Three anchors landed inside the four working days from Thursday 23 July to Sunday 26 July 2026. On 23 July the NCSC and fifteen partner agencies exposed LAUNDRY BEAR - the Russian state-supported actor also tracked as Void Blizzard - for a zero-click Zimbra Collaboration Suite espionage campaign using a custom Ulej exploit against CVE-2025-66376 that has been active since July 2025. On 26 July the ExfilSquad ransomware group added the UK Department for Education to its dark-web leak site inside a fourteen-victim, five-country simultaneous drop, claiming approximately six hundred thousand parent and staff records from the Customer Help Portal and seven thousand from the Turing Assessment Portal. And the Cyber Security and Resilience Bill's Lords Committee stage is now confirmed for Tuesday 1 September 2026. Three jobs pinned to Friday 31 July, Wednesday 30 July and end of week for UK schools, charities and small businesses.
Key takeaways
- The NCSC, CISA, the FBI, the NSA and fifteen partner national agencies exposed LAUNDRY BEAR - the Russian state-supported actor also tracked as Void Blizzard - on Thursday 23 July for a zero-click espionage campaign against Zimbra Collaboration Suite that has been active since July 2025. The custom Ulej exploit (Улей, beehive in Russian) targets CVE-2025-66376, a stored cross-site-scripting bug in the Zimbra Classic UI that Zimbra fixed in versions 10.0.18 and 10.1.13 on 6 November 2025. The mitigations advice names third-party passkey authentication in front of Zimbra by name.
- The ExfilSquad ransomware group added the UK Department for Education to its dark-web leak site on Sunday 26 July inside a fourteen-victim, five-country simultaneous drop of more than one hundred and fifteen million records. The named systems are the DfE Customer Help Portal at customerhelpportal.education.gov.uk (approximately six hundred thousand records - full names, email addresses, phone numbers and job titles of parents, teachers and education providers) and the Turing Assessment Portal at turing-assessment.education.gov.uk (approximately seven thousand records).
- The Cyber Security and Resilience (Network and Information Systems) Bill's Committee stage in the House of Lords - the first chance for line-by-line examination of the Bill in the second chamber - is now confirmed for Tuesday 1 September 2026. That retires the six-post before-the-Lords-second-reading calendar bracket and opens a new five-working-week window to Committee. The Bennett transnational-repression amendment and the RMSP concentration-risk duty are the two amendment areas most likely to move.
- Job One for the week is the Zimbra patch review plus passkeys audit by Friday 31 July. If you run Zimbra, confirm the version is on or above 10.0.18 or 10.1.13 and search IMAP logs for unexpected app-specific credentials named ZimbraWeb - that is the Ulej fingerprint. If you do not, use the joint advisory as the excuse to complete the passkeys audit the NCSC April 2026 passkeys blog recommended. Job Two is a DfE-derived phishing and vishing script for the front office by Wednesday 30 July, updated for the six-hundred-thousand-record ExfilSquad leak.
- Job Three is the DUAA Section 164A five numbers ready for the ICO Deputy Commissioner's Day-Thirty commentary by end of week. Monday 28 July is Day Forty of the Section 164A regime that commenced on 19 June, and the first ICO public commentary on how the acknowledgement discipline is reading in practice is now due. The five numbers are complaints received in the rolling thirty days, complaints acknowledged inside thirty days, median acknowledgement time, complaints escalated, and the named owner on your public complaints page.
Three things landed inside the four working days between Thursday 23 July and Sunday 26 July that between them redraw the working week for anyone in a UK school, charity or small business who has been half-following the running cyber story of the last two months. On Thursday 23 July, GCHQ's National Cyber Security Centre joined CISA, the FBI, the NSA and fifteen other national agencies in a joint advisory exposing LAUNDRY BEAR — the Russian state-supported actor also tracked as Void Blizzard — for a zero-click espionage campaign that has been quietly stealing email, passwords and two-factor tokens from Zimbra Collaboration Suite users since July 2025. Two days later, on Sunday 26 July, the ransomware crew ExfilSquad added the UK Department for Education to its dark-web leak site as part of a fourteen-victim, five-country simultaneous drop, claiming approximately six hundred thousand parent and staff contact records from the DfE Customer Help Portal and a further seven thousand records from the Turing Assessment Portal. And on the parliamentary side, the Lords Government Whips' Office confirmed that the Cyber Security and Resilience (Network and Information Systems) Bill's Committee stage — the first line-by-line examination of the Bill in the second chamber — will begin on Tuesday 1 September 2026, which retires the "before the Lords second reading" calendar bracket post #26, post #27, post #28, post #29, post #30, post #31 and post #32 all pointed at, and opens a new five-working-week bracket to Committee.
