Resources

SharePoint ToolShell Zero-Day, the TfL Sentencing at Woolwich Crown Court, and the Cyber Security and Resilience Bill's Lords Second Reading: What UK Schools, Charities and SMBs Should Do in the Week After 14 July 2026

Three things landed inside the same seventy-two hours in the week of 14 July 2026. Microsoft shipped the largest Patch Tuesday in its history at more than five hundred and seventy CVEs, including an actively exploited SharePoint Server zero-day (CVE-2026-56164) that CISA added to the Known Exploited Vulnerabilities catalogue the same day with a three-day federal remediation deadline. The Cyber Security and Resilience (Network and Information Systems) Bill had its Lords second reading. And at Woolwich Crown Court, Thalha Jubair and Owen Flowers were each sentenced to five years and six months for the September 2024 Transport for London attack in what the National Crime Agency called the largest cybercrime prosecution ever brought before the UK courts and the first successful conviction under Section 3ZA of the Computer Misuse Act 1990. Three jobs for UK schools, charities and small businesses in the week commencing 21 July: the SharePoint patch and four supplier questions by Friday 25 July, the phone-based password-reset script this week, and the DUAA Section 164A thirty-day rolling check from Monday 28 July.

Key takeaways

  • Microsoft's July 2026 Patch Tuesday was the largest in its history at more than five hundred and seventy CVEs in a single release, including three zero-days already exploited in the wild. CVE-2026-56164 is a missing-authentication elevation-of-privilege bug in on-premises SharePoint Server (Enterprise 2016, Server 2019, Subscription Edition). CISA added it to the Known Exploited Vulnerabilities catalogue on 14 July and set a three-day federal remediation deadline. CVE-2026-56155 is an Active Directory Federation Services elevation-of-privilege flaw also under active exploitation. Attackers are chaining CVE-2026-56164 with older SharePoint weaknesses in the same fingerprint as last year's ToolShell campaign.
  • At Woolwich Crown Court on Thursday 16 July, Mr Justice Turner sentenced Thalha Jubair, twenty, and Owen Flowers, eighteen, to five years and six months each for the September 2024 Transport for London attack. The mechanic was partial employee credentials bought from a criminal forum, followed by a phone call to the IT helpdesk impersonating a TfL employee, followed by a helpdesk worker persuaded to reset the password and bypass two-factor authentication. The National Crime Agency called it the largest cybercrime prosecution ever brought before the UK courts, and the first successful conviction under Section 3ZA of the Computer Misuse Act 1990.
  • The Cyber Security and Resilience (Network and Information Systems) Bill had its Lords second reading on Tuesday 14 July. Baroness Lloyd of Effra opened for the Government; Baroness Harding of Winscombe, Baroness Kidron, Lord Arbuthnot of Edrom and Lord Vaizey of Didcot contributed. The Bill goes into Committee stage in essentially the shape the House of Lords Library research briefing set out: RMSPs brought into the Network and Information Systems regime, twenty-four-hour initial incident reporting to regulators and the NCSC with a seventy-two-hour full report, an RMSP concentration-risk duty, and Secretary of State powers to add sectors and issue national-security directions.
  • On Wednesday 15 July the NCSC formally launched a free Cyber Advisor programme offering thirty-minute one-to-one consultations to small organisations, alongside the existing Cyber Action Toolkit, Funded Cyber Essentials Programme and Early Warning service. If you are the whole security function for a small organisation, that half-hour of NCSC time is now on the shelf and worth booking.
  • Three jobs for the week commencing 21 July. Job One by Friday 25 July: apply the July SharePoint update and rotate ASP.NET machine keys if you run on-premises SharePoint, or send the four supplier questions to your top ten suppliers if you do not. Job Two this week: write the one-page phone-based password-reset and MFA-bypass script for anyone who answers the phone, with the standing rule that password resets are never completed on the initial call. Job Three from Monday 28 July: pull the five DUAA Section 164A thirty-day complaints numbers for the Data Protection lead ahead of the ICO's expected first commentary.

