Black Arrow Cyber Threat Intelligence Briefing 17 July 2026
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
We start this week’s review of cyber security in the specialist and general media with news that the UK Government plans to encourage households to keep emergency supplies in case a cyber attack or other crisis disrupts essential services. This aligns with previous reports in which the Government called on businesses to prepare to continue operating if an incident causes the loss of access to technology.
We also report that CISOs are concerned that leadership teams do not fully understand the cyber risks associated with employee behaviour. Other stories highlight evolving phishing techniques, the need to manage a higher volume of security updates, and the continuing development of AI-enabled attacks and ClickFix social engineering campaigns.
A key step in managing these risks is ensuring that leadership teams understand their cyber responsibilities, can oversee risk management effectively and have rehearsed plans for responding to an incident. Contact us to hear how we support organisations across different sectors and of different sizes to achieve this.
Top Cyber Stories of the Last Week
UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows
The UK Government is preparing to launch a national resilience campaign encouraging households to keep basic supplies such as food, water and medicines in case essential services are disrupted by events including a cyber attack. The initiative follows growing concern over threats to critical national infrastructure, including energy, water and communications networks, alongside plans for a national exercise to test the Government's response to a large-scale hybrid attack. For business leaders, the campaign and exercise reinforce the need to consider how disruption to power, water or communications could affect organisational continuity.
https://www.ibtimes.co.uk/uk-government-emergency-preparedness-campaign-1808763
75% CISOs Fear Executives Don’t Understand Cyber Security Risks Employees Face
MetaCompliance has found that many organisations face a growing gap between cyber security leaders and senior executives, with 78% of Chief Information Security Officers believing board-level decision makers do not fully understand the cyber risks created by employee behaviour. Almost 80% said executive support for security awareness declines over time, while 40% are concerned employees are sharing sensitive information with generative AI tools. As AI enables more convincing fraudulent communications at scale, sustained executive engagement and clear governance are becoming essential to strengthening organisational resilience.
https://www.infosecurity-magazine.com/news/cisos-fear-execs-dont-understand/
Finance Phishing Works Because It Sounds Boringly Normal
Finance-themed phishing is a common initial access route because malicious messages closely resemble routine business correspondence and fit expected finance and procurement workflows. Cofense found that 59% to 79% of subject lines in campaigns against financial organisations referred to routine operations, while 21% to 41% used urgency. By imitating normal business processes, including invoices, payment confirmations and supplier enquiries, these emails are more likely to evade automated email security tools and persuade employees to open attachments or click malicious links.
https://www.helpnetsecurity.com/2026/07/16/cofense-finance-phishing-tactics-report/
Microsoft Warns of Increase in Number of Security Updates
Microsoft is using AI to identify software weaknesses across Windows more quickly, meaning organisations should expect a higher number of security updates in future. Microsoft says the increase reflects improved identification and remediation of weaknesses. Its multi-model scanning process validates potential findings before they reach engineers, aiming to reduce false positives and shorten the window in which zero-day vulnerabilities can be exploited. Human experts will continue to oversee the process. Business leaders should therefore expect patching demand to increase and ensure that update processes can absorb a higher volume of security releases.
https://www.infosecurity-magazine.com/news/microsoft-increase-number-security/
Destructive Windows Backdoor Stuffs Multiple Wipers and Ransomware Code into a Single Package
Microsoft has identified a new type of destructive malware that combines several attack techniques into a single tool, giving criminals greater flexibility once they gain access to a network. Rather than simply demanding payment, it can overwrite storage, encrypt files so they cannot be recovered, steal information, record user activity and disable recovery features. For business leaders, the combined capabilities broaden the potential impact of a compromise beyond data theft to remote control, permanent system damage and wider operational disruption.
Identity Attacks Overtake Exploits as Top Ransomware Cause
Identity-related attacks have become the leading cause of ransomware, overtaking software vulnerabilities for the first time in three years. Sophos found that malicious emails, phishing and stolen login details accounted for almost three quarters of ransomware incidents, while software vulnerabilities fell to 18% of cases. Although 97% of organisations affected by credential theft had multi-factor authentication in place, attackers were still able to gain access, highlighting that this important security control must be fully deployed and supported by additional measures to detect and respond to suspicious activity.
