惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fox-IT International blog
Recent Announcements
Recent Announcements
D
Docker
IT之家
IT之家
B
Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
量子位
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
博客园 - 司徒正美
李成银的技术随笔
美团技术团队
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
T
Tailwind CSS Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
小众软件
小众软件
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
M
Microsoft Research Blog - Microsoft Research
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
Stack Overflow Blog
Stack Overflow Blog

www.infosecurity-magazine.com

Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens Fake Streams, Counterfeit Merch and Other Scams: How Fraudsters Target F1 Fans Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning Apple Blocked $2.2bn in App Store Fraud in the Last Year Cybercriminal VPN Dismantled in Europol Crackdown GitHub Breach Traced to Malicious 'Nx Console' VS Code Extension Three-Quarters of Firms Knowingly Ship Vulnerable Code Nine-Year-Old Linux Kernel Flaw Leaks SSH Keys and Password Hashes Grafana Labs Says Code Breach Stemmed from TanStack Attack Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem China-Linked Webworm APT Evolves Tactics, Expands to European Targets GitHub Confirms Breach of Internal Repositories Via Malicious VS Code Extension Researchers Warn CypherLoc Scareware Has Targeted Millions of Users Verizon DBIR: Vulnerability Exploits Overtake Credentials as Top Access Vector Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool AI Raises the Bar on Vulnerability Awareness and Secure-by-Design Software Agentic AI Accelerates Software Builds and Mobile App Attacks Grafana Labs Confirms Hackers Stole Source Code Hackers Bypass Security Tools to Target Users Directly Interpol Launches Sweeping Cybercrime Crackdown in MENA Region The Infosecurity Europe Cyber Startup Competition: Meet the Finalists NCSC Publishes Guidance on Securing Agentic AI Use Security Researchers Find 47 Zero-Days at Pwn2Own Berlin Bank of England, FCA and Treasury Raise Alarm Over Frontier AI Gremlin Stealer Evolves into Modular Threat with Advanced Evasion Capabilities Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage Campaign Google Launches Android Spyware Forensics Tool for High-Risk Users New Fragnesia Flaw Hands Linux Local Users Root Access Most Organizations Now Use AI Agents for Sensitive Security Tasks ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks Canvas Owner Reaches Agreement With Cybercriminals After Ransomware Attack Avada Builder Flaws Expose One Million WordPress Sites Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers Global Cyber Agencies Issue New SBOMs for AI Guidance to Tackle AI Supply Chain Risks UK Cybersecurity Market Expands to £14.7bn with Strong Growth in AI Security Firms Microsoft Fixes 17 Critical Flaws in May Patch Tuesday OpenAI Launches 'Daybreak' to Help Build Secure By Design Software Mini Shai-Hulud Hits TanStack npm Packages End‑to‑End Encrypted RCS Messaging Arrives Across iPhone and Android Attackers Combine ClickFix With PySoxy Proxying to Maintain Persistence Malicious Hugging Face Repository Typosquats OpenAI South Staffordshire Water Fined £1m After Data Breach TrickMo Variant Routes Android Trojan Traffic Through TON Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities Fake Claude Code Page Pushes PowerShell Stealer at Devs Hackers Observed Using AI to Develop Zero-Day for the First Time US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates ShinyHunters Escalates Canvas Extortion with School by School Ransom Campaign Zara Data Breach Impacts Nearly 200,000 Customers Police Shut Relaunched Crimenetwork Dark Web Marketplace Australian Cyber Security Centre Issues Alert Over ClickFix Attacks PCPJack Campaign Boots TeamPCP Off Compromised Machines Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds Cline Kanban Flaw Lets Websites Hijack AI Coding Agents OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos Fake Claude AI Site Drops Beagle Backdoor on Windows Users Daemon Tools Developer Confirms Software Was Trojanized Researchers Spot Uptick in Use of Vercel for Phishing Campaigns CloudZ Malware Abuses Phone Link to Steal SMS OTPs CISA Urges Critical Infrastructure Providers to Make Plans to Remain Operational if hit by Cyber-Attack Iran-Linked APT Posed as Chaos Ransomware Member in Espionage Campaign One in Eight Workers Has Sold Their Corporate Logins Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails North Korean APT Targets Yanbian Gamers via Trojanized Platform Fake SSA Emails Drive Venomous#Helper Phishing Campaign AI Adoption Outpaces Safety Policies, Leaving Organizations Exposed to Cyber Risk NCSC Warns of an AI-Fuelled “Vulnerability Patch Wave” Trellix Reveals Unauthorized Access to Source Code Small Defense Firms Lack Network Data to Stop Nation-State Hackers, Analyst Says OpenAI To Extend Cyber Program to Government Agencies Anthropic Rolls Out Claude Security for AI Vulnerability Scanning Two American Cybersecurity Workers Jailed for BlackCat Ransomware Attacks Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher Three Arrested for Hacking Over 610,000 Roblox Accounts Deep#Door Python Backdoor Evades Detection On Windows CISA and Partners Publish Zero Trust Guidance For OT Security UK: Education Sector Faces Surge in Cyber Breaches Despite Stable National Threat Levels Europol Busts Albanian Scam Call Centers in Major Online Fraud Case Cyber is the Number One Global “People Risk,” Says Marsh Cursor Extension Flaw Exposes Developer API Keys Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets Researchers Track 2.9 Billion Compromised Credentials Critical Flaw Turns Vect Ransomware into Data Destroying Wiper A Quarter of Healthcare Organizations Report Medical Device Cyber-Attacks Medtronic Confirms Data Breach After ShinyHunters Claims Ransomware Turf War as 0APT and KryBit Groups Trade Blows Chinese National Extradited Over Silk Typhoon Cyber Campaign No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures US Sanctions Target Cambodian Scam Network Leaders Utilities Tech Supplier Itron Discloses Cyber-Attack, Operations Unaffected Widely Used Browser Extensions Selling User Data Most Cybersecurity Professionals Feel Undervalued and Underpaid Researchers Identify Fast16 Sabotage Malware That Pre-Dates Stuxnet BlackFile Group Targets Retail and Hospitality with Vishing Attacks UK Biobank Data Breach: Health Data of 500,000 Listed for Sale in China
UK Cyber Security Council Launches Associate Cyber Security Professional Title
2026-04-13 · via www.infosecurity-magazine.com