Three things landed inside the same seventy-two hours last week, and between them they redraw the working week for anyone in a UK school, charity or small business who has been half-following the running story of the last two months. On Tuesday 14 July, Microsoft shipped the largest single Patch Tuesday in its history — more than five hundred and seventy CVEs in one release, including an actively exploited zero-day in on-premises SharePoint Server (CVE-2026-56164) that CISA added to its Known Exploited Vulnerabilities catalogue the same day and gave federal agencies just three days to remediate. On the same Tuesday, the Cyber Security and Resilience (Network and Information Systems) Bill had its Lords second reading — the calendar anchor that posts #26, #27, #28, #29, #30 and #31 all pointed at as their tail. And on Thursday 16 July, at Woolwich Crown Court, Mr Justice Turner sentenced Thalha Jubair (twenty, east London) and Owen Flowers (eighteen, Walsall) to five years and six months each for the September 2024 Transport for London cyber-attack — the National Crime Agency calling it the largest cybercrime prosecution ever brought before the UK courts, and the first successful conviction under Section 3ZA of the Computer Misuse Act 1990.

That is a lot to metabolise. The point of today's post is not to walk through any one of the three in isolation — each will be picked over in the trade press for weeks — but to translate what they mean for a UK school office, a charity finance team or a fifteen-person professional services firm working through the last full week of July. The audience for this blog is not the SOC analyst at a FTSE 100 bank. It is the person who is the whole IT function for a two-hundred-pupil primary or a small charity, or the practice manager who is the whole security function for a professional-services SMB, and who has ten hours a week to spend on cyber and needs each of those ten hours to matter.

Start with the SharePoint zero-day, because it is the one that has an active-exploitation clock ticking on it. CVE-2026-56164 is a missing-authentication-for-a-critical-function bug in on-premises SharePoint Server (Enterprise 2016, Server 2019 and Subscription Edition). It requires no existing account, no user interaction, and low attack complexity — an unauthenticated attacker can reach it over the network and elevate privileges. Microsoft confirmed active exploitation in the wild on the day of the patch. CISA added it to the Known Exploited Vulnerabilities catalogue on 14 July and set a remediation deadline of 17 July for all Federal Civilian Executive Branch agencies — three days from patch release. The NCSC's own July 2025 SharePoint ToolShell alert, still live on the NCSC news page, is the template: apply the security update, make sure the Anti-malware Scan Interface is on and configured, run Defender for Endpoint or an equivalent, and rotate SharePoint Server ASP.NET machine keys. Attackers are chaining CVE-2026-56164 with older, previously disclosed SharePoint weaknesses (CVE-2026-32201, CVE-2026-45659, CVE-2026-58644) to steal Internet Information Services machine keys, establish persistence on compromised servers and drop malware — the same mechanical fingerprint as last year's ToolShell campaign, when the Chinese state-linked Linen Typhoon, Violet Typhoon and the Storm-2603 ransomware crew hit finance, healthcare, government and energy targets at scale. The July Patch Tuesday release around it is itself the largest in Microsoft's history: five hundred and seventy CVEs in one drop by the conservative count, six hundred and twenty-two by some others, including two additional zero-days already exploited in the wild — CVE-2026-56155, an elevation-of-privilege flaw in Active Directory Federation Services that hands attackers administrator rights, and CVE-2026-50661, a BitLocker security-feature bypass that lets an attacker with physical access defeat drive encryption. Microsoft has attributed part of the record volume to an AI-powered vulnerability-discovery system it recently deployed against its own Windows codebase — the defensive-AI shift that post #30 traced through the NCSC Cyber Shield blueprint and that pairs, uncomfortably, with the offensive-AI story post #29 walked through in JADEPUFFER.