Companies Keep Getting Breached by Vulnerabilities They Already Knew About
A survey of 300 IT and cyber security leaders found that while organisations have become highly effective at identifying security weaknesses, many still struggle to fix them quickly. Around eight in ten experienced a security incident in the past year linked to a vulnerability already in their inventory, and about half said the relevant weakness had been known for 30 to 90 days. The biggest barriers were unclear ownership, competing business priorities and lengthy approval processes. Organisations requiring a verified follow-up scan before closing a vulnerability reported substantially fewer incidents involving weaknesses they already knew about.
https://www.helpnetsecurity.com/2026/07/16/ciso-vulnerability-remediation-gap/
ClickFix Is Changing the Economics of Social Engineering
ClickFix has evolved into a highly organised cyber crime service that allows even low skilled attackers to launch convincing social engineering campaigns. Rather than exploiting software flaws, victims are tricked into running malicious commands themselves after visiting fake CAPTCHA pages, browser updates or IT support prompts. Attack kits are available on underground forums from around $250 per month, driving a sharp rise in attacks. Researchers also identified 123 previously undetected ClickFix pages, highlighting how these campaigns can bypass traditional security tools and reinforcing the importance of user awareness alongside technical controls.
https://www.helpnetsecurity.com/2026/07/15/clickfix-social-engineering-attacks-report/
AI, Once Relegated to Helping Hackers with Certain Tasks, Can Now Power Every Stage of a Cyber Attack
Artificial intelligence is now being used across every stage of a cyber attack, marking a significant shift from simply assisting with isolated tasks. Research found that criminal groups are using AI to identify security weaknesses, generate malicious code, automate attacks and move through victim networks with far less human involvement. In one case, a single developer used AI to produce around 88,000 lines of working code in under a week. As AI accelerates both the speed and scale of attacks, organisations face much shorter windows to detect and respond to emerging threats.
Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds
GuidePoint Security has reported that ransomware activity has continued to rise, with threat actors claiming 2,279 victims, up 7% on the previous quarter and 43% compared with a year earlier. Researchers identified a record 91 active ransomware groups operating across 108 countries. AI is helping criminals process stolen information and tailor their extortion tactics, rather than creating fundamentally different ransomware attacks. Manufacturing remained the most affected sector, accounting for almost 15% of reported incidents. Business leaders should combine recovery planning with measures to understand what sensitive data could be exposed and reduce how attackers could use it as leverage.
Russian Hackers Exploit Weak Router Security to Breach Critical Infrastructure, Western Allies Warn
Western governments have warned that Russian state-backed hackers continue to target critical infrastructure by exploiting poorly secured routers and other internet connected network devices. The activity has affected organisations across financial services, healthcare, communications, defence, energy, and government. The warning follows an attempted cyber attack against Poland's power grid that could have disrupted electricity supplies to around 500,000 people. The campaign highlights the importance of replacing default passwords, keeping network equipment up to date and monitoring internet facing systems as closely as other critical business assets.
UK Firms Make Cyber Resilience Measurable
ISG reports that UK organisations are embedding cyber security into wider business resilience, with boards increasingly expecting measurable evidence that security investments reduce risk and improve response times. As AI is used by both defenders and attackers, organisations are adopting AI supported detection while maintaining human oversight and clear decision making. Growing concerns over supply chain risk and critical infrastructure are also driving demand for continuous monitoring, real time reporting and integrated security services that strengthen resilience and support regulatory expectations.