The audience-translation point is that each of the three anchors targets a different layer of the same working week. LAUNDRY BEAR is a state-sponsored espionage story that reads as remote until you notice that its actual technical demand is the exact passkeys-and-phishing-resistant-MFA move post #15 walked through in April — and the mitigations advice inside the joint advisory names third-party passkey authentication in front of Zimbra by name. The DfE ExfilSquad leak is the concrete UK-education case study that turns any parent-and-staff communications channel into an obvious phishing and vishing target from Monday morning; if you are a UK school your parent contact list is now overlapping with a six-hundred-thousand-record leak on a Russian-language dark-web forum, and the vishing-and-helpdesk shape post #27 and post #28 walked through in June is the shape that will be used against your front office this week. And the Bill's Committee date on 1 September is the calendar peg that lets you plan the next five weeks of governance-and-supplier work rather than reacting to it: the RMSP scope, the twenty-four-hour and seventy-two-hour incident-reporting duty, and the Secretary of State's regulation-making powers are now inside a fixed five-week window rather than a moving one.
Take the three anchors in turn. LAUNDRY BEAR — the Russian espionage crew previously prosecuted by the US Department of Justice in Boston in the FSB Void Blizzard indictment on 9 July — has been running a novel exploit against CVE-2025-66376, a stored cross-site-scripting bug in the Zimbra Classic UI that Zimbra patched in versions 10.0.18 and 10.1.13 on 6 November 2025. The mechanic is the interesting part. Instead of the traditional phishing shape where a user has to click a link or open an attachment, an HTML email that carries a specially-crafted JavaScript payload is enough on its own — the payload fires the moment the recipient views the message inside a vulnerable Zimbra webmail client. LAUNDRY BEAR's custom tool for this — named Ulej (Улей, "beehive" in Russian) — mints a fake application-specific credential called "ZimbraWeb", quietly enables IMAP access as a second foothold, exfiltrates the email address, password and 2FA tokens, and then aggregates the take at scale. More than ten organisations have already been confirmed compromised across the Defence Industrial Base, federal and local government, law enforcement, education, media, energy, technology and NGOs in the United States, and the Ukrainian government was one of the first named targets. The joint advisory is unusually explicit about mitigations for organisations that do not run Zimbra directly: patch to a current supported version if you do, and — whether you do or not — consider a third-party authentication service that supports passkeys sitting in front of Zimbra and any other webmail or SaaS that does not natively support passkeys, so an autocompleted or reused password cannot be silently harvested from a compromised browser session. That is post #15's recommendation, restated by fifteen national agencies against the backdrop of an active espionage campaign.
The DfE ExfilSquad leak is the concrete UK anchor. Late on Sunday 26 July, ExfilSquad published a simultaneous drop naming fourteen alleged victims across five countries — banks, airlines, municipalities, university and school-district systems, and government ministries — totalling more than one hundred and fifteen million exfiltrated records. The UK Department for Education is on that list. The two named systems are the DfE Customer Help Portal at customerhelpportal.education.gov.uk (the front-door enquiry portal used by teachers, parents and education providers to raise queries with the Department, from which approximately six hundred thousand records are claimed to have been taken — full names, email addresses, phone numbers and job titles) and the Turing Assessment Portal at turing-assessment.education.gov.uk (the portal education providers use to assess applications under the Turing Scheme, from which around seven thousand records are claimed). ExfilSquad has been publishing steadily through July — including District of Columbia Public Schools and Newcastle University earlier the same weekend — and the group's shape is consistent with the escalation pattern post #22 tracked at the start of the current UK-education wave. The DfE has not, at the time of writing, published a public statement confirming or contesting the scope of the ExfilSquad claim, and the most recent official DfE update on GOV.UK is the Further Education update of Tuesday 22 July, which does not mention the incident. That absence of confirmation is the wrong reason to wait: the claim is on a public dark-web leak site, the affected portals are named, and the population — teachers, parents, education providers — is exactly the population every UK school, multi-academy trust and further-education college is in daily contact with. If your school-year new-intake letter goes out on Wednesday, the phishing-and-vishing follow-up is on Friday.
