DarkInvader
DarkInvader is an External Attack Surface Management (EASM) platform that provides continuous visibility across all internet-facing assets.
06/10/2026
Three things get confused constantly, and mixing them up wastes the first few hours of your response.
A breach dump comes from a compromised service and exposes credentials for that one service, often as hashes. A combolist is old material aggregated, reshuffled and resold, telling you almost nothing about currency or which device was involved. A stealer log is different: it comes from a compromised endpoint, it includes live session cookies and tokens as well as passwords, and it means a machine somewhere was running infostealer malware. Only the third one obliges you to think about rebuilding hardware and revoking sessions rather than just forcing a password reset.
That distinction decides what you do on the Tuesday morning the alert lands. The full 48-hour triage sequence, including the awkward case where the infected device sits outside your control, is here: https://www.darkinvader.io/blog/stealer-logs-triage-guide
05/10/2026
A common way finance teams find out about a spoofed domain: a supplier rings to ask why the bank details changed. By then brandname-payments.co.uk has been sending mail for weeks, and nothing in your email security flagged it.
That is not a tooling failure. DMARC is an authentication control for domains you own. Once you are at enforcement, nobody can spoof your exact domain, which is a real win and roughly half the problem. A registered lookalike is a different animal. The attacker owns it, publishes their own records, and the mail authenticates cleanly because there is nothing to fail.
The patterns worth separating are typosquats, homoglyph and IDN tricks, and combosquats like brand-invoices or brand-hr-portal. Combosquats deserve most of your attention, because they are plausible to anyone who has never memorised your real domain structure. We have written up the five signals that surface these early and what it takes to get one taken down: https://www.darkinvader.io/blog/domain-spoofing-detection
02/10/2026
On 15 October 2025 the ICO issued a combined £14m penalty over the March 2023 Capita attack, £8m to Capita plc and £6m to Capita Pension Solutions Ltd, after the personal data of more than six million people was affected.
The sequence the ICO describes is ordinary: a malicious file on an employee device, an alert raised but not acted on quickly enough, privilege escalation and lateral movement, then data leaving the estate before ransomware was deployed. No zero-day. A detection that worked and a response that did not keep pace. That is why it reads as a visibility and ownership problem rather than a tooling one. Findings sitting in a queue with no named owner, no triage timestamp and no escalation threshold is now a compliance issue, not just an operational annoyance.
One other point for anyone building a business case: reporting at the time indicated a provisional intention to fine somewhere in the region of £45m to £58m, reduced to £14m before the notice was issued, with remediation and engagement taken into account. We've written up the six external exposure gaps the notice exposes and what to fix first: https://www.darkinvader.io/blog/capita-ico-fine-exposure-gaps
01/10/2026
Every NCSC hacktivist alert produces the same two working days: internal emails, a board asking whether you are affected, and a security team that cannot answer because nobody has looked at the estate from the outside recently.
The useful thing about the pattern these advisories describe is how unsophisticated it is. The 2024 joint advisory from CISA, the FBI, the NSA, the EPA and partners including the NCSC set out pro-Russia activity against operational technology that relied on finding control interfaces answering on the public internet with no password or a factory default, then changing setpoints and disabling alarms through the legitimate interface. Remote access software such as VNC featured heavily.
Worth noting too that "we are not critical national infrastructure" is not a defence. Groups scanning IP ranges find what answers, and contractors, building management providers and suppliers inherit the target profile of the organisations they serve. Our write-up covers what to check first, how to test a claimed breach posted on Telegram, and how to summarise it all on one page for the board: https://www.darkinvader.io/blog/ncsc-hacktivist-alert-exposure-check
29/09/2026
A regional retailer runs a discovery exercise and finds a campaign microsite nobody in the business recognises. An agency registered the domain three years earlier for a Christmas promotion, built it on WordPress, invoiced once and moved on. The site is still live, the plugin stack has not been touched since, and the admin login answers from the open internet.
Nobody in IT knew, because it never went near a change request. That is the honest shape of unknown asset discovery: not theoretical exposure, but infrastructure carrying your brand and your risk while sitting outside every record you hold.
Dangling subdomains are the other common one. Marketing points a CNAME at a SaaS platform or a storage bucket, the subscription is cancelled eighteen months later, and the DNS record stays behind. Anyone who registers the abandoned resource can then serve their own content from your brand domain with a valid certificate. Comparing your authoritative DNS zone against live resolution will surface them. The full seven hiding places are here: https://www.darkinvader.io/blog/unknown-asset-discovery
28/09/2026
The NCSC's adversary simulation guidance, published alongside the Cyber Adversary Simulation (CyAS) scheme, sets out what an assured engagement should look like. What it deliberately leaves to you is the preparation, and that is what decides the value you get.
