Cookie Consent by Free Privacy Policy Generator

Cyber Brief: NCSC Guidance, SharePoint Exploits and AI Attacks

Today's brief highlights practical developments across governance, vulnerability management and emerging threat techniques. The NCSC has published new guidance for the water sector on secure connectivity, SharePoint vulnerabilities are being actively exploited following proof-of-concept publication, the Lazarus Group has deployed a Windows zero-day in targeted attacks, and researchers have observed what appears to be the first near-autonomous AI-driven attack on a government target. Each story offers clear operational lessons for UK organisations.

NCSC publishes water sector guidance on secure connectivity

The NCSC has added a water sector example to its Secure Connectivity Principles guidance, marking the first content authored by the Industrial Control System Community of Interest to appear on ncsc.gov.uk. The guidance provides practical advice on securing operational technology networks in water and wastewater environments, addressing connectivity between corporate IT systems, industrial control systems and third-party remote access. The NCSC published the update on 11 August 2026, reflecting ongoing collaboration with critical infrastructure operators to develop sector-specific security guidance that organisations can apply directly to their operational environments.

For UK water companies and organisations managing critical infrastructure, this guidance provides a clear reference point for reviewing how operational networks are segmented, monitored and connected to external systems. Water sector organisations face particular challenges around legacy systems, remote monitoring requirements and the operational impact of connectivity decisions. The NCSC's sector-specific approach helps translate broader security principles into practical steps that reflect the realities of operational technology environments, including the need to balance security, safety and operational continuity.

Why it matters

For UK organisations operating industrial control systems, particularly in water, energy, manufacturing or transport, this is a prompt to review how secure connectivity principles are applied across operational networks. Consider whether network segmentation, remote access controls and monitoring capabilities reflect current NCSC guidance and whether operational technology security responsibilities are clearly assigned and understood across IT, engineering and operational teams.

Source: NCSC UK

SharePoint vulnerability exploited following proof-of-concept release

Threat actors have begun exploiting CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint, following the public release of proof-of-concept exploit code. SecurityWeek reports that the vulnerability, which carries a CVSS score of 9.1, stems from weak authentication mechanisms and was patched by Microsoft in its July 2026 Patch Tuesday updates. The Hacker News confirms that exploitation activity began shortly after the proof-of-concept was made publicly available, allowing attackers to bypass authentication and potentially gain unauthorised access to SharePoint environments. CISA had previously warned that the vulnerability could be exploited in the wild.

This pattern of rapid exploitation following proof-of-concept publication is increasingly common and creates a compressed window for organisations to apply patches before attacks begin. SharePoint is widely deployed across UK businesses for document management, collaboration and intranet services, often holding sensitive business information, customer data and operational documentation. The authentication bypass nature of the vulnerability means that exploitation does not require existing access or user interaction, making it particularly attractive to opportunistic attackers scanning for unpatched systems.

Why it matters

For UK businesses running SharePoint, this is a prompt to confirm that July 2026 patches have been applied across all SharePoint environments, including on-premises deployments and hybrid configurations. Review whether patch management processes are able to respond quickly when proof-of-concept code is published for critical vulnerabilities, and consider whether SharePoint access logs and authentication monitoring would detect unusual access patterns or bypass attempts.

Source: SecurityWeek

Lazarus Group exploits Windows zero-day in targeted defence sector attacks

The North Korean threat actor known as Lazarus Group has exploited a Windows zero-day vulnerability to deliver a previously unseen backdoor as part of Operation Dream Job, a long-running espionage campaign targeting defence and aerospace companies. The Hacker News reports that Check Point Research identified the activity affecting organisations across France, Germany, Brazil and India. The zero-day, which has since been patched by Microsoft, allowed the attackers to gain SYSTEM-level access on compromised Windows machines. Infosecurity Magazine notes that the malware used post-quantum key exchange mechanisms to protect delivery of the zero-day exploit, demonstrating sophisticated operational security by the attackers.