The third anchor is parliamentary. The Cyber Security and Resilience (Network and Information Systems) Bill had its Lords second reading on Tuesday 14 July, the calendar peg that closed the six-post bracket from post #26 through post #32. The Lords Government Whips' Office has now confirmed that Committee stage — the first line-by-line examination in the second chamber — will begin on Tuesday 1 September 2026. That is the natural next calendar peg for anyone tracking the RMSP-into-scope, twenty-four-hour initial and seventy-two-hour full incident-reporting duty, RMSP concentration-risk duty, and the Secretary of State's power to add sectors and set requirements by regulation that the House of Lords Library research briefing set out. Baroness Bennett of Manor Castle's transnational-repression amendment named in post #32 is the one to watch for reintroduction in Committee; the Bennett draft would extend the Bill's reach into cyber attacks connected with foreign state intimidation of diaspora communities in the UK. The five working weeks between now and 1 September are the window in which trade bodies, sector groups and individual RMSPs — if that is the shape you find yourself in after the SI defining Relevant Managed Service Providers lands — can put written evidence in front of peers before the amendments crystallise.
The sub-anchor for the week is quieter but important. Monday 28 July is Day Forty of the DUAA Section 164A regime that commenced on 19 June and that post #21, post #24, post #25 and post #32 each walked through in sequence. The first Day-Thirty rolling window closed on Monday 21 July for any organisation that started counting on Day One, and the first ICO public commentary on how the Deputy Commissioner's Office is reading the acknowledgement discipline in practice — whether that commentary lands as a Deputy Commissioner speech, a Regulator's Diary blog, or an update to the ICO's DUAA guidance page — is now due. The right posture for the audience is not to predict what the commentary will say but to have the five numbers ready for whenever it arrives: complaints received in the rolling thirty days, complaints acknowledged inside thirty days, median acknowledgement time, complaints escalated, and the named owner on the public complaints page. That is Job Three.
Three jobs, pinned to three specific dates in the working week ahead.
Job One — Zimbra patch review plus passkeys audit, by Friday 31 July. If your organisation runs Zimbra Collaboration Suite on-premises or through a hosted provider, confirm the running version and confirm it is on or above 10.0.18 or 10.1.13 — the two branches that received the CVE-2025-66376 fix in November 2025. If it is not, the joint advisory is explicit that patching immediately is the first action, followed by a review of network logs for the indicators of compromise CISA has published in its AA26-204A advisory and a search of your IMAP logs for unexpected app-specific credentials named "ZimbraWeb" (that is the fingerprint Ulej leaves). If you do not run Zimbra, Job One is still yours: use the joint advisory as the excuse to complete the passkeys audit the NCSC's April 2026 passkeys blog recommended and that post #15 walked through in detail. Name the applications where a webmail or SaaS login does not natively support passkeys, put a third-party authentication service that does in front of them, and switch off any autocomplete-driven password vault export path from browsers your staff use on shared or remote-desktop endpoints. The four supplier questions post #31 walked through — patch status, disclosure timeline, contractual notification duty, and evidence — apply directly to any hosted Zimbra provider and to any other webmail or collaboration supplier you depend on. This is the mundane fundamentals move that post #30's Cyber Shield "act now to strengthen the fundamentals" checklist points at, and the direct sister of the FortiBleed credential-rotation and MFA-recheck work post #24 walked through.