https://www.businesswire.com/news/home/20260710009829/en/U.K.-Firms-Make-Cyber-Resilience-Measurable
Governance, Risk and Compliance
U.K. Firms Make Cyber Resilience Measurable
As Global Conflicts Go Digital, Businesses Require Wartime Plans
Technology is driving an increase in online threats to the UK, senior officials say - ABC News
Stop looking for ironclad cybersecurity answers. They often don't exist | PCWorld
What a financial planner taught me about cybersecurity - Help Net Security
Threats
Ransomware, Extortion and Destructive Attacks
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
Ransomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018 - Security Affairs
Ransom demands are down, email is the top way attackers get in - Help Net Security
Identity Attacks Overtake Exploits as Top Ransomware Cause
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security
New Ransomware Exploits Malicious Driver to Remove Security Protection - Infosecurity Magazine
Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand | CSO Online
GigaWiper: The Windows Backdoor Built to Spy, Fake Ransomware and Erase Disks |
New Qilin Ransomware Attack Uses DCSync Technique to Abuse Active Directory Replication Protocols
Everest Ransomware Claims 1 TB Data Theft But Encryptor Shows No Exfiltration Code
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
Ransomware ecosystem grows, but ‘four-headed monster’ dominates - TechCentral.ie
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in June | IT Pro
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
Former ransomware negotiator gets 4 years for BlackCat attacks
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Ransomware and Destructive Attack Victims
Centers Laboratory Data Breach Affects 540,000 Individuals - SecurityWeek
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims - SecurityWeek
Phishing & Email Based Attacks
Ransom demands are down, email is the top way attackers get in - Help Net Security
Phishing Toolkits Harvest Entra Tokens in Real Time
New phishing kits target Microsoft 365 accounts, evade MFA
Finance phishing works because it sounds boringly normal - Help Net Security
Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many
Phishing Campaign Abuses eCards to Deploy RMM Tools - Infosecurity Magazine
Open Directory Exposes Three Evilginx Phishing Operators - Infosecurity Magazine
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
Other Social Engineering
ClickFix and removable media lead malware delivery methods | TechTarget
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
ClickFix is changing the economics of social engineering - Help Net Security
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek
Is that QR code a trap? How to spot quishing scams before it's too late | ZDNET
QR Codes Are the New Security Blindspots That Steal Your Card Details and Deliver Malware
Tech support scam caused massive data breach at Australian airline Qantas
Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many
LastPass, Bitwarden users targeted with fake security alerts
Scammers are using FaceTime to steal bank account passwords - CBS News
2FA/MFA
Only 28% of financial workforce MFA is phishing-resistant - Help Net Security
AML/CFT/Money Laundering/Terrorist Financing/Sanctions
EU, UK sanction Russian cyberespionage networks over destructive attacks | CyberScoop
Money launderer accused of stealing seized crypto while in prison
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
Artificial Intelligence
99.9% of fixable AI vulnerabilities remain unpatched - Help Net Security
AI Is Changing Financial Services Security Faster Than Many Organisations Can Keep Up | Scoop News
Enterprises are rethinking where their AI applications run - Help Net Security
Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
AI Agents Are a New Kind of Identity & Most Orgs Aren't Ready
Risk of democratic interference added to National Risk Register - GOV.UK
What are 'context bombs'? Get familiar with the new cybersecurity tool. | Mashable
AI-assisted Software Engineering Is Creating A New Delivery Paradox
Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine
EU unveils AI cybersecurity action plan for AI and Cybersecurity
You Can't Secure Your Agents If You Can't See Them
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge - SecurityWeek
Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk | CSO Online
Why conversational AI is redefining your security perimeter | TechTarget
Musk promises purge after Grok Build caught sending entire repos to the cloud
Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife
Bots/Botnets
'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek
Careers, Roles, Skills, Working in Cyber and Information Security
ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight
Cloud/SaaS
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek
Phishing Toolkits Harvest Entra Tokens in Real Time
New phishing kits target Microsoft 365 accounts, evade MFA
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security
Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
European Companies Have a Collaboration Security Confidence Gap
Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk | CSO Online
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments - Infosecurity Magazine
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Money launderer accused of stealing seized crypto while in prison
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
London teenager who offered crypto advice to terror groups convicted | The Standard
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
Cyber Crime, Organised Crime & Criminal Actors
New tutorials on underground hacking forums have roughly doubled - Help Net Security
London teenager who offered crypto advice to terror groups convicted | The Standard
