Weekly Updates

IT News & Updates

The latest in cloud, cybersecurity, AI, and web technology — curated for UK businesses every week

69
Articles
5
Categories
Weekly
New Content
100%
Free to Read
Showing 16–30 of 58 articles in IT Support
EU AI Act — 15 Days to the 2 August 2026 Deadline: What Every UK Business Using AI Must Do Before Enforcement Begins

EU AI Act — 15 Days to the 2 August 2026 Deadline: What Every UK Business Using AI Must Do Before Enforcement Begins

The EU AI Act's binding enforcement deadline for high-risk AI systems under Annex III arrives on 2 August 2026 — just 15 days away — and it reaches UK businesses regardless of Brexit, applying wherever AI outputs touch the EU market. With fines up to €35 million or 7% of global turnover, and more than half of organisations still lacking a systematic AI inventory, the compliance window for UK SMEs with EU exposure is now critically compressed.

The Patch Apocalypse Is Here — AI-Driven CVE Surge Breaks Traditional Patch Management for UK SMEs

The Patch Apocalypse Is Here — AI-Driven CVE Surge Breaks Traditional Patch Management for UK SMEs

AI-accelerated vulnerability discovery has triggered a Patch Apocalypse that makes traditional CVE tracking impractical for UK SMEs: June 2026's Patch Tuesday brought 206 Microsoft CVEs, Chrome 150 shipped 433 security fixes, Adobe has switched to twice-monthly patches, and CVE-2026-50656 (RoguePlanet) received an emergency out-of-band fix on 9 July 2026 after a researcher published live exploit code. The volume is now so high that security professionals are abandoning CVE-by-CVE tracking in favour of continuous patch-as-you-go programmes — and UK SMEs without a managed Network Admin function are the most exposed.

FortiBleed — 73,932 Fortinet Firewalls Compromised: What UK SMEs in the Public Sector Supply Chain Must Do Now

FortiBleed — 73,932 Fortinet Firewalls Compromised: What UK SMEs in the Public Sector Supply Chain Must Do Now

A Russian-speaking threat group has compromised credentials for 73,932 Fortinet FortiGate firewalls across 194 countries — including UK government and Foreign Office email accounts now on sale on the dark web for up to £44,000. The FortiBleed campaign, confirmed by CISA on 18 June 2026 and tracked into UK government networks by S-RM on 10 July 2026, exposes every UK SME in a public-sector supply chain to follow-on intrusion risk without a full credential rotation and governance review.

UK Designates Microsoft, Google, AWS & Oracle as Critical Third Parties — 13 July 2026: What Every UK Business Running Cloud Infrastructure Must Understand Now

UK Designates Microsoft, Google, AWS & Oracle as Critical Third Parties — 13 July 2026: What Every UK Business Running Cloud Infrastructure Must Understand Now

On 10 July 2026, HM Treasury designated Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd, Amazon Web Services EMEA SARL, and Oracle Corporation UK Ltd as Critical Third Parties to the UK financial sector under the Financial Services and Markets Act 2023 — effective 13 July 2026. The Bank of England, PRA, and FCA will jointly oversee these providers for the first time, marking a structural shift in how cloud dependency risk is governed across UK banking and financial services.

Cloud Misconfiguration Is Now the #1 Breach Vector — DBIR 2026 Confirms 14% of All Global Breaches: What Every UK SME Running Azure Must Fix This Week

Cloud Misconfiguration Is Now the #1 Breach Vector — DBIR 2026 Confirms 14% of All Global Breaches: What Every UK SME Running Azure Must Fix This Week

On 1 July 2026 security firm SharkStriker’s analysis of the Verizon Data Breach Investigations Report 2026 confirmed cloud misconfiguration as the single largest technical breach vector of the year — responsible for 14% of all global breaches in Q1 2026, up from 9% in 2024. The threat is no longer someone breaking in; it is a door left open by the organisation itself. Here is the full UK SME decode for businesses running Azure workloads.

