Cookie Consent by Free Privacy Policy Generator

Cyber Brief: Vulnerabilities, AI governance and supply chain risk

Today's stories share a common thread: the importance of maintaining disciplined security practices across the technologies and platforms that UK organisations rely on every day. Whether it's patching known vulnerabilities under active exploitation, reviewing permissions before deploying AI tools, or recognising sophisticated phishing techniques targeting cloud environments, each story highlights the value of clear ownership, timely action and proportionate governance. These are not dramatic new threats, but reminders that mature security depends on the fundamentals being consistently applied.

JFrog Artifactory and ConnectWise ScreenConnect vulnerabilities under active exploitation

The US Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities catalogue, including three affecting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 and CVE-2026-85706) and one affecting ConnectWise ScreenConnect (CVE-2026-84869). The Register and The Hacker News report that all three JFrog vulnerabilities are being actively exploited in the wild, with patches available. The vulnerabilities involve incorrect authorisation, improper authentication and path traversal issues. CISA's inclusion of these flaws signals that exploitation is confirmed and organisations should treat patching as a priority.

JFrog Artifactory is widely used across UK software development and DevOps teams as a repository manager for build artefacts and dependencies. ConnectWise ScreenConnect is a remote access and support tool commonly deployed by managed service providers and internal IT teams. Both products sit in positions of significant trust within enterprise environments, making them attractive targets for attackers seeking to move laterally, access sensitive code or compromise supply chains. The operational risk here is not theoretical: these vulnerabilities are being exploited now, and organisations using these platforms should assume that attackers are actively scanning for unpatched instances.

Why it matters

For UK businesses using JFrog Artifactory or ConnectWise ScreenConnect, this is a prompt to confirm that patches have been applied and that vulnerability management processes are working as intended. If these platforms are managed by third parties, now is the time to verify that your suppliers have acted. This is also an opportunity to review whether you have clear visibility of where these tools are deployed and who is responsible for maintaining them.

Source: The Register

Microsoft warns of passkey-themed phishing and large-scale financial fraud campaigns

Microsoft has disclosed two phishing campaigns targeting cloud environments and business users. The Hacker News and Dark Reading report that the first campaign involved over one million scam emails sent between 3 and 5 August 2026, impersonating chief executives and using third-party email delivery infrastructure to bypass traditional email security controls. The second campaign used passkey-themed social engineering to trick users into granting access to Microsoft cloud accounts, allowing attackers to exfiltrate data. Both campaigns demonstrate how attackers are adapting their techniques to exploit trust in legitimate platforms and emerging authentication methods.

The use of third-party email infrastructure to deliver phishing at scale is a growing concern for UK organisations, particularly those relying on Microsoft 365 for collaboration and productivity. The passkey-themed phishing is especially notable because passkeys are being promoted as a more secure alternative to passwords, and attackers are already exploiting user unfamiliarity with how they work. For many organisations, this highlights the gap between deploying new authentication technologies and ensuring that users understand how to recognise and respond to social engineering attempts that misuse them. The operational impact is clear: even modern authentication methods require user awareness and organisational vigilance to remain effective.

Why it matters

For UK businesses, this is a reminder to review email security controls, particularly how third-party sending infrastructure is handled, and to ensure that user awareness training reflects current phishing techniques. Organisations deploying passkeys or other modern authentication methods should consider whether users have been given clear guidance on what legitimate authentication prompts look like and how to report suspicious requests.

Source: The Hacker News

Most organisations skip permissions reviews before deploying AI tools in Microsoft 365

A study by Syskit, reported by Infosecurity Magazine, has found that only 43% of organisations deploying AI agents in Microsoft 365 environments completed a permissions review beforehand. The research highlights a significant governance gap: AI tools such as Microsoft Copilot operate with the same permissions as the users who deploy them, meaning they can access, summarise and act on any data those users can see. Without a permissions review, organisations risk AI tools inadvertently exposing sensitive information, creating compliance issues or amplifying existing over-permissioned access across SharePoint, OneDrive and Teams.

