Two ransomware anchors landed on the same evening on Tuesday 28 July 2026, both naming UK victims. The Qilin ransomware group added a UK organisation listed only as Hoc to its leak site at just before 22:00 UK time, its second confirmed UK casualty inside four weeks and the first since Arctic Wolf Labs published the definitive attribution paper on Monday 21 July linking Qilin's initial-access chain to active exploitation of CVE-2026-0257, the PAN-OS GlobalProtect authentication-bypass flaw that Palo Alto Networks patched on Tuesday 13 May 2026 and that CISA added to its Known Exploited Vulnerabilities catalogue on Thursday 29 May. Coinbasecartel, an emerging financially-motivated extortion actor active since April 2026, added Accesso - the UK-headquartered ticketing, virtual-queuing and guest-experience technology provider whose platforms sit under a large fraction of UK theme parks, ski resorts, cultural venues, cathedrals, museums and school-trip attractions - to its leak site at just before 20:00 UK time. Day Forty-One of the DUAA Section 164A regime closes the first calendar month of the new data-protection complaints duty. Three jobs pinned to Friday 31 July (Palo Alto GlobalProtect verification), Monday 3 August (Accesso supplier-question note to ticketing, virtual-queuing and school-trip partners) and end of week (Section 164A first-month five numbers on one sheet).
Three anchors landed inside the four working days from Thursday 23 July to Sunday 26 July 2026. On 23 July the NCSC and fifteen partner agencies exposed LAUNDRY BEAR - the Russian state-supported actor also tracked as Void Blizzard - for a zero-click Zimbra Collaboration Suite espionage campaign using a custom Ulej exploit against CVE-2025-66376 that has been active since July 2025. On 26 July the ExfilSquad ransomware group added the UK Department for Education to its dark-web leak site inside a fourteen-victim, five-country simultaneous drop, claiming approximately six hundred thousand parent and staff records from the Customer Help Portal and seven thousand from the Turing Assessment Portal. And the Cyber Security and Resilience Bill's Lords Committee stage is now confirmed for Tuesday 1 September 2026. Three jobs pinned to Friday 31 July, Wednesday 30 July and end of week for UK schools, charities and small businesses.
Three things landed inside the same seventy-two hours in the week of 14 July 2026. Microsoft shipped the largest Patch Tuesday in its history at more than five hundred and seventy CVEs, including an actively exploited SharePoint Server zero-day (CVE-2026-56164) that CISA added to the Known Exploited Vulnerabilities catalogue the same day with a three-day federal remediation deadline. The Cyber Security and Resilience (Network and Information Systems) Bill had its Lords second reading. And at Woolwich Crown Court, Thalha Jubair and Owen Flowers were each sentenced to five years and six months for the September 2024 Transport for London attack in what the National Crime Agency called the largest cybercrime prosecution ever brought before the UK courts and the first successful conviction under Section 3ZA of the Computer Misuse Act 1990. Three jobs for UK schools, charities and small businesses in the week commencing 21 July: the SharePoint patch and four supplier questions by Friday 25 July, the phone-based password-reset script this week, and the DUAA Section 164A thirty-day rolling check from Monday 28 July.
SOCRadar updated its FortiBleed research this week to name INC Ransom and Lynx as the ransomware brands sitting on the other end of the credential pipeline, with twelve confirmed deployments and 354 domain-admin compromises tied back to the same operator. On Sunday 5 July The Telegraph reported that Foreign Office and UK government logins are on sale on the dark web for up to forty thousand pounds each, alongside credentials at NHS trusts, energy companies and local councils. Arctic Wolf's CISO calls the operation a repeatable credential factory. Four working days from now, on Tuesday 14 July 2026, the Cyber Security and Resilience Bill has its Lords second reading. Three jobs fit the four days: the two-hour FortiBleed exposure check and credential rotation today, the four supplier questions to the top five vendors on Monday, and the DUAA Section 164A paragraph for the complaints page on Tuesday.
The NCSC and DSIT published the Cyber Shield blueprint on Tuesday 7 July 2026 - the UK's plan to hardwire agentic AI into national-scale cyber defence, first trailed by GCHQ Director Anne Keast-Butler at Bletchley Park on 27 May. Six core capabilities: reliable and explainable AI, federated agents, automated vulnerability discovery and mitigation, co-ordinated detection and response, national-level scanning and national-level mitigation. Downing Street pinned it, the same day, to the formal launch of the Cyber Resilience Pledge with more than sixty signatories including Marks and Spencer, Nationwide, Microsoft UK, Vodafone and Capita. Yesterday's post walked through the offensive-AI half of the same seven-day window (JADEPUFFER); Cyber Shield is the defensive-AI half. Three jobs fit the five days before the Cyber Security and Resilience Bill's Lords second reading on Tuesday 14 July 2026: on Friday 10 July write down the two-column list the NCSC blog implies but does not spell out - what fundamentals are in place and which of the six Cyber Shield capabilities you have imitated at your scale; on Monday 13 July run the four supplier questions against your top five vendors; on Tuesday 14 July over lunch, write the AI-application paragraph the DUAA Section 164A complaints inbox owner needs by day thirty.