Three things no provider supplies: a definition of your critical business functions, accurate data on your internet-facing estate, and ownership of remediation once the report lands. An assured team brings tradecraft, threat intelligence and controlled delivery. It does not know which of your business processes would genuinely hurt if it stopped for a day.
The practical test before you scope anything is whether you have defences worth testing. If there is no SOC, no logging on the identity provider and a long patch backlog, spend the budget on the basics first. Full readiness guide here, written from the attacker reconnaissance side: https://www.darkinvader.io/blog/ncsc-adversary-simulation-guidance
27/09/2026
Fake versions of company websites tend to be found the slow way: a customer rings up confused about a payment page, or an email lands that nobody in marketing sent. By then the clone has been live for a while.
There are earlier signals. A domain registered last week that differs from yours by a hyphen or a single character. A TLS certificate issued far too recently for a site claiming years of trading history. Your own favicon, logos and product images served from someone else's hosting, which reverse image search can trace. The same hosting fingerprint showing up behind several lookalike domains, because phishing kits get reused. And a login form that quietly posts to a host with no connection to your business.
Watching new domain registrations and searching for your own imagery each week turns this from a complaint you respond to into something you spot first. Getting the site removed is a separate job, and it is a great deal easier when you are not starting from a customer's phone call.
25/09/2026
Every advisory about a Check Point VPN vulnerability ends the same way: apply the hotfix. That instruction is correct, and on its own it is not a response plan.
CVE-2024-24919 allowed unauthenticated file read on Security Gateways running Remote Access VPN or the Mobile Access blade. That means configuration files, local password hashes and certificate data could be read off the appliance. Patch afterwards and the flaw is closed, but any credentials already taken still work. Check Point confirmed exploitation attempts before public disclosure, which means the window was open before most teams knew there was one.
The other half of the problem is discovery. Asset registers routinely undercount internet-facing gateways: DR and failover appliances, perimeters inherited through acquisitions, lab boxes from a migration nobody decommissioned. Certificate transparency logs and sweeps of vpn., remote., access. and gw. hostnames across every domain you own tend to surface the ones the CMDB missed. Full checklist, in order: https://www.darkinvader.io/blog/check-point-vpn-vulnerability-exposure-checklist
24/09/2026
The Cyber Security and Resilience Bill, introduced to Parliament in November 2025, amends the 2018 NIS Regulations rather than replacing them. The familiar structure of essential services, digital service providers and sector regulators stays recognisable. What changes is who is caught and how fast you have to speak up.
Managed service providers move from being somebody else's third-party risk to being directly regulated. Suppliers can be designated as critical to an essential service. Reporting moves to a two-stage clock with a trigger that captures potential disruption, not only disruption that has already occurred. And it does not replace UK GDPR: if personal data is involved, the 72-hour ICO notification runs in parallel.
There is no prescribed control list, deliberately. The standard stays outcome-based, which means a regulator asking questions after an incident will want to see your reasoning, the evidence behind it and the dates. The NCSC's Cyber Assessment Framework remains the most useful reference for what good looks like. Our readiness checklist walks through what in-scope firms and MSPs need to be able to prove: https://www.darkinvader.io/blog/cyber-security-and-resilience-bill-readiness
22/09/2026
The detail most coverage of the Harrods data breach skipped: the retailer's own network was not the way in. According to Harrods' statement, around 430,000 customer records were accessed through a third-party provider in September 2025, covering names, contact details and marketing preferences. Passwords and payment information were not involved, and the attackers then approached the retailer directly in an extortion attempt.
Customer contact data leaves the perimeter for entirely ordinary reasons. A mid-size retail estate might run an e-commerce platform, an email service provider, a loyalty vendor, two agency-run campaign subdomains and a clienteling app used by store staff. That is five parties able to read customer records before you count sub-processors, and marketing is where shadow IT tends to concentrate: the survey tool bought on a corporate card that quietly retained 40,000 email addresses and was never offboarded.
Start with a register short enough that people maintain it, then ask each vendor which of their sub-processors can read your customer records and where those are hosted. Six supplier-side checks and a 30-day plan here: https://www.darkinvader.io/blog/harrods-data-breach-supplier-lessons
Click here to claim your Sponsored Listing.
Category
Contact the business
Website
Address
Platform 7D, New Station Street
Leeds
LS14BT
Opening Hours
| Monday | 8am - 5pm |
| Tuesday | 8am - 5pm |
| Wednesday | 8am - 5pm |
| Thursday | 8am - 5pm |
| Friday | 8am - 5pm |
Alerts
Be the first to know and let us send you an email when DarkInvader posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.