For UK organisations, this is a practical governance challenge. Many businesses have accumulated years of loosely managed permissions across Microsoft 365, with users retaining access to files, sites and channels long after they needed them. When AI tools are introduced into this environment, they inherit those permissions and can surface information that users may not have actively accessed in years but still technically have rights to view. This creates both a data protection risk and a potential compliance issue, particularly for organisations handling sensitive personal data, financial records or legally privileged material. The operational lesson here is that AI deployment should not be treated as a purely technical rollout; it requires a clear understanding of what data the AI can access and whether that access is appropriate.

Why it matters

For UK businesses deploying or planning to deploy AI tools in Microsoft 365, this is a prompt to review permissions before rollout, not after. Organisations should consider auditing who has access to what, removing unnecessary permissions and ensuring that AI tools are deployed in a way that reflects the principle of least privilege. This is also an opportunity to clarify who is responsible for permissions governance across collaboration platforms.

Source: Infosecurity Magazine

Revolut confirms customer data breach through fake government requests

TechCrunch reports that Revolut has confirmed a customer data breach caused by fraudulent government data requests. Attackers impersonated law enforcement or regulatory authorities to submit fake legal requests for customer information, successfully obtaining personal data before the fraud was detected. Revolut has notified affected customers and alerted the relevant government agencies, law enforcement and financial regulators. The incident highlights a growing supply chain risk: attackers are increasingly targeting the processes organisations use to comply with legitimate legal obligations, exploiting trust in official channels to gain access to sensitive information.

For UK organisations, this incident is a reminder that supply chain risk extends beyond technology vendors and software dependencies. It also includes the administrative and legal processes that organisations rely on to operate compliantly. Revolut is a financial services provider with mature compliance and legal teams, yet attackers were still able to exploit the process used to respond to government requests. This suggests that even well-resourced organisations can be vulnerable to social engineering that targets operational processes rather than technical systems. The broader lesson is that organisations should consider how they verify the legitimacy of legal requests, regulatory inquiries or official communications, particularly when those requests involve disclosing customer or employee data.

Why it matters

For UK businesses, particularly those in regulated sectors, this is a prompt to review how legal and regulatory requests are handled, who is authorised to respond to them and what verification steps are in place to confirm their legitimacy. Organisations should consider whether they have clear procedures for validating the identity of requesters and whether those procedures are consistently followed across legal, compliance and customer service teams.

Source: TechCrunch

Today's Key Actions

  • Confirm that patches for JFrog Artifactory and ConnectWise ScreenConnect have been applied, and verify that vulnerability management processes are working as intended, particularly for tools managed by third parties.
  • Review email security controls to ensure third-party sending infrastructure is appropriately handled, and update user awareness training to reflect current phishing techniques, including passkey-themed social engineering.
  • Audit permissions across Microsoft 365 environments before deploying AI tools, removing unnecessary access and ensuring that AI agents operate with the principle of least privilege.
  • Review procedures for handling legal and regulatory requests, ensuring that verification steps are in place to confirm the legitimacy of requesters and that those procedures are consistently followed across relevant teams.
  • Ensure that ownership of vulnerability management, email security, permissions governance and legal request handling is clearly assigned and that accountability for these areas is understood across the organisation.

Secarma Insight

Today's stories reflect a consistent theme: mature security practice depends on maintaining clear ownership, timely action and proportionate governance across the platforms and processes that organisations rely on every day. Whether it's patching known vulnerabilities, reviewing permissions before deploying new tools, recognising sophisticated phishing techniques or verifying the legitimacy of official requests, the fundamentals remain the same. Good security is not about reacting to every new headline with urgency; it's about having the discipline, processes and accountability in place to respond proportionately when issues arise. Organisations that invest in these foundations are better positioned to manage risk confidently, even as the threat landscape continues to evolve.

News and blog posts
Today's stories share a common thread: the importance of maintaining...
The US Cybersecurity and Infrastructure Security Agency (CISA) has added five...
Microsoft has disclosed two phishing campaigns targeting cloud environments and...
A study by Syskit, reported by Infosecurity Magazine, has found that only 43%...