Sysdig published its JADEPUFFER threat report on Tuesday 7 July 2026 - the first documented case of a ransomware operation in which every hands-on-keyboard step, from reconnaissance through credential theft, lateral movement, privilege escalation and destructive database extortion, was executed by an autonomous large-language-model agent. The operator picked the target and set the goal. The AI did the rest, moving from a failed login to a working credential in thirty-one seconds at one point in the captured session. The initial foothold was an internet-facing Langflow instance unpatched against CVE-2025-3248, a missing-authentication bug fixed by the vendor in April 2025. The agent then pivoted to a production MySQL and Alibaba Nacos server via CVE-2021-29441. Both patches were public. Three jobs fit the six days before the Cyber Security and Resilience Bill's Lords second reading on Tuesday 14 July 2026: inventory every LLM app running against your data on Friday 10 July, audit the credential each one holds the same afternoon, and on Tuesday 14 July write down the one paragraph that says what each AI agent can and cannot do and who owns the exceptions.
Qantas has confirmed that a cybercriminal walked through a third-party Salesforce-hosted customer-service platform used by a Manila call centre and walked out with personal data on 5.7 million customers. Darktrace's Toby Lewis says the breach bears the hallmarks of Scattered Spider - the crew behind Marks and Spencer, Co-op and Harrods last spring and now WestJet, Hawaiian Airlines and Qantas. It is the first big confirmed casualty of the airline wave the FBI, Mandiant and Palo Alto Unit 42 warned about last week. Three jobs fit the 14 days before the Cyber Security and Resilience Bill's Lords second reading on Tuesday 14 July 2026: list the suppliers who can change records or reset credentials on your behalf, send them a four-question side-letter on help-desk verification, and extend your DUAA Section 164A complaints page to name the supplier route.
Two stories landed between Thursday 26 and Friday 27 June 2026. The FBI's public advisory says the cybercrime crew tracked as Scattered Spider has pivoted to airlines, with Mandiant and Palo Alto Unit 42 advisories following the same week, after WestJet, Hawaiian Airlines and Qantas have all confirmed intrusions in the past three weeks. The New York Times and TechCrunch report Russian-speaking criminal hackers behind the 31 August 2025 Jaguar Land Rover attack that cost the UK economy an estimated 1.9 billion pounds. Both share the help-desk social-engineering vector that took down M and S, Co-op and Harrods in spring 2025. Three jobs fit the fifteen days before the Cyber Security and Resilience Bill's Lords second reading on Tuesday 14 July 2026.
The Public Accounts Committee report of Wednesday 24 June 2026 tells DCMS that UK national museums and galleries are being left vulnerable to cyber-attack, with the Government working reactively rather than strategically. Three weeks before the Cyber Security and Resilience Bill's now-scheduled Lords second reading on Tuesday 14 July, and on the Friday close of DUAA Week One, here is what UK charities, schools and SMBs should take from the report and the three jobs that fit the next eighteen days.
DUAA Week One closes on Friday and the Cyber Security and Resilience Bill is in the Lords between its 17 June first reading and a second reading still to be scheduled. The DSIT Cyber Security Breaches Survey 2025/2026 puts 43 per cent of UK businesses and 28 per cent of charities at a breach last year, 91 per cent of universities, 85 per cent of FE colleges and 60 per cent of secondary schools the same. Here is the thirty-day plan for UK schools, charities and SMBs.
On Thursday 18 June 2026 the NCSC issued an alert advising UK organisations on a global credential-harvesting campaign targeting Fortinet firewalls and SSL VPN gateways, with indications of UK impact. CISA issued a parallel hardening advisory. Researchers put the verified dataset at around 74,000 working credential sets across more than 190 countries, in what has been dubbed FortiBleed. The DUAA Section 164A complaints duty switched on the morning after. Here is the four-day, 30-day and 90-day plan for UK schools, charities and businesses.
On 17 June 2026 the NCSC's Richard Horne told RUSI his teams had handled more than 200 cyber incidents affecting UK critical national infrastructure and its supply chain in the year to May 2026, with around three-quarters linked to hostile states - Russia, China and Iran. He reframed cyber as a 'contest' rather than a 'risk' and asked every board to focus on three core capabilities. Thirty-six hours later, the DUAA data protection complaints duty switches on for every UK controller. Here is the four-day, 30-day and 90-day plan for UK schools, charities and businesses.
Three UK education organisations - Powys (13 schools), Great Marlow School and the University of Nottingham - disclosed cyber incidents in the ten days before the new Data (Use and Access) Act complaints duty switches on this Friday 19 June 2026. ShinyHunters used a pre-auth Oracle PeopleSoft zero-day (CVE-2026-35273) against more than 100 organisations, and Microsoft shipped its biggest ever Patch Tuesday on the same day Great Marlow closed. Here is the four-day, 30-day and 90-day plan for every UK school, charity and business.
