Jessica Entwistle
August 13 2026
Today's brief highlights practical developments across governance, vulnerability management and emerging threat techniques. The NCSC has published new guidance for the water sector on secure connectivity, SharePoint vulnerabilities are being actively exploited following proof-of-concept publication, the Lazarus Group has deployed a Windows zero-day in targeted attacks, and researchers have observed what appears to be the first near-autonomous AI-driven attack on a government target. Each story offers clear operational lessons for UK organisations.
The NCSC has added a water sector example to its Secure Connectivity Principles guidance, marking the first content authored by the Industrial Control System Community of Interest to appear on ncsc.gov.uk. The guidance provides practical advice on securing operational technology networks in water and wastewater environments, addressing connectivity between corporate IT systems, industrial control systems and third-party remote access. The NCSC published the update on 11 August 2026, reflecting ongoing collaboration with critical infrastructure operators to develop sector-specific security guidance that organisations can apply directly to their operational environments.
For UK water companies and organisations managing critical infrastructure, this guidance provides a clear reference point for reviewing how operational networks are segmented, monitored and connected to external systems. Water sector organisations face particular challenges around legacy systems, remote monitoring requirements and the operational impact of connectivity decisions. The NCSC's sector-specific approach helps translate broader security principles into practical steps that reflect the realities of operational technology environments, including the need to balance security, safety and operational continuity.
For UK organisations operating industrial control systems, particularly in water, energy, manufacturing or transport, this is a prompt to review how secure connectivity principles are applied across operational networks. Consider whether network segmentation, remote access controls and monitoring capabilities reflect current NCSC guidance and whether operational technology security responsibilities are clearly assigned and understood across IT, engineering and operational teams.
Source: NCSC UK
Threat actors have begun exploiting CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint, following the public release of proof-of-concept exploit code. SecurityWeek reports that the vulnerability, which carries a CVSS score of 9.1, stems from weak authentication mechanisms and was patched by Microsoft in its July 2026 Patch Tuesday updates. The Hacker News confirms that exploitation activity began shortly after the proof-of-concept was made publicly available, allowing attackers to bypass authentication and potentially gain unauthorised access to SharePoint environments. CISA had previously warned that the vulnerability could be exploited in the wild.
This pattern of rapid exploitation following proof-of-concept publication is increasingly common and creates a compressed window for organisations to apply patches before attacks begin. SharePoint is widely deployed across UK businesses for document management, collaboration and intranet services, often holding sensitive business information, customer data and operational documentation. The authentication bypass nature of the vulnerability means that exploitation does not require existing access or user interaction, making it particularly attractive to opportunistic attackers scanning for unpatched systems.
For UK businesses running SharePoint, this is a prompt to confirm that July 2026 patches have been applied across all SharePoint environments, including on-premises deployments and hybrid configurations. Review whether patch management processes are able to respond quickly when proof-of-concept code is published for critical vulnerabilities, and consider whether SharePoint access logs and authentication monitoring would detect unusual access patterns or bypass attempts.
Source: SecurityWeek
The North Korean threat actor known as Lazarus Group has exploited a Windows zero-day vulnerability to deliver a previously unseen backdoor as part of Operation Dream Job, a long-running espionage campaign targeting defence and aerospace companies. The Hacker News reports that Check Point Research identified the activity affecting organisations across France, Germany, Brazil and India. The zero-day, which has since been patched by Microsoft, allowed the attackers to gain SYSTEM-level access on compromised Windows machines. Infosecurity Magazine notes that the malware used post-quantum key exchange mechanisms to protect delivery of the zero-day exploit, demonstrating sophisticated operational security by the attackers.
Operation Dream Job is a well-established Lazarus campaign that uses fake recruitment approaches to deliver malware to individuals working in defence, aerospace and technology sectors. The use of a Windows zero-day and post-quantum cryptography shows continued investment in sophisticated attack techniques by a persistent and well-resourced threat actor. For UK organisations in targeted sectors, this activity reinforces the importance of endpoint detection, user awareness of social engineering techniques and the operational security challenges posed by nation-state actors who combine technical sophistication with patient, targeted approaches.
For UK businesses in defence, aerospace, technology and related supply chains, this is a prompt to review whether endpoint detection capabilities would identify unusual privilege escalation or SYSTEM-level access, and whether employees are aware of recruitment-themed social engineering techniques. Consider whether security awareness programmes specifically address the risks of unsolicited recruitment contact, particularly for individuals in sensitive roles, and whether incident response plans account for sophisticated, persistent threat actors.
Source: The Hacker News
Israeli cybersecurity firm Dream has reported observing what appears to be the first near-autonomous AI-driven attack on a government target, specifically Taiwan's nuclear safety agency. The Register reports that the attack framework adapted mid-operation, corrected its own mistakes and expanded its scope as it progressed. CyberScoop confirms that the AI system adjusted its approach in response to defensive measures and operational conditions, demonstrating a level of autonomous decision-making not previously observed in live attack scenarios. The researchers described the activity as involving an "agentic swarm" capable of coordinated, adaptive behaviour.
This development represents a meaningful shift in how automated attack tools may operate in future. Traditional automated attacks follow pre-programmed logic and decision trees, whereas near-autonomous AI systems can potentially adapt tactics, learn from failed attempts and adjust targeting in real time without direct human control. For defenders, this creates new challenges around detection, response and attribution, as attack patterns may change dynamically and may not follow predictable sequences. The targeting of a nuclear safety agency also highlights the potential for AI-driven attacks to be directed at sensitive operational technology and critical infrastructure environments.
For UK organisations, particularly those managing critical infrastructure, operational technology or sensitive government functions, this is a prompt to consider whether detection and response capabilities are designed to identify adaptive, non-linear attack behaviour rather than only signature-based or rule-based threats. Review whether security monitoring can detect unusual patterns of reconnaissance, lateral movement or privilege escalation that may not follow traditional attack frameworks, and ensure incident response plans account for rapidly evolving threats that may not behave predictably.
Source: The Register
Today's stories reflect the breadth of security challenges facing UK organisations, from practical operational technology guidance to rapidly exploited vulnerabilities and evolving attack techniques. Mature security practice comes from having clear processes already in place for reviewing sector-specific guidance, applying patches quickly when exploitation is likely, understanding the threat actors relevant to your sector, and building detection capabilities that can identify unusual behaviour rather than only known attack patterns. These are not reactive tasks to be addressed during an incident, but ongoing disciplines that should be embedded in how organisations operate, with clear ownership, regular review and confidence that the fundamentals are in place before threats arrive.