#NCSC
8 stories taggedNCSC.

UK Account Hijacking Fraud Up 400% as Scammers Sell Fake Tickets Through Victims' Own Profiles
Criminals are breaking into people's email and social media accounts to impersonate them, then selling counterfeit concert tickets to the victim's own friends. The UK's cybersecurity authority says one fix is already in most people's pockets.

Dutch cyber agency warns of live attacks on macOS Screen Sharing flaw
Hackers are breaking into Mac computers exposed to the internet, seizing top-level control, and quietly mining Monero cryptocurrency.

Cyber-attack on England's Department for Education exposes 607,000 records
Contact details for individuals and organisations were taken in a breach affecting two government education portals. No bank details were stolen, but the incident lands as UK school and college cyber-attacks hit record frequency.

AI Is Finding Software Flaws Faster Than Companies Can Fix Them. Something Has to Change.
Security experts are calling time on the old 'scan once a month, patch when you can' model. Artificial intelligence now finds vulnerabilities faster than human teams can close them.

The US Blocked Britain's AI Access. Now the UK Wants Its Own.
A temporary American export ban on two Anthropic AI models has pushed the UK government to announce a homegrown 'Cyber Shield' and question how much it can rely on US technology.

Britain Plans AI Sentinels to Guard Its Networks Around the Clock
The UK's National Cyber Security Centre has published a blueprint for an autonomous AI defence system called Cyber Shield. The ambition is real. So are the unsolved problems.

More Than Half of CISOs Would Pay a Ransomware Demand. The Maths Are Not Flattering.
A survey of 750 CISOs in the US and UK finds 58% would hand over money to ransomware operators, despite law enforcement advice, incomplete decryption rates, and the lingering question of whether the data stays exclusive.

GRU Operators Drained Microsoft 365 Tokens by Rewriting DNS on 18,000 SOHO Routers
Forest Blizzard shifted from targeted router malware to mass DNS hijacking after a UK advisory in August, intercepting OAuth tokens on Outlook on the web.