Weekly Updates

IT News & Updates

The latest in cloud, cybersecurity, AI, and web technology — curated for UK businesses every week

69
Articles
5
Categories
Weekly
New Content
100%
Free to Read
Showing 1–15 of 43 articles in Cybersecurity
Oracle July 2026 CPU — 1,434 CVEs, 1,449 Patches: The Largest Quarterly Security Release in Oracle's History and What Every UK Business Running Oracle Must Do This Week

Oracle July 2026 CPU — 1,434 CVEs, 1,449 Patches: The Largest Quarterly Security Release in Oracle's History and What Every UK Business Running Oracle Must Do This Week

Oracle released its July 2026 Critical Patch Update on 21 July — the largest quarterly security release in the company's history, addressing 1,434 CVEs across 334 products with 1,449 patches, ~600 of which are remotely exploitable without authentication. A CVSS 9.8 PeopleSoft zero-day (CVE-2026-35278) was already exploited by ShinyHunters to breach 100+ organisations before this fix shipped — making this the most urgent Oracle patching cycle for UK businesses since the 2026 EBS payments exploit.

Proofpoint 2026 AI-Era Ransomware Report — 58% of UK Victims Paid Despite NCSC Warnings: Why AI-Powered Attacks Are Now a Human Problem, Not a Malware Problem

Proofpoint 2026 AI-Era Ransomware Report — 58% of UK Victims Paid Despite NCSC Warnings: Why AI-Powered Attacks Are Now a Human Problem, Not a Malware Problem

Proofpoint's 2026 AI-Era Ransomware Report — released 22 July — reveals that 58% of UK organisations hit by ransomware paid a ransom despite NCSC guidance not to do so, while 65% said AI made the attack more effective and 66% had data stolen before encryption even began.

Scattered Spider Sentencing — 5.5 Years Each for the £39m TfL Hack: What Every UK SME Needs to Know About Social Engineering and Managed IT

Scattered Spider Sentencing — 5.5 Years Each for the £39m TfL Hack: What Every UK SME Needs to Know About Social Engineering and Managed IT

Two members of Scattered Spider — Owen Flowers (18) and Thalha Jubair (20) — were sentenced to five years and six months each at Woolwich Crown Court on 16 July 2026 for the 2024 cyber-attack on Transport for London, which cost £39m, rendered 148 IT systems inoperable, forced 27,000 staff to reset passwords in person, and exposed the data of up to 10 million customers. The hack succeeded entirely through social engineering: the attackers phoned a TfL help desk worker and persuaded them to reset a two-factor authentication code — a threat vector that trained, managed IT support with strict identity verification protocols addresses directly.

Microsoft July 2026 Patch Tuesday — 622 CVEs, 3 Actively Exploited SharePoint & AD FS Zero-Days: What Every UK Business Running Microsoft 365 Must Do This Week

Microsoft July 2026 Patch Tuesday — 622 CVEs, 3 Actively Exploited SharePoint & AD FS Zero-Days: What Every UK Business Running Microsoft 365 Must Do This Week

Microsoft's July 2026 Patch Tuesday — released 14 July — is the largest in the company's history at 622 CVEs, including three zero-days actively exploited in the wild targeting on-premises SharePoint Server and Active Directory Federation Services, with CISA issuing an emergency alert the same day urging immediate patching. The SharePoint RCE flaw CVE-2026-58644 (CVSS 9.8) allows unauthenticated remote code execution via deserialization, while CVE-2026-56164 (SharePoint EoP) and CVE-2026-56155 (AD FS privilege escalation) were both confirmed exploited before Microsoft published patches — making this the most operationally significant Patch Tuesday for UK Microsoft 365 users since Hafnium targeted Exchange Server in 2021.

UK Cyber Attacks Surge 34% to 1,589 per Week — Check Point June 2026: The Gentlemen Ransomware Picks Victims by Unpatched Device, Not by Target

UK Cyber Attacks Surge 34% to 1,589 per Week — Check Point June 2026: The Gentlemen Ransomware Picks Victims by Unpatched Device, Not by Target

Check Point Research's June 2026 threat data, published 13 July, reveals UK organisations now absorb 1,589 cyber attacks per week — a 34% year-on-year rise at double the global rate — while a previously unknown ransomware group called The Gentlemen has overtaken Qilin as the most active operator by exploiting a pool of 14,000 pre-compromised FortiGate firewalls via CVE-2024-55591, selecting victims entirely by which devices are unpatched rather than by sector, size, or geography.

