Weekly Updates

IT News & Updates

The latest in cloud, cybersecurity, AI, and web technology — curated for UK businesses every week

69
Articles
5
Categories
Weekly
New Content
100%
Free to Read
Showing 16–30 of 43 articles in Cybersecurity
UK Cyber Security & Resilience Bill Clears Commons — Enters Lords 25 June 2026: The 10-Step MSP & SME Compliance Plan Every UK Business Must Start Now

UK Cyber Security & Resilience Bill Clears Commons — Enters Lords 25 June 2026: The 10-Step MSP & SME Compliance Plan Every UK Business Must Start Now

The UK Cyber Security and Resilience Bill passed all House of Commons stages and entered the House of Lords on 25 June 2026 — the most significant expansion of the UK’s cyber regulation framework since NIS 2018, extending mandatory duties to 1,000+ managed service providers and digital supply chains for the first time. With Royal Assent expected by late 2026 and phased enforcement through 2028, every UK SME and MSP now has a closing window to achieve Cyber Essentials certification, implement the CAF controls, and build the evidence base regulators will demand.

Oracle EBS CVE-2026-46817 — CVSS 9.8 Actively Exploited 27 June 2026: The 10-Step UK SME Database Security Audit Plan Every Business Using Oracle Must Run This Week

Oracle EBS CVE-2026-46817 — CVSS 9.8 Actively Exploited 27 June 2026: The 10-Step UK SME Database Security Audit Plan Every Business Using Oracle Must Run This Week

A critical unauthenticated CVSS 9.8 vulnerability in Oracle E-Business Suite’s Payments module — CVE-2026-46817 — was confirmed actively exploited over the weekend of 27–28 June 2026, with attackers targeting unpatched instances via automated HTTP sweeps. Oracle shipped the patch in its May 2026 Critical Security Patch Update, meaning any UK SME running EBS 12.2.3 to 12.2.15 without the May CPU is now exposed to a fully weaponised, no-authentication-required takeover of its Oracle Payments system.

Microsoft’s Biggest-Ever Patch Tuesday — 206 CVEs, 9 June 2026: The 10-Step IT Admin Action Plan Every UK SME Must Run Before Exploit Wednesday Hits

Microsoft’s Biggest-Ever Patch Tuesday — 206 CVEs, 9 June 2026: The 10-Step IT Admin Action Plan Every UK SME Must Run Before Exploit Wednesday Hits

On 9 June 2026 Microsoft released its largest-ever Patch Tuesday, addressing 206 vulnerabilities — including 37 critical flaws, 3 publicly disclosed zero-days and two CVSS 9.8 remote code execution vulnerabilities in the Windows Kernel and HTTP.sys — making it the biggest single security release in the programme’s 23-year history. With Cyber Essentials v3.3 now mandating a strict 14-day patch window for critical fixes, every UK SME still running unpatched Windows systems as of 1 July 2026 is already outside compliance and structurally exposed.

CVE-2026-20230: Cisco Unified CM Actively Exploited — 30 June 2026: The 10-Step VoIP Security Action Plan Every UK SME Must Run This Week

CVE-2026-20230: Cisco Unified CM Actively Exploited — 30 June 2026: The 10-Step VoIP Security Action Plan Every UK SME Must Run This Week

On 24–25 June 2026 attackers began actively exploiting CVE-2026-20230 — a CVSS 8.6 server-side request forgery flaw in Cisco Unified Communications Manager — dropping webshells via automated Tor-routed sweeps and escalating to root on unpatched systems. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 25 June 2026 with a 3-day remediation deadline for federal agencies, and Cisco released patches on 3 June 2026 — meaning any UK SME still running Unified CM without the June fixes is three weeks overdue.

Russia’s £2bn JLR Cyberattack — Revealed 26 June 2026: The Costliest Hack in UK History and the 10-Step Virtual CIO Resilience Plan Every UK SME Needs Now

Russia’s £2bn JLR Cyberattack — Revealed 26 June 2026: The Costliest Hack in UK History and the 10-Step Virtual CIO Resilience Plan Every UK SME Needs Now

On 26 June 2026 The New York Times and TechCrunch revealed that a Russian hacking group was behind the late-August 2025 cyberattack on Jaguar Land Rover — the most expensive cyberattack in UK history. The five-week production shutdown cost the British economy an estimated $2.5 billion (£2bn) and triggered a £1.5 billion UK government bailout. Here is the full decode: what the attack actually involved, why standard criminal ransomware defences would not have stopped it, and the 10-step Virtual CIO resilience programme UK SMEs must implement before the next state-linked attack targets their supply chain.