Next, the TfL sentencing. Owen Flowers and Thalha Jubair pleaded guilty on 22 June, the first day of what had been listed as a six-week trial, and received a fifteen per cent sentence reduction for the plea. The attack itself, from 31 August to 3 September 2024, made one hundred and forty-eight TfL systems inoperable, forced all twenty-seven thousand employees into an office to reset their passwords in person, and cost the transport authority twenty-nine million pounds in recovery. The mechanic is worth pausing on because it is the same mechanic that post #27 walked through for the airline pivot and that post #28 walked through for the Qantas Salesforce tenant: partial employee credentials bought from a criminal forum, a phone call to the IT helpdesk impersonating a TfL employee, a helpdesk worker persuaded to reset the password and bypass two-factor authentication. Deputy Director Paul Foster, head of the National Crime Agency's National Cyber Crime Unit, described Scattered Spider on the day of sentencing as the most significant cybercrime threat to the UK in recent years, and credited TfL's early engagement with law enforcement as the reason the convictions were secured. Mr Justice Turner told the defendants he was satisfied their actions were primarily motivated by selfish bravado, heedless of the consequences on others; he acknowledged their immaturity but also the sophistication, the scale of the impact and the significant planning behind the offending. Section 3ZA of the Computer Misuse Act 1990 — the Act's most serious offence, for unauthorised acts causing significant risk of serious damage — had never been tried to a successful conviction before this one. It is now, on the record, a precedent, and the National Police Chiefs' Council has already cited the case in its ongoing push for the proposed Cybercrime Risk Orders trailed in the May 2026 King's Speech and expected to be introduced in late 2027 or early 2028.

Third, the Bill's second reading. Baroness Lloyd of Effra, Minister for Digital Economy, opened the debate for the Government. Contributions came from Baroness Alexander of Cleveden, Lord Arbuthnot of Edrom, Baroness Harding of Winscombe (former head of NHS Test and Trace and former chief executive of the UK Health Security Agency), Baroness Kidron (Data Protection Foundation) and Lord Vaizey of Didcot. Baroness Bennett of Manor Castle used her speech to signal that the transnational-repression amendment voted down in the Commons last month will be reintroduced in the Lords. The Bill's core is unchanged from the House of Lords Library research briefing that post #26 walked through: bringing Relevant Managed Service Providers (RMSPs) into the Network and Information Systems regime, twenty-four-hour initial incident reporting to regulators and the NCSC with a seventy-two-hour full report, an RMSP concentration-risk duty preventing any single provider from managing services above a threshold that would cause significant national disruption if compromised, and Secretary of State powers to add sectors and issue directions on national-security grounds. The debate did not produce a substantive Government commitment to Royal Assent by year-end, and no Government amendments were tabled — the shape of the Bill going into Committee is essentially the shape post #20 previewed after Anne Keast-Butler's Bletchley Park lecture on 27 May, and that GCHQ named at the time as its moment of consequence.

Layered on top of those three, one smaller item worth naming because it is directly aimed at this blog's audience. On Wednesday 15 July, the NCSC formally launched a free, hands-on Cyber Advisor programme offering thirty-minute one-to-one consultations to small organisations, alongside the existing Cyber Action Toolkit, the Funded Cyber Essentials Programme and the NCSC Early Warning service that the Cyber Resilience Pledge formally pinned as one of its three asks in May. Cyber Advisors will help set up Early Warning and use the alerts to improve defence. The NCSC's own framing quotes the Cyber Security Breaches Survey 2026's baseline that sixty-five per cent of medium and forty-six per cent of small organisations reported a breach or attack last year — the same baseline post #25 walked through on 24 June. If you are the whole security function for a small organisation, that half-hour of NCSC time is now on the shelf. Book it.

Now the three jobs. They are pinned to three specific dates in the week commencing Monday 21 July: a patching job by Friday 25 July, a helpdesk job through the week, and a DUAA regime job that opens on Monday 28 July as the Section 164A duty passes its thirty-day mark.

Job One, by Friday 25 July: the SharePoint patch and the wider Patch Tuesday sweep. If your organisation runs on-premises SharePoint Server (Subscription Edition, 2019 or 2016), apply the July security update this week and rotate the SharePoint ASP.NET machine keys immediately after. Do not wait for a maintenance window; CISA gave federal agencies three days for a reason. If AMSI is not on, turn it on, and make sure it is paired with an active antivirus solution — Defender Antivirus or an equivalent. Confirm you have Defender for Endpoint protection or equivalent detection and response coverage on the SharePoint host. If you do not run on-premises SharePoint yourself — which is most of this blog's audience — the work is a supplier question and takes the four-question shape post #28 walked through for the Salesforce tenant cascade: (i) does any supplier of ours run on-premises SharePoint that touches our data; (ii) if so, when was the July 2026 security update applied and were the ASP.NET machine keys rotated; (iii) if not applied, what is the timeline and what compensating controls are in place until then; (iv) has the supplier been checked against the CISA KEV catalogue for CVE-2026-56164, CVE-2026-56155 and CVE-2026-50661 exposure. Send those questions to your top ten suppliers by Wednesday 23 July and give a Friday 25 July return-by date. In parallel, use the wider Patch Tuesday sweep as the trigger to apply pending Windows and Microsoft 365 updates on all admin devices this week. This is the mundane fundamentals work the NCSC Cyber Shield blueprint called "act now to strengthen the fundamentals" and the direct sister-work to post #24's original FortiBleed rotation checklist and to post #31's Fortinet escalation.