UK Businesses Plan £505k Average Cyber Spend in 2026 — But Only 30% Can Respond to an Incident: The Virtual CIO Gap Every UK SME Must Close

UK Businesses Plan £505k Average Cyber Spend in 2026 — But Only 30% Can Respond to an Incident: The Virtual CIO Gap Every UK SME Must Close

The headline finding from Barclays’ Q1 2026 Business Prosperity Index reveals a paradox defining British IT: 68% of UK businesses plan to increase cybersecurity investment, average cyber budgets have climbed to £505,000, and cloud, cyber and AI together absorb 44% of all planned tech spending — yet fewer than 30% could actually respond to a serious incident. Here is the Virtual CIO decode for UK SMEs closing the investment-to-capability gap.

Cyber Security Breaches Survey 2026: 43% of UK Businesses Breached — What the 612,000-Company Figure Means for Your Proactive IT Support Plan

Cyber Security Breaches Survey 2026: 43% of UK Businesses Breached — What the 612,000-Company Figure Means for Your Proactive IT Support Plan

On 30 April 2026 DSIT and the Home Office published the Cyber Security Breaches Survey 2025/2026 — the UK government’s most authoritative annual measurement of how businesses and charities are faring against cyber crime. Its headline finding is stark: 43% of UK businesses identified a breach or attack in the last 12 months, roughly 612,000 organisations, and an estimated 5.19 million cyber crimes committed against UK businesses over the year. Here is the proactive IT Support decode every UK SME needs now.

Exchange CVE-2026-42897 — OWA XSS Zero-Day Actively Exploited: The Microsoft 365 Patch Plan Every UK SME on On-Premises Exchange Must Run This Week

Exchange CVE-2026-42897 — OWA XSS Zero-Day Actively Exploited: The Microsoft 365 Patch Plan Every UK SME on On-Premises Exchange Must Run This Week

On 4 July 2026, any UK business still running on-premises Microsoft Exchange faces a decision that has quietly changed shape. CVE-2026-42897 — a cross-site scripting zero-day in Exchange Server’s Outlook Web Access — has been actively exploited since mid-May 2026, was added to CISA’s Known Exploited Vulnerabilities catalogue, and carries a Microsoft-assigned CVSS score of 8.1. It requires no attacker privileges: a single crafted email is enough. Here is the full patch plan every UK SME must run this week.

Microsoft SharePoint CVE-2026-45659 — CVSS 8.8 RCE Actively Exploited, CISA KEV 1 July 2026: The 10-Step IT Support Patch Plan Every UK SME Must Run This Week

Microsoft SharePoint CVE-2026-45659 — CVSS 8.8 RCE Actively Exploited, CISA KEV 1 July 2026: The 10-Step IT Support Patch Plan Every UK SME Must Run This Week

Microsoft SharePoint Server — used by thousands of UK businesses to share documents and collaborate — contains a CVSS 8.8 remote code execution flaw (CVE-2026-45659) that CISA confirmed is being actively exploited on 1 July 2026. Patched on 21 May 2026 but accidentally omitted from Microsoft’s May Security Updates bulletin, the fix has been silently available for six weeks — meaning any UK SME running on-premises SharePoint without managed patching is already structurally exposed.

UK Cyber Security & Resilience Bill Clears Commons — Enters Lords 25 June 2026: The 10-Step MSP & SME Compliance Plan Every UK Business Must Start Now

UK Cyber Security & Resilience Bill Clears Commons — Enters Lords 25 June 2026: The 10-Step MSP & SME Compliance Plan Every UK Business Must Start Now

The UK Cyber Security and Resilience Bill passed all House of Commons stages and entered the House of Lords on 25 June 2026 — the most significant expansion of the UK’s cyber regulation framework since NIS 2018, extending mandatory duties to 1,000+ managed service providers and digital supply chains for the first time. With Royal Assent expected by late 2026 and phased enforcement through 2028, every UK SME and MSP now has a closing window to achieve Cyber Essentials certification, implement the CAF controls, and build the evidence base regulators will demand.

