The UK government is moving to update the Computer Misuse Act (CMA), originally enacted in 1990, to better protect ethical hacking and legitimate cybersecurity research. The lack of exemptions for researchers in the original law has long been a concern, and recent recognition of the growing scale of cybercrime and the need for robust research has prompted calls for reform. The changes aim to ensure that cybersecurity professionals can conduct research without fear of prosecution, reflecting the evolving threat landscape and the importance of proactive defense.
In parallel, the UK's National Cyber Security Centre (NCSC) has highlighted the value and risks of cyber deception technologies such as honeypots and decoy accounts. Findings from the NCSC's Active Cyber Defense 2.0 program indicate that, when properly implemented, these tools can provide valuable threat intelligence and disrupt attacker confidence. However, the NCSC warns that poor implementation can generate noise, create vulnerabilities, or foster a false sense of security, emphasizing the need for clear strategy and ongoing management. The NCSC is working to help organizations invest in and deploy these technologies effectively as part of a modern defense strategy.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
The UK government is considering reforms to the Computer Misuse Act to give ethical hackers more freedom to test live infrastructure. The move reflects recognition of the need for more cybersecurity professionals and support for legitimate security research.
Polish police detained three Ukrainian nationals suspected of operating as traveling hackers. Authorities said they were equipped with penetration-testing tools and encrypted storage devices.
Police in Spain arrested a 19-year-old suspected of stealing and selling 64 million personal records. The arrest was reported as part of a roundup of notable security developments.
Ox Security revealed a security issue affecting Cursor and AWS Bedrock in which unprivileged users could change spending limits and expose API tokens. The flaw could have enabled major financial losses and credential leakage.
CISA released its 2025 list of the top 25 most dangerous software weaknesses and said cross-site scripting ranked first for the second consecutive year. The agency urged organizations to prioritize remediation of these weaknesses.
The UK introduced the Computer Misuse Act, criminalizing unauthorized access to and alteration of computer data. The law did not explicitly accommodate legitimate cybersecurity research or ethical hacking.
Four British hackers accessed the Prestel system, highlighting that the UK lacked adequate computer crime legislation. The incident later helped drive creation of the Computer Misuse Act.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.