Photo of Phil Muncaster

The UK’s professional body for the cybersecurity sector has launched a new title designed to support more people at the start of their careers in the industry.

UK Cyber Security Council said that the Associate Cyber Security Professional title is open to applications from April 13 to May 17. It joins three others: Practitioner, Principal, and Chartered Cyber Security Professional.

Certification at this level ensures individuals are placed on the UK's Cyber Security Professional Register – signalling that they have the requisite knowledge, skills and ethics, and are committed to 75 hours of continuing professional development (CPD) over three years.

Individuals must demonstrate competence in five key areas, but they can fast-track their applications if they already hold certain qualifications, training or certifications which have been aligned to these areas, the council said.

Read more on professional qualifications: UK Cyber Security Council Officially Launches as Independent Body.

"There are so many people who have the skills and drive for a career in cybersecurity but struggle to prove it to employers. The Associate title changes that,” said UK Cyber Security Council CEO, Giles Grant.

“It gives individuals a credible, government-backed way to demonstrate their readiness for their first cyber role, while giving employers the confidence to hire them. This is a hugely important step in closing the cyber-skills gap and ensuring the UK has the pipeline of cybersecurity professionals it needs.”

Closing the Cybersecurity Skills Gap

Industry skills shortages and gaps have been a concern for many years.

The UK government’s most recent Cyber Security Skills in the UK Labour Market report estimated that half of all UK businesses have a basic cyber-skills gap, while 49% of cybersecurity firms faced problems filling technical roles in the previous 12 months.

An ISC2 report from December revealed that 59% of organizations globally have “critical or significant” skills shortages, up from 44% the previous year. It claimed a dearth of talent (30%) and lack of budget (29%) were the biggest drivers.

The Associate title is designed to enable early-career professionals to evidence their knowledge and skills in cyber even if they’ve not been able to prove these in practice. That “experience paradox” makes it challenging for many at the start of their career journeys to persuade employers to take a chance on them.

Holders of the title may have taken various routes to attaining the requisite knowledge and skills, including academic qualifications, self-directed study, certifications, bootcamps, apprenticeships, or transferable experience from another career.

The Associate Cyber Security Professional title is open to anyone who is either ready for, or working in, their first cybersecurity role, the council said.