Oracle EBS CVE-2026-46817 — CVSS 9.8 Actively Exploited 27 June 2026: The 10-Step UK SME Database Security Audit Plan Every Business Using Oracle Must Run This Week

Oracle EBS CVE-2026-46817 — CVSS 9.8 Actively Exploited 27 June 2026: The 10-Step UK SME Database Security Audit Plan Every Business Using Oracle Must Run This Week

A critical unauthenticated CVSS 9.8 vulnerability in Oracle E-Business Suite’s Payments module — CVE-2026-46817 — was confirmed actively exploited over the weekend of 27–28 June 2026, with attackers targeting unpatched instances via automated HTTP sweeps. Oracle shipped the patch in its May 2026 Critical Security Patch Update, meaning any UK SME running EBS 12.2.3 to 12.2.15 without the May CPU is now exposed to a fully weaponised, no-authentication-required takeover of its Oracle Payments system.

Microsoft’s Biggest-Ever Patch Tuesday — 206 CVEs, 9 June 2026: The 10-Step IT Admin Action Plan Every UK SME Must Run Before Exploit Wednesday Hits

Microsoft’s Biggest-Ever Patch Tuesday — 206 CVEs, 9 June 2026: The 10-Step IT Admin Action Plan Every UK SME Must Run Before Exploit Wednesday Hits

On 9 June 2026 Microsoft released its largest-ever Patch Tuesday, addressing 206 vulnerabilities — including 37 critical flaws, 3 publicly disclosed zero-days and two CVSS 9.8 remote code execution vulnerabilities in the Windows Kernel and HTTP.sys — making it the biggest single security release in the programme’s 23-year history. With Cyber Essentials v3.3 now mandating a strict 14-day patch window for critical fixes, every UK SME still running unpatched Windows systems as of 1 July 2026 is already outside compliance and structurally exposed.

CVE-2026-20230: Cisco Unified CM Actively Exploited — 30 June 2026: The 10-Step VoIP Security Action Plan Every UK SME Must Run This Week

CVE-2026-20230: Cisco Unified CM Actively Exploited — 30 June 2026: The 10-Step VoIP Security Action Plan Every UK SME Must Run This Week

On 24–25 June 2026 attackers began actively exploiting CVE-2026-20230 — a CVSS 8.6 server-side request forgery flaw in Cisco Unified Communications Manager — dropping webshells via automated Tor-routed sweeps and escalating to root on unpatched systems. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 25 June 2026 with a 3-day remediation deadline for federal agencies, and Cisco released patches on 3 June 2026 — meaning any UK SME still running Unified CM without the June fixes is three weeks overdue.

Russia’s £2bn JLR Cyberattack — Revealed 26 June 2026: The Costliest Hack in UK History and the 10-Step Virtual CIO Resilience Plan Every UK SME Needs Now

Russia’s £2bn JLR Cyberattack — Revealed 26 June 2026: The Costliest Hack in UK History and the 10-Step Virtual CIO Resilience Plan Every UK SME Needs Now

On 26 June 2026 The New York Times and TechCrunch revealed that a Russian hacking group was behind the late-August 2025 cyberattack on Jaguar Land Rover — the most expensive cyberattack in UK history. The five-week production shutdown cost the British economy an estimated $2.5 billion (£2bn) and triggered a £1.5 billion UK government bailout. Here is the full decode: what the attack actually involved, why standard criminal ransomware defences would not have stopped it, and the 10-step Virtual CIO resilience programme UK SMEs must implement before the next state-linked attack targets their supply chain.

Scattered Spider Conviction — 22 June 2026: The £29m TfL Breach Playbook Every UK SME Must Study Before the Next Attack

Scattered Spider Conviction — 22 June 2026: The £29m TfL Breach Playbook Every UK SME Must Study Before the Next Attack

On 22 June 2026 two British teenagers pleaded guilty at Woolwich Crown Court to hacking Transport for London — a three-day breach that cost TfL £29m and forced 28,000 employees to reset passwords in person. Here is the full social-engineering decode: how Scattered Spider gained access, why the same tactics work against any UK SME, and the 10-step IT Support plan to close the same identity and access gaps before sentencing day on 16 July 2026.

Need IT Support?

Get in touch with our team for an obligation-free chat about your business IT

Contact Us

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

20
  • Cloud Backup

Backup for Remote Workers: Protecting Distributed Data

20 Sep, 2025

Read more
18
  • Internet & Connectivity

How to Optimise Your Network for Microsoft 365

18 Mar, 2026

Read more
12
  • Database Reporting

Custom Reporting & Dashboard Development Cost in the UK in 2026

12 Apr, 2026

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.