Job Two, this week: the helpdesk vishing script. The TfL judgment gives every organisation in the country a case study to point at when explaining to a board or trustee why phone-based password resets and MFA bypasses are the single most-abused control weakness of the last two years. Write a one-page script this week for anyone who answers the phone in your organisation. It has three parts. First, the standing rule: password resets and MFA bypasses are never completed on the initial call. The caller is politely told the reset request has been logged and a call-back will be made through the number on file in the HR system within a defined window (say, one hour). Second, the verification pathway: the call-back verifies identity through at least two of a set of hard checks — the phone number on the HR record, an in-person confirmation from the line manager, a code sent to a pre-registered device, or a passkey challenge on the target account, per the NCSC's April 2026 passkeys guidance walked through in post #15. Third, the escalation: any request to bypass MFA is escalated to the named security lead before any change is made, and both the request and the outcome are logged. This is not a technology change; it is a written procedure and a fifteen-minute conversation with the reception, office manager or shared services team who handle these calls. It is the direct answer to the help-desk layer post #27 named for the airline pivot and the supplier help-desk layer post #28 named for Qantas. Do it this week; do not wait for a supplier or a consultant.

Job Three, from Monday 28 July: the DUAA Section 164A thirty-day rolling check. The Data (Use and Access) Act 2025 complaints regime — walked through in detail in post #21 — comes into force on 19 June 2026. Monday 28 July is the point at which the first thirty-day rolling window is fully closed for every organisation that started counting on Day One. Pull five numbers together for the Data Protection lead, the trustee board or the SMT: (i) how many data-protection complaints did we receive between 19 June and 28 July; (ii) what was the median and worst-case acknowledgement time under the Section 164A thirty-day duty; (iii) how many complaints were closed inside our internal target and how many were not; (iv) how many were escalated to the ICO; (v) is the complaints-page owner named in post #21's Day-One walkthrough still the named owner, and if the answer is "we do not have one" then that is the single most important thing to fix this week. The ICO's first thirty-day commentary on the new regime is expected this week or next and will set the tone for how the Deputy Commissioner intends to enforce — organisations that can show the numbers before the commentary is published will be in a stronger position than those that cannot.

A short list of things this post is deliberately not doing. It is not predicting how the SharePoint zero-day scales beyond the currently confirmed UK exploitation — the NCSC's July 2025 ToolShell precedent suggests it will get worse before it gets better, but naming victims in advance would not be responsible. It is not predicting the ICO's first thirty-day DUAA enforcement posture under the Deputy Commissioner; the commentary is due and will speak for itself. It is not predicting whether the Bill will complete Royal Assent by year-end or whether the RMSP concentration threshold will be widened by amendment in Committee. It is not predicting the outcome of the Cybercrime Risk Order legislation the National Police Chiefs' Council is pushing for on the back of the TfL judgment. And it is not naming the current Scattered Spider airline UK casualty — the pattern post #27 traced is still developing and we will pick that up when a UK carrier confirms.

The takeaway for a UK school office, a charity finance team or a small professional-services firm is that the week of 14 July was not a policy story you can leave to someone else. Patch the SharePoint estate you own and ask the four supplier questions of the SharePoint estate you rent. Write the phone-based-password-reset script and have the fifteen-minute conversation with your reception team, because the TfL sentencing has just made "we followed the standing script and did not bypass MFA on a phone call" a phrase every UK board will want to hear from its IT function this quarter. And, on Monday 28 July, pull the five DUAA complaints numbers for whoever chairs your governance meeting.

If any of those three jobs would land better with a second pair of eyes — the SharePoint patch verification, the helpdesk script, or the DUAA thirty-day check — our cybersecurity-resilience service is where to start, and a thirty-minute discovery call will scope it into the shape your week allows.

Written by Boris Didov