NCSC + 18 Allied Agencies Issue Emergency Advisory — FSB Centre 16 Is Actively Scanning UK Routers for Weak SNMP Passwords: What Every UK Business Must Do Today

NCSC + 18 Allied Agencies Issue Emergency Advisory — FSB Centre 16 Is Actively Scanning UK Routers for Weak SNMP Passwords: What Every UK Business Must Do Today

On 13 July 2026, the UK's NCSC — alongside 18 agencies from 12 countries — issued a joint advisory confirming that Russia's FSB Centre 16 is actively scanning the public internet for UK business routers running weak or default SNMP credentials and outdated Cisco firmware. UK simultaneously sanctioned 24 Russian individuals and formally attributed the December 2025 attack on Poland's power grid to the same group — making this the most operationally significant router security warning issued to UK businesses since the NCSC's founding.

EU AI Act — 15 Days to the 2 August 2026 Deadline: What Every UK Business Using AI Must Do Before Enforcement Begins

EU AI Act — 15 Days to the 2 August 2026 Deadline: What Every UK Business Using AI Must Do Before Enforcement Begins

The EU AI Act's binding enforcement deadline for high-risk AI systems under Annex III arrives on 2 August 2026 — just 15 days away — and it reaches UK businesses regardless of Brexit, applying wherever AI outputs touch the EU market. With fines up to €35 million or 7% of global turnover, and more than half of organisations still lacking a systematic AI inventory, the compliance window for UK SMEs with EU exposure is now critically compressed.

The Patch Apocalypse Is Here — AI-Driven CVE Surge Breaks Traditional Patch Management for UK SMEs

The Patch Apocalypse Is Here — AI-Driven CVE Surge Breaks Traditional Patch Management for UK SMEs

AI-accelerated vulnerability discovery has triggered a Patch Apocalypse that makes traditional CVE tracking impractical for UK SMEs: June 2026's Patch Tuesday brought 206 Microsoft CVEs, Chrome 150 shipped 433 security fixes, Adobe has switched to twice-monthly patches, and CVE-2026-50656 (RoguePlanet) received an emergency out-of-band fix on 9 July 2026 after a researcher published live exploit code. The volume is now so high that security professionals are abandoning CVE-by-CVE tracking in favour of continuous patch-as-you-go programmes — and UK SMEs without a managed Network Admin function are the most exposed.

FortiBleed — 73,932 Fortinet Firewalls Compromised: What UK SMEs in the Public Sector Supply Chain Must Do Now

FortiBleed — 73,932 Fortinet Firewalls Compromised: What UK SMEs in the Public Sector Supply Chain Must Do Now

A Russian-speaking threat group has compromised credentials for 73,932 Fortinet FortiGate firewalls across 194 countries — including UK government and Foreign Office email accounts now on sale on the dark web for up to £44,000. The FortiBleed campaign, confirmed by CISA on 18 June 2026 and tracked into UK government networks by S-RM on 10 July 2026, exposes every UK SME in a public-sector supply chain to follow-on intrusion risk without a full credential rotation and governance review.

UK Designates Microsoft, Google, AWS & Oracle as Critical Third Parties — 13 July 2026: What Every UK Business Running Cloud Infrastructure Must Understand Now

UK Designates Microsoft, Google, AWS & Oracle as Critical Third Parties — 13 July 2026: What Every UK Business Running Cloud Infrastructure Must Understand Now

On 10 July 2026, HM Treasury designated Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd, Amazon Web Services EMEA SARL, and Oracle Corporation UK Ltd as Critical Third Parties to the UK financial sector under the Financial Services and Markets Act 2023 — effective 13 July 2026. The Bank of England, PRA, and FCA will jointly oversee these providers for the first time, marking a structural shift in how cloud dependency risk is governed across UK banking and financial services.