Job Two — a DfE-derived phishing-and-vishing script for the front office, in place by Wednesday 30 July. Write a three-part briefing note for every member of staff who takes a phone call from a parent, an education provider, a supplier or a trustee this week. Part one: a paragraph that names the DfE ExfilSquad leak by name, states clearly which portals are named in the claim (the Customer Help Portal and the Turing Assessment Portal), and states which fields are alleged to have been taken (name, email, phone, job title). Part two: three concrete red flags for the front office to listen for on calls this week — a caller who quotes a genuine-sounding parent name and phone number as their opening credential; a caller claiming to be from the Department for Education, a local authority, an academy trust head office or an exam-board technical helpdesk with an unusual urgency; and any request to reset a password or MFA credential without an in-person or video-verified callback on a number your organisation controls. Part three: the verified callback procedure — the person on the phone waits while your front-office member of staff calls back on the number in your directory, not the number the caller offers. That is the shape post #27's in-house helpdesk vishing paragraph and post #28's supplier-side helpdesk vishing paragraph pointed at, updated for the DfE-derived contact list that is now in play. If your organisation is a school, the parent-newsletter equivalent — a short, calm note explaining that a national portal leak means parents should expect an uptick in DfE-themed phishing emails and text messages, and confirming which contact routes the school itself will and will not use — is the second half of Job Two and the piece the post #22 education-sector work was written to make routine.
Job Three — DUAA Section 164A five numbers ready for the ICO Day-Thirty commentary, by end of week. The five numbers are the ones post #32 named for the 28 July count and the ones that any Deputy Commissioner speech, Regulator's Diary blog or DUAA guidance-page update in the week ahead will read against. One: complaints received in the rolling thirty days to Monday 28 July. Two: complaints acknowledged inside the thirty-day statutory window under Section 164A. Three: median time to acknowledgement — not the maximum, not the mean; the median is the number that tells the ICO whether the process is working under load. Four: the count of complaints escalated to the ICO by data subjects because the acknowledgement or the resolution did not land in the statutory window. Five: the named owner on your public complaints page and the last-reviewed date beside that name. The three-week Cyber Security Breaches Survey 2025-26 baseline post #25 referenced — sixty-five per cent of medium businesses and forty-six per cent of small businesses experiencing a cyber breach or attack in the last twelve months — is the frame the ICO's DUAA commentary will sit alongside; complaints volumes will rise from the ExfilSquad DfE leak, from the LAUNDRY BEAR fallout at any organisation that has been on Zimbra, and from the tail of the FortiBleed and SharePoint ToolShell campaigns post #31 and post #32 tracked. The Day-One complaints-page owner post #21 recommended is the person who owns Job Three.
What is not in this post. It does not name a UK school, multi-academy trust, charity or business as an ExfilSquad casualty beyond the Department for Education itself; the fourteen-victim ExfilSquad drop on 26 July includes education targets in the United States and elsewhere but no named UK entity below the DfE itself has been added to the leak site at the time of writing. It does not predict the Zimbra count of confirmed UK LAUNDRY BEAR victims — the joint advisory names more than ten confirmed compromises internationally but does not name specific UK organisations, and speculative naming would neither be responsible nor useful. It does not predict which amendments will pass in the Bill's Committee stage on 1 September or in the subsequent Lords committee days, though the Bennett transnational-repression amendment and the RMSP concentration-risk duty are the two most likely to move. It does not predict the ICO's Day-Thirty DUAA commentary content, either the shape (Deputy Commissioner speech, Regulator's Diary blog, or guidance-page update) or the enforcement posture. It does not name the next Scattered Spider UK airline confirmation (post #27, post #28 and post #32 have all held on that point) and it does not predict how the NPCC Cybercrime Risk Order push post #32 named will land inside the Bill's Committee stage or as separate legislation.
The takeaway for the week commencing 28 July 2026 is that three anchors landing inside four working days — a state-espionage joint advisory that names passkeys as the fifteen-national-agency mitigation, a UK education-sector ransomware leak that puts approximately six hundred thousand parent and staff contact records into circulation, and a parliamentary Committee date that opens a five-week window on the Bill — collectively push the same working conclusion that the last seven posts have pushed. The fundamentals are the deliverable. The three jobs are patch and passkeys audit, front-office vishing script, and the DUAA five numbers, pinned to Friday 31 July, Wednesday 30 July and end of week. If any of those three jobs would land better with a second pair of eyes — the Zimbra-and-passkeys review, the DfE-derived front-office script, or the DUAA Day-Thirty numbers work — our cybersecurity-resilience service is where to start, and a thirty-minute discovery call will scope it into the shape your week allows.