News
Cyber Security News: July 2026
The last fortnight of July was about the ways attackers get in without help from your staff: a phishing campaign that needs no click, firewall-adjacent kit being exploited within days of disclosure, and a UK software supplier breach that puts other firms’ data in play. Here is what happened between roughly 16 and 30 July, and what it means if you run a small business or buy cyber cover.
The UK exposes a Russian phishing campaign that needs no click
On 23 July the NCSC, part of GCHQ, joined cyber agencies in 15 other countries to expose LAUNDRY BEAR, a Russian state-supported group running what it calls a zero-click phishing campaign. The trick is that a target does not have to click anything: they only have to view a malicious email inside a vulnerable version of the Zimbra Collaboration Suite webmail service to be compromised. The campaign has run since July 2025 against Western organisations in defence, government, education, energy, law enforcement, media and technology, and the NCSC urges affected organisations to patch immediately, improve network monitoring and sign up for its free Early Warning service. The wider lesson for a small business is that staff awareness alone will not stop this class of attack, so keeping internet-facing mail and webmail software patched matters as much as training. Our guide to types of phishing attacks and how to spot them covers the human side, and social engineering and BEC cover explains the endorsement that decides whether a policy pays when email is the way in. Read the alert at the NCSC.
Fortinet flaws come under active attack with a three-day patch clock
On 16 July the US cyber agency CISA added two critical Fortinet FortiSandbox flaws, CVE-2026-39808 and CVE-2026-25089, both rated CVSS 9.1, to its Known Exploited Vulnerabilities catalogue and told federal bodies to patch by 19 July. Both are command-injection bugs that let an attacker run commands on the device, one of them without needing to log in first, and both are being exploited in the wild. Edge appliances like firewalls, VPNs and sandboxes have become a favoured way into corporate networks for ransomware crews, so the read for a small firm is to ask whoever runs your network whether any Fortinet kit is exposed and to patch known-exploited flaws fast. Cyber Essentials already expects you to fix flaws like these within 14 days, and our patch deadline calculator works out your date; our guide to Cyber Essentials certification sets out the controls insurers look for, and penetration testing for UK businesses explains how to find exposed kit before an attacker does. Reported by Infosecurity Magazine.
A UK healthcare software firm confirms a data breach
Craneware, an Edinburgh-based UK maker of healthcare billing software, has confirmed a cyberattack in which attackers stole a share of its employee and customer data along with partner records. Details are limited so far, with no group named and no numbers attached, but it is a reminder that a breach at a supplier can expose your business even when your own systems are untouched. If a vendor holds your data, you can still face notification duties, regulatory questions and claims, which is why it is worth checking what your policy does when a third party is the point of failure. Our note on what cyber insurance actually covers and its exclusions explains where third-party incidents sit, GDPR breach compensation covers the liability side, and our cyber insurance readiness checker is a quick way to see whether your basics are in order. Reported in the weekly Privacy Guides breach roundup.