Dutch police bust investment fraud ring stealing over €100 million
Spanish Police take down €140 million cyber fraud ring, arrest four
Police Disrupt a €140M Euro Cyber Fraud Ring in Spain
Russian Cybercrime Trio Indicted In Alleged $62M Scheme
Teen hackers jailed after live streaming cyber attack on TfL - BBC News
Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals
Data Breaches/Leaks
Police suspects Dutch hackers were involved in Odido breach
Lidl Confirms Data Breach After Third-Party IT Provider Hack - IT Security Guru
Tech support scam caused massive data breach at Australian airline Qantas
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims - SecurityWeek
CISA credential leak prompts tighter security measures | CyberScoop
Musk promises purge after Grok Build caught sending entire repos to the cloud
Centers Laboratory Data Breach Affects 540,000 Individuals - SecurityWeek
Data/Digital Sovereignty
Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife
Denial of Service/DoS/DDoS
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
Encryption
MEPs fail to prevent Chat Control snoopfest revival
Fraud, Scams and Financial Crime
Scammers are now cloning trusted news websites to steal your money - Digital Trends
Spanish Police take down €140 million cyber fraud ring, arrest four
Dutch police bust investment fraud ring stealing over €100 million
Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many
UK charges suspects linked to Russian Coms call spoofing platform
Tech support scam caused massive data breach at Australian airline Qantas
Scammers are using FaceTime to steal bank account passwords - CBS News
Identity and Access Management
Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru
Identity Attacks Overtake Exploits as Top Ransomware Cause
AI Agents Are a New Kind of Identity & Most Orgs Aren't Ready
Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine
A wolf in sheep’s clothing | Professional Security Magazine
Insider Risk and Insider Threats
75% CISOs Fear Executives Don’t Understand Cybersecurity Risks - Infosecurity Magazine
Law Enforcement Action and Take Downs
INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million
Third US Security Expert Sentenced to Prison for Helping Ransomware Gang - SecurityWeek
Spanish Police take down €140 million cyber fraud ring, arrest four
Dutch police bust investment fraud ring stealing over €100 million
UK charges suspects linked to Russian Coms call spoofing platform
Police suspects Dutch hackers were involved in Odido breach
London teenager who offered crypto advice to terror groups convicted | The Standard
Teen hackers jailed after live streaming cyber attack on TfL - BBC News
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
764 splinter group leader sentenced to 40 years in jail | CyberScoop
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
Welsh Doxbin admin jailed for egging on swatters from behind a screen
Linux and Open Source
Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine
OpenMandriva Linux says contributor tried to sabotage the project
Malware
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
GigaWiper: The Windows Backdoor Built to Spy, Fake Ransomware and Erase Disks |
Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru
ClickFix and removable media lead malware delivery methods | TechTarget
CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
New CrashStealer malware poses as Apple crash reporting tool
New MacOS Malware Exploits Legitimate Developer ID - Infosecurity Magazine
Windows Bind Link Attacks Can Hide Malware From EDR Tools - SecurityWeek
Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek
AI-assisted Software Engineering Is Creating A New Delivery Paradox
222 GitHub Repositories Linked to Fake Go Package Malware Operation
Hackers backdoor Jscrambler npm package with infostealer malware
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
Compromised npm Packages in the AsyncAPI Namespace Deliver M...
Mobile
RedHook Android malware now uses Wireless ADB for shell access
US personnel faced phone-tracking campaign during Iran war – FT | Iran International
Models, Frameworks and Standards
EU sues 4 nations for leaving hospitals, banks unprotected | Cybernews
EU unveils AI cybersecurity action plan for AI and Cybersecurity
Where do SMEs stand in preparing for the Cyber Resilience Act? | ENISA
New AI Security Charter Backed by Over 70 Cyber Firms - Infosecurity Magazine
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge - SecurityWeek
Pentagon announces 'immediate suspension' of CMMC Phase II mandates - Breaking Defense
Passwords, Credential Stuffing & Brute Force Attacks
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
Microsoft Entra ID authentication overhaul to start in September 2026 - Help Net Security
Don't let an AI chatbot pick your password, ever | ZDNET
Regulations, Fines and Legislation
EU sues 4 nations for leaving hospitals, banks unprotected | Cybernews
Government Updates UK’s National Risk Register with Cyber Warnings - Infosecurity Magazine
Where do SMEs stand in preparing for the Cyber Resilience Act? | ENISA
Risk of democratic interference added to National Risk Register - GOV.UK
MEPs fail to prevent Chat Control snoopfest revival
More Countries Jump on the Social Media 'Ban Wagon'
Cyber Security Bill amendment to be reintroduced in House of Lords — Hong Kong Watch
Pentagon announces 'immediate suspension' of CMMC Phase II mandates - Breaking Defense
Social Media
More Countries Jump on the Social Media 'Ban Wagon'
Software Supply Chain
222 GitHub Repositories Linked to Fake Go Package Malware Operation
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek
Ghost Accounts Abuse GitHub API in Mass Recon Campaign - SecurityWeek
Why SBOMs, signing, and provenance still don't tell you if software is safe - Help Net Security