Scattered Spider Conviction — 22 June 2026: The £29m TfL Breach Playbook Every UK SME Must Study Before the Next Attack

Scattered Spider Conviction — 22 June 2026: The £29m TfL Breach Playbook Every UK SME Must Study Before the Next Attack

On 22 June 2026 two British teenagers pleaded guilty at Woolwich Crown Court to hacking Transport for London — a three-day breach that cost TfL £29m and forced 28,000 employees to reset passwords in person. Here is the full social-engineering decode: how Scattered Spider gained access, why the same tactics work against any UK SME, and the 10-step IT Support plan to close the same identity and access gaps before sentencing day on 16 July 2026.

EU AI Act Transparency Deadline — 2 August 2026: 38 Days for UK Businesses to Comply or Face €35 Million Fines

EU AI Act Transparency Deadline — 2 August 2026: 38 Days for UK Businesses to Comply or Face €35 Million Fines

On 2 August 2026 — just 38 days away — the EU AI Act's Article 50 transparency obligations come into full legal force, catching every UK business whose AI tools affect EU individuals regardless of Brexit. With fines reaching €35 million or 7% of global turnover and the European Commission's draft guidelines closing the consultation period on 3 June 2026, here is the 10-step UK SME compliance plan.

Five Eyes AI Cyber Warning — 22 June 2026: How the 612,000 UK Businesses Breached This Year Can Close the Gap Before Attackers Do

Five Eyes AI Cyber Warning — 22 June 2026: How the 612,000 UK Businesses Breached This Year Can Close the Gap Before Attackers Do

On 22 June 2026 the Five Eyes cybersecurity agencies issued a joint warning that frontier AI is shrinking the window between vulnerability discovery and exploitation to months. With only 5% of UK businesses holding Cyber Essentials certification and 612,000 breached in the past year, here is the 10-step action plan.

Patch Tuesday May 2026: Two CVSS 9.8 Criticals — Every UK SME Has 48 Hours to Act

Patch Tuesday May 2026: Two CVSS 9.8 Criticals — Every UK SME Has 48 Hours to Act

Microsoft's May 2026 Patch Tuesday dropped 137 CVEs — including a wormable CVSS 9.8 Windows Netlogon flaw and a CVSS 9.8 DNS Client bug that exposes every Windows endpoint. UK SMEs with on-premises domain controllers must patch within 48 hours or risk full Active Directory compromise.

NGINX Rift: The 18-Year-Old Web Server Vulnerability That Hands Attackers Code Execution on Most UK SME Websites — The 14-Day Network Admin Audit

NGINX Rift: The 18-Year-Old Web Server Vulnerability That Hands Attackers Code Execution on Most UK SME Websites — The 14-Day Network Admin Audit

On 14 May 2026 F5 and depthfirst disclosed CVE-2026-42945 — codenamed NGINX Rift — an unauthenticated remote-code-execution flaw in the NGINX rewrite module that has sat undetected since 2008. CVSS v4 9.2, three more new CVEs released alongside it, and reachable with a single crafted HTTP request. NGINX powers the front of nearly every modern UK SME website. Here is the full Network Admin decode: where NGINX hides in a typical UK SME stack, the realistic cost of getting this wrong, the 14-day Cyber Essentials v3.3 patching window, and the 10-step controlled-remediation programme.

Backups Are Quietly Failing: What Veeam's 8 May 2026 Data Resilience Findings Mean for UK SMEs — And the 3-2-1-1-0 Cloud Backup Plan for the Next 90 Days

Backups Are Quietly Failing: What Veeam's 8 May 2026 Data Resilience Findings Mean for UK SMEs — And the 3-2-1-1-0 Cloud Backup Plan for the Next 90 Days

On 8 May 2026 Veeam published the data resilience findings UK SMEs cannot afford to ignore: the gap between perceived backup confidence and actual recovery capability has widened, the old 3-2-1 rule has quietly become 3-2-1-1-0, and Cyber Essentials v3.3 now expects evidence of tested immutable backups. Here is the full UK SME decode — what the analysis actually said, where most businesses are losing today, the realistic cost of getting recovery wrong, and the 10-step 90-day Cloud Backup programme to get the evidence on file before your next insurance renewal.

