peter bassill · operator

Threats — writing by Peter Bassill

peter@hardened:~$ ls -t writing/threats/

Threats · page 3 of 4

Breaches, campaigns and the vulnerabilities being used right now. 58 articles

  • The week in cyber — 18 to 22 May 2026

    A self-spreading npm worm, a government letter that boards should read, and the second-quietest Patch Tuesday in two years. What the past working week looked like through a UK board lens.

    • 6 min read
  • The week in cyber — 11 to 15 May 2026

    A self-spreading npm worm hit TanStack, Patch Tuesday had its quietest month in two years, the Cyber Security and Resilience Bill moved to Report Stage, and the ICO issued a five-step plan boards should actually read.

    • 6 min read
  • The week in cyber — 4 to 8 May 2026

    The ICO fined South Staffordshire Water nearly £1m, the DSIT cyber newsletter quietly confirmed the regulatory direction of travel, and the Canvas extortion played out on a public timeline.

    • 5 min read
  • The week in cyber — 27 April to 1 May 2026

    A learning platform serving thirty million people was breached, cPanel disclosed a zero-day that had been live in the wild for months, and April closed as the worst month for ransomware on record.

    • 5 min read
  • The week in cyber — 20 to 24 April 2026

    NCSC and CISA named the Beijing-based outfit running covert botnets, the UK cyber chief told businesses to brace, and a sitting MP's website was hit with 142 million requests. A busy week.

    • 6 min read
  • Healthcare's reckoning

    Three months of attacks have produced a clarifying set of numbers. £32.7m at Synnovis. 150,000 households warned at NHS Dumfries and Galloway. At least one patient death attributed. Healthcare is where concentration risk meets the lowest acceptable downtime threshold.

    • 7 min read
  • SolarWinds at five

    Five years on from the disclosure of the SolarWinds Orion compromise, what actually changed in how UK boards think about third-party software risk — and what did not. A practitioner's retrospective on the case study that defined the decade.

    • 8 min read
  • The supplier underneath the supplier

    Three disclosures last month tell the same story from three angles: NHS England's tech provider, an NHS GP software supplier, and the Foreign Office. None of them is the headline brand. All of them are where the actual attack surface lives.

    • 6 min read
  • The incidents that do not make the papers

    What three years on the CREST Incident Response Pan-Europe board has taught me about the work the headlines never cover, and the kind of firm a customer should actually want to be on the end of the phone with.

    • 6 min read
  • From prepositioning to action

    Iran has shifted its UK-facing cyber activity from quiet infrastructure presence to operational disruption. The NCSC's August advisory on Salt Typhoon names three Chinese firms. The trajectory of 2025 is no longer ambiguous.

    • 5 min read
  • Synnovis, a year on

    One year after the Qilin ransomware attack on Synnovis took NHS pathology services in south-east London offline, what did we actually learn — and what is still unfixed?

    • 7 min read
  • What the retail wave actually cost

    M&S resumed online orders this week after 46 days offline. Co-op is counting £206m. Harrods got off relatively lightly. Three compromises, one actor, one Easter weekend — and a lesson UK retail boards are still digesting.

    • 6 min read
  • CrowdStrike: cyber resilience without a bad actor

    Four weeks after the CrowdStrike Falcon update that took 8.5 million Windows machines offline, the post-mortem is in. The interesting question is not what CrowdStrike did wrong. It is what the rest of us did wrong by assuming this kind of event could not happen.

    • 7 min read
  • Malware and the layered defence

    Antivirus is necessary but not sufficient. The defence-in-depth approach that actually catches malware — and how it joins up with everything else we have done this year.

    • 6 min read
  • Email is the front door: spotting phishing and stopping BEC

    Over 90% of breaches begin with email. How to spot phishing, build a reporting culture, configure SPF/DKIM/DMARC, and prevent the single most expensive small business fraud: business email compromise.

    • 7 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…