Supply Chain and Third Parties
Lidl Confirms Data Breach After Third-Party IT Provider Hack - IT Security Guru
Manage Vendor Risk in a Few Practical Steps
Edtech gets schooled by third-party cyberthreats | TechTarget
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Stockpile food in case of Russian cyber attack, Government will tell public
EU adopts largest-ever cyber sanctions package against Russia
UK and EU impose sanctions on hacking groups linked to Kremlin | Computer Weekly
Europe is building resilience – but not the kind it needs for war - Friends of Europe
As Global Conflicts Go Digital, Businesses Require Wartime Plans
Government Updates UK’s National Risk Register with Cyber Warnings - Infosecurity Magazine
Nation State Actors
China
China, India-Linked Hackers Both Targeted Same Pakistani Police Force - SecurityWeek
Russia
UK government to warn the public to prepare for a cyberattack | Cybernews
Weak Security Continues to Fuel Russian Cyberattacks
CISA Stresses Router Hardening Against Nation-State Hackers
UK and international allies warn critical sectors over Russian cyber threats | UKAuthority
EU adopts largest-ever cyber sanctions package against Russia
Europe is building resilience – but not the kind it needs for war - Friends of Europe
EU, UK sanction Russian cyberespionage networks over destructive attacks | CyberScoop
NATO Condemns Russian Cyber Attacks, Warns of Reprisals | Newsmax.com
UK, EU officially pin Poland energy cyberattack on Russia
UK charges suspects linked to Russian Coms call spoofing platform
Russian Cybercrime Trio Indicted In Alleged $62M Scheme
North Korea
Cyberattacks against S. Korean military top 18,000 last year: report - The Korea Herald
Iran
Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure
US personnel faced phone-tracking campaign during Iran war – FT | Iran International
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
London teenager who offered crypto advice to terror groups convicted | The Standard
Teenager convicted of terrorism offences after CTP London investigation | Metropolitan Police
Tools and Controls
75% CISOs Fear Executives Don’t Understand Cybersecurity Risks - Infosecurity Magazine
Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife
NCSC advice on vulnerable routers | Professional Security Magazine
Windows Bind Link Attacks Can Hide Malware From EDR Tools - SecurityWeek
Only 28% of financial workforce MFA is phishing-resistant - Help Net Security
New Ransomware Exploits Malicious Driver to Remove Security Protection - Infosecurity Magazine
As Global Conflicts Go Digital, Businesses Require Wartime Plans
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek
Microsoft Entra ID authentication overhaul to start in September 2026 - Help Net Security
Phishing Campaign Abuses eCards to Deploy RMM Tools - Infosecurity Magazine
AI Coding: Do Security Risks Outweigh Productivity Gains?
The best defense against AI attacks turns out to be a skeptical human - Help Net Security
Why AI 'harnesses' matter more than frontier LLMs for cybersecurity | CyberScoop
Why SBOMs, signing, and provenance still don't tell you if software is safe - Help Net Security
ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight
VPN service favored by ransomware groups is sanctioned by US | The Record from Recorded Future News
EU launches AI test platform to find cybersecurity flaws | Cybernews
Reports Published in the Last Week
Other News
UK to be told how to prepare for food or water shortages | News UK | Metro News
Cyber-attacks, heatwaves and power cuts: Why Britons are being told to prepare | ITV News
Cybercriminals Flock to Healthcare Businesses as Attacks Surge
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
When Hackers Cut the Internet, Will the Water Still Flow?
Construction Begins On £1bn Cyber-Security Centre | Silicon UK
Vulnerability Management
Microsoft Warns of Increase in Number of Security Updates - Infosecurity Magazine
99.9% of fixable AI vulnerabilities remain unpatched - Help Net Security
Companies keep getting breached by vulnerabilities they already knew about - Help Net Security
Microsoft is rewriting Windows patch guidance because of AI - Help Net Security
EU launches AI test platform to find cybersecurity flaws | Cybernews
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | CyberScoop
Vulnerabilities
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Windows BitLocker 0‑Day Vulnerability Allows Hackers to Bypass Security Feature
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities - SecurityWeek
Dell PCs are shutting down after Windows 11's July update, Microsoft admits and blocks it
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Fresh SharePoint Vulnerability Exploited Soon After Disclosure - SecurityWeek
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities - SecurityWeek
Adobe Patches Critical ColdFusion Vulnerabilities - SecurityWeek
Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution
Debian 13.6 security update patches over a hundred advisories in trixie - Help Net Security
CISA urges immediate action on actively exploited Fortinet flaws
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates - SecurityWeek
Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud - SecurityWeek
Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow - SecurityWeek
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Splunk, Zoom Patch Critical Vulnerabilities - SecurityWeek
These 5 Routers Are No Longer Safe To Use After A New Security Backdoor Was Discovered
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer - SecurityWeek
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zoom issues a warning to Windows users about critical security flaw - BetaNews
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.