Operation Dream Job is a well-established Lazarus campaign that uses fake recruitment approaches to deliver malware to individuals working in defence, aerospace and technology sectors. The use of a Windows zero-day and post-quantum cryptography shows continued investment in sophisticated attack techniques by a persistent and well-resourced threat actor. For UK organisations in targeted sectors, this activity reinforces the importance of endpoint detection, user awareness of social engineering techniques and the operational security challenges posed by nation-state actors who combine technical sophistication with patient, targeted approaches.

Why it matters

For UK businesses in defence, aerospace, technology and related supply chains, this is a prompt to review whether endpoint detection capabilities would identify unusual privilege escalation or SYSTEM-level access, and whether employees are aware of recruitment-themed social engineering techniques. Consider whether security awareness programmes specifically address the risks of unsolicited recruitment contact, particularly for individuals in sensitive roles, and whether incident response plans account for sophisticated, persistent threat actors.

Source: The Hacker News

Researchers observe near-autonomous AI attack on Taiwan government target

Israeli cybersecurity firm Dream has reported observing what appears to be the first near-autonomous AI-driven attack on a government target, specifically Taiwan's nuclear safety agency. The Register reports that the attack framework adapted mid-operation, corrected its own mistakes and expanded its scope as it progressed. CyberScoop confirms that the AI system adjusted its approach in response to defensive measures and operational conditions, demonstrating a level of autonomous decision-making not previously observed in live attack scenarios. The researchers described the activity as involving an "agentic swarm" capable of coordinated, adaptive behaviour.

This development represents a meaningful shift in how automated attack tools may operate in future. Traditional automated attacks follow pre-programmed logic and decision trees, whereas near-autonomous AI systems can potentially adapt tactics, learn from failed attempts and adjust targeting in real time without direct human control. For defenders, this creates new challenges around detection, response and attribution, as attack patterns may change dynamically and may not follow predictable sequences. The targeting of a nuclear safety agency also highlights the potential for AI-driven attacks to be directed at sensitive operational technology and critical infrastructure environments.

Why it matters

For UK organisations, particularly those managing critical infrastructure, operational technology or sensitive government functions, this is a prompt to consider whether detection and response capabilities are designed to identify adaptive, non-linear attack behaviour rather than only signature-based or rule-based threats. Review whether security monitoring can detect unusual patterns of reconnaissance, lateral movement or privilege escalation that may not follow traditional attack frameworks, and ensure incident response plans account for rapidly evolving threats that may not behave predictably.

Source: The Register

Today's Key Actions

  • Review whether operational technology networks, particularly in water, energy or manufacturing environments, reflect NCSC secure connectivity principles, including network segmentation, remote access controls and monitoring capabilities.
  • Confirm that Microsoft SharePoint environments have been patched with July 2026 updates and review whether patch management processes can respond quickly when proof-of-concept exploit code is publicly released for critical vulnerabilities.
  • For organisations in defence, aerospace or technology sectors, review whether endpoint detection would identify unusual privilege escalation and whether security awareness programmes address recruitment-themed social engineering techniques used by persistent threat actors.
  • Consider whether security monitoring and incident response capabilities are designed to detect adaptive, non-linear attack behaviour rather than only signature-based threats, particularly for organisations managing critical infrastructure or sensitive operational environments.
  • Ensure that ownership of operational technology security, vulnerability management, threat intelligence and adaptive threat detection is clearly assigned and understood across IT, security, engineering and operational teams.

Secarma Insight

Today's stories reflect the breadth of security challenges facing UK organisations, from practical operational technology guidance to rapidly exploited vulnerabilities and evolving attack techniques. Mature security practice comes from having clear processes already in place for reviewing sector-specific guidance, applying patches quickly when exploitation is likely, understanding the threat actors relevant to your sector, and building detection capabilities that can identify unusual behaviour rather than only known attack patterns. These are not reactive tasks to be addressed during an incident, but ongoing disciplines that should be embedded in how organisations operate, with clear ownership, regular review and confidence that the fundamentals are in place before threats arrive.

News and blog posts
The North Korean threat actor known as Lazarus Group has exploited a Windows...
Israeli cybersecurity firm Dream has reported observing what appears to be the...
Today's brief highlights practical developments across governance,...
The NCSC has added a water sector example to its Secure Connectivity Principles...