Cryptojacker Scripts
Researchers say cyrptojackers are bypassing ad-blocking software in an attempt to run in-browser...