From 19 June 2026 a new statutory duty under the Data (Use and Access) Act 2025 switches on. Every UK controller - every school, charity and business - must have a working data protection complaints process, an electronic form and at least one alternative route, a 30-day acknowledgement clock, and a record the ICO can ask to see. There are no carve-outs for size. Here is the minimum viable position for Friday week and the 30/60/90-day plan to make it boring.
On 27 May 2026 the Director of GCHQ used the agency's first ever Annual Lecture at Bletchley Park to say UK cyber security needs to be 'ten times more urgent', from boardrooms to living rooms. Eight working days later, on 10 June 2026, the Cyber Security and Resilience Bill reaches report stage in the Commons. We unpack what the speech and the Bill mean for UK schools, charities and businesses - who are largely exempt from the Bill directly but not from its supply-chain cascade - and what to do across the next 30, 60 and 90 days.
On 18 May 2026 the NCSC reissued joint guidance with CISA, the NSA and its Australian, Canadian and New Zealand counterparts on the 'Careful Adoption of Agentic AI Services.' Agentic AI - AI that does not just answer questions but plans, decides and takes actions inside your IT environment - is now arriving inside the SaaS that UK schools, charities and businesses already pay for. We unpack what changes about the risk picture, why the procurement signal is invisible, and what to do across the next 30, 60 and 90 days before switching it on across the organisation.
ShinyHunters compromised Instructure's Canvas LMS via the free Free-for-Teacher programme in late April 2026 and lifted around 3.65 TB of data covering roughly 275 million records and 8,809 institutions worldwide, including Oxford and a long list of other universities. Instructure reached an agreement on 11 May. We unpack the entry route, why it lands harder on UK schools, charities and businesses than it might appear, and what to do across the next 30, 60 and 90 days.
The UK government renewed its call on 12 May 2026 for organisations across the economy to sign the Cyber Resilience Pledge, the voluntary commitment first announced at CYBERUK 2026 on 22 April. The Pledge bundles three actions - board-level cyber ownership, the NCSC's free Early Warning service, and Cyber Essentials across the supply chain - into one signed, dated declaration. We unpack the three actions, why they map onto every major UK cyber story of the last twelve months, and what UK schools, charities and smaller businesses should do over the next quarter to be ready when the public signatory list opens in summer 2026.
BIBA's 2026 broker conference opens in Manchester on 13 May with cyber insurance as a feature topic for the first time, and the timing is not accidental. Premiums, exclusions and claim outcomes are now driven by a small set of security controls - the same controls Cyber Essentials Danzell now treats as auto-fail and the same controls the M&S, Co-op and Harrods stories told us actually matter. We unpack what underwriters are asking in 2026, where claims are getting denied, and what UK schools, charities and smaller businesses should have ready before they renew.
Last week the NCSC took a position it had been carefully avoiding for years: passkeys, not passwords, should now be the default way to log into online services. We unpack what changed in the April 2026 guidance, why it lines up so neatly with Cyber Essentials Danzell, the 2025/2026 breaches survey and the M&S supplier story - and the four things UK schools, charities and smaller businesses should actually do in the next ninety days.
It is one year since Marks & Spencer disclosed the cyber attack that took down its tills, click-and-collect and online store. The attackers did not exploit a zero-day - they phoned an outsourced IT helpdesk and got a password reset on a third-party supplier's account. We walk through what the M&S, Co-op and Harrods incidents really tell UK schools, charities and smaller businesses about supplier and service-desk risk - and the five things to change in the next ninety days.
DSIT published the Cyber Security Breaches Survey 2025/2026 on 30 April 2026. The headline of '43% of UK businesses breached' is broadly flat year on year, but the interesting findings are in the small movements - phishing increasingly AI-assisted, ransomware impact roughly doubled, and supply-chain reviews almost non-existent for smaller organisations. We unpack what the report actually says and the five things UK businesses, charities and schools should change in the next ninety days.
On 27 April 2026, Cyber Essentials v3.3 ('Danzell') replaced Willow as the mandatory question set. For the first time in the scheme's history there are auto-fail questions — missed MFA on a cloud service or a high-risk patch left longer than 14 days will now fail the assessment outright. Here is what changed and what to fix before your next renewal.
A critical pre-auth SQL injection in LiteLLM (CVE-2026-42208, CVSS 9.3) lets attackers steal every API key the proxy holds. Exploitation was observed in the wild within 36 hours of disclosure. Here is what to do this week.
HMRC's biggest tax overhaul in 29 years goes live on 6 April 2026, but 94% of affected businesses say they are not prepared. We break down who is affected, what has actually changed, and what to do if you have left it late.
David Heacock grew a $260 million air filter business and says AI matters more to plumbers than programmers. We unpack the opportunity for UK trades and businesses trying to do more with a small team.
A practical subset of security controls sized for small teams: MFA, endpoint hardening, backup testing, access reviews, and incident response checklists.
A priority sequence for anyone inheriting IT responsibility: audit current state, secure quick wins, establish documentation, review vendors, and build a roadmap.
A decision framework for cloud vs on-premises vs hybrid hosting, weighing data residency, cost structures, skills requirements, and compliance obligations.