Cloud Misconfiguration Is Now the #1 Breach Vector — DBIR 2026 Confirms 14% of All Global Breaches: What Every UK SME Running Azure Must Fix This Week

Cloud Misconfiguration Is Now the #1 Breach Vector — DBIR 2026 Confirms 14% of All Global Breaches: What Every UK SME Running Azure Must Fix This Week

On 1 July 2026 security firm SharkStriker’s analysis of the Verizon Data Breach Investigations Report 2026 confirmed cloud misconfiguration as the single largest technical breach vector of the year — responsible for 14% of all global breaches in Q1 2026, up from 9% in 2024. The threat is no longer someone breaking in; it is a door left open by the organisation itself. Here is the full UK SME decode for businesses running Azure workloads.

UK Businesses Plan £505k Average Cyber Spend in 2026 — But Only 30% Can Respond to an Incident: The Virtual CIO Gap Every UK SME Must Close

UK Businesses Plan £505k Average Cyber Spend in 2026 — But Only 30% Can Respond to an Incident: The Virtual CIO Gap Every UK SME Must Close

The headline finding from Barclays’ Q1 2026 Business Prosperity Index reveals a paradox defining British IT: 68% of UK businesses plan to increase cybersecurity investment, average cyber budgets have climbed to £505,000, and cloud, cyber and AI together absorb 44% of all planned tech spending — yet fewer than 30% could actually respond to a serious incident. Here is the Virtual CIO decode for UK SMEs closing the investment-to-capability gap.

Cyber Security Breaches Survey 2026: 43% of UK Businesses Breached — What the 612,000-Company Figure Means for Your Proactive IT Support Plan

Cyber Security Breaches Survey 2026: 43% of UK Businesses Breached — What the 612,000-Company Figure Means for Your Proactive IT Support Plan

On 30 April 2026 DSIT and the Home Office published the Cyber Security Breaches Survey 2025/2026 — the UK government’s most authoritative annual measurement of how businesses and charities are faring against cyber crime. Its headline finding is stark: 43% of UK businesses identified a breach or attack in the last 12 months, roughly 612,000 organisations, and an estimated 5.19 million cyber crimes committed against UK businesses over the year. Here is the proactive IT Support decode every UK SME needs now.

Exchange CVE-2026-42897 — OWA XSS Zero-Day Actively Exploited: The Microsoft 365 Patch Plan Every UK SME on On-Premises Exchange Must Run This Week

Exchange CVE-2026-42897 — OWA XSS Zero-Day Actively Exploited: The Microsoft 365 Patch Plan Every UK SME on On-Premises Exchange Must Run This Week

On 4 July 2026, any UK business still running on-premises Microsoft Exchange faces a decision that has quietly changed shape. CVE-2026-42897 — a cross-site scripting zero-day in Exchange Server’s Outlook Web Access — has been actively exploited since mid-May 2026, was added to CISA’s Known Exploited Vulnerabilities catalogue, and carries a Microsoft-assigned CVSS score of 8.1. It requires no attacker privileges: a single crafted email is enough. Here is the full patch plan every UK SME must run this week.

Microsoft SharePoint CVE-2026-45659 — CVSS 8.8 RCE Actively Exploited, CISA KEV 1 July 2026: The 10-Step IT Support Patch Plan Every UK SME Must Run This Week

Microsoft SharePoint CVE-2026-45659 — CVSS 8.8 RCE Actively Exploited, CISA KEV 1 July 2026: The 10-Step IT Support Patch Plan Every UK SME Must Run This Week

Microsoft SharePoint Server — used by thousands of UK businesses to share documents and collaborate — contains a CVSS 8.8 remote code execution flaw (CVE-2026-45659) that CISA confirmed is being actively exploited on 1 July 2026. Patched on 21 May 2026 but accidentally omitted from Microsoft’s May Security Updates bulletin, the fix has been silently available for six weeks — meaning any UK SME running on-premises SharePoint without managed patching is already structurally exposed.

Need IT Support?

Get in touch with our team for an obligation-free chat about your business IT

Contact Us

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

22
  • Virtual CIO

What is a Virtual CIO and Does Your Business Need One?

22 Jan, 2026

Read more
2
  • Network Admin

How to Set Up Remote Access Without Compromising Security

2 Feb, 2026

Read more
20
  • Cloud Backup

How to Recover Individual Files from a Cloud Backup

20 Oct, 2025

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.