WordPress Mass-Takeover Wave: Two CVSS 9.8 Plugin Vulnerabilities Hand Attackers Admin Access to UK SME Websites — The 7-Day Web Stack Audit Plan

WordPress Mass-Takeover Wave: Two CVSS 9.8 Plugin Vulnerabilities Hand Attackers Admin Access to UK SME Websites — The 7-Day Web Stack Audit Plan

Two critical WordPress plugin vulnerabilities disclosed on 4 May 2026 — CVE-2026-5722 in MoreConvert Pro and CVE-2025-13618 in Mentoring — both score the maximum CVSS 9.8 and both hand unauthenticated attackers full administrator control of any affected UK SME website. Mass-scanning is already in progress. Here is the full UK SME decode: the seven-day web stack audit plan, the Cyber Essentials v3.3 auto-fail risk, the GDPR exposure, the realistic cost-of-compromise envelope, and the 10-step rollout for a managed WordPress posture that does not crumble at the next plugin advisory.

Windows Secure Boot’s 42-Day Cliff: Microsoft’s 2011 UEFI Certificates Expire 19 June 2026 — The UK SME Deployment Plan Before Next Tuesday’s Last-Comfort Patch Window

Windows Secure Boot’s 42-Day Cliff: Microsoft’s 2011 UEFI Certificates Expire 19 June 2026 — The UK SME Deployment Plan Before Next Tuesday’s Last-Comfort Patch Window

Microsoft’s 2011 Secure Boot certificate chain starts to expire on 19 June 2026 — 42 days from today. Devices keep booting, but a 2011-only Windows estate is locked out of every future Boot Manager update, every new DBX revocation, and every 2023-signed third-party bootloader once the post-June DBX revocation lands. Patch Tuesday on 12 May is the last comfortable rollout window. The full UK SME action plan: the four supported deployment paths, the 0x5944 registry value, the PowerShell verification kit, the Cyber Essentials v3.3 A2.4 angle, and a 42-day rollout sequence.

Palo Alto Zero-Day Hits Live: CVE-2026-0300 Lets Attackers Take Over PAN-OS Firewalls — The 7-Day UK SME Action Plan Before the 13 May Patch

Palo Alto Zero-Day Hits Live: CVE-2026-0300 Lets Attackers Take Over PAN-OS Firewalls — The 7-Day UK SME Action Plan Before the 13 May Patch

Palo Alto Networks confirmed this morning that CVE-2026-0300, an unauthenticated buffer-overflow remote-code-execution flaw in the PAN-OS User-ID Authentication Portal, is being actively exploited against internet-facing firewalls. With 5,800+ VM-Series appliances exposed online and a patch not due until 13 May 2026, here is the UK SME 7-day mitigation plan, the Cyber Essentials v3.3 implication, the cost envelope by business size, and the 10-step hardening sequence to take today.

Cyber Resilience Pledge & £90m SME Fund: How the UK Government's 22 April Announcement Reshapes Your Boardroom, Supply Chain and Insurance — A 12-Week Plan

Cyber Resilience Pledge & £90m SME Fund: How the UK Government's 22 April Announcement Reshapes Your Boardroom, Supply Chain and Insurance — A 12-Week Plan

At CYBERUK 2026 in Birmingham the UK government committed £90 million over three years to SME cybersecurity and launched the new Cyber Resilience Pledge — a framework that puts cyber on every board agenda, mandates NCSC Early Warning enrolment, and pushes Cyber Essentials through every supply chain. Here is the full Pledge decode, the realistic 12-week SME readiness plan, the cost envelope by business size, the cyber-insurance angle, and how it stacks with v3.3 Danzell.

Need IT Support?

Get in touch with our team for an obligation-free chat about your business IT

Contact Us

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

18
  • VoIP & Phone Systems

How to Migrate from a Traditional PBX to VoIP

18 Mar, 2026

Read more
28
  • Google Ads & PPC

Google Ads for Healthcare: Reaching Patients Online

28 May, 2026

Read more
28
  • SEO

Voice Search Optimisation: Preparing for How People Search Now

28 Apr, 2026

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.