Jessica Entwistle
September 16 2026
Today's brief brings together stories that highlight the breadth of modern security challenges facing UK organisations. From state-sponsored surveillance tools targeting individuals at risk, to supply chain vulnerabilities in widely deployed enterprise technology, to the growing insider threat posed by fraudulent hiring practices, the common thread is the need for clear visibility, disciplined processes and practical defences that work across technical, operational and human risk.
The National Cyber Security Centre (NCSC) has published a joint advisory with international partners exposing CHOSEN BRICK, a sophisticated spyware tool used by Iranian state actors to target dissidents, activists and journalists. The NCSC reports that the malware has been deployed to conduct surveillance, steal communications and compromise devices belonging to individuals deemed threats to the Iranian regime. The advisory includes detailed technical analysis of the malware's capabilities, indicators of compromise, and practical guidance to help organisations and individuals at risk detect and defend against the threat. The disclosure is part of a coordinated effort to raise awareness of the targeting and provide actionable intelligence to those who may be affected.
For UK organisations, particularly those working with human rights groups, media organisations, academic institutions, legal practices or civil society networks, this advisory is directly relevant. Many UK-based individuals and organisations maintain contact with diaspora communities, activists and journalists who may be at heightened risk of state-sponsored surveillance. The operational context here is that spyware targeting is not limited to the individuals themselves; it can extend to their professional networks, colleagues, legal representatives and the organisations that support them. Understanding the threat profile and ensuring that appropriate technical and operational safeguards are in place is an important part of duty of care for organisations working in these sectors.
For UK businesses working with at-risk communities or individuals, this is a prompt to review endpoint security, mobile device management policies and awareness training for staff who may be targeted. The NCSC advisory provides specific indicators of compromise and detection guidance that security teams can use to assess whether devices or networks have been affected. Ensuring that staff understand the risk, know how to report suspicious activity and have access to secure communication channels is a practical and proportionate response.
Source: NCSC UK
Apple has released an unusually large volume of security patches as part of its September 2026 update cycle, addressing vulnerabilities across iOS, iPadOS, macOS, watchOS and other platforms. The Register reports that the update includes fixes for a record-setting number of bugs, many of which affect core system components, WebKit, kernel-level code and device drivers. While Apple has not disclosed active exploitation of the majority of these vulnerabilities, the scale of the patching effort reflects the ongoing impact of the Mythos vulnerability disclosure initiative, which has driven a significant increase in reported flaws across the software industry throughout 2026. The update is available now and Apple is urging users and organisations to apply it promptly.
For UK organisations managing Apple devices across their estate, this update represents a significant patching task that should be prioritised. Apple products are widely used in enterprise environments, particularly for executive teams, creative departments, mobile workforces and bring-your-own-device programmes. The volume of patches increases the operational risk that something may break during deployment, but it also underscores the importance of timely updates. Delaying patches on widely used consumer and enterprise devices creates exposure, particularly when vulnerabilities affect core system functions or web rendering engines that are targeted by attackers. The operational challenge is balancing the need for rapid deployment with the need for testing and rollback capability.
For many organisations, this is a reminder to review patch management processes for Apple devices and ensure that mobile device management platforms are configured to deploy updates in a controlled and monitored way. Testing updates on a representative sample of devices before broad deployment, ensuring rollback plans are in place, and communicating clearly with users about the importance of applying updates are all practical steps that reduce risk without creating unnecessary disruption.
Source: The Register
Cisco has confirmed that a zero-day vulnerability in its Secure Email Gateway product has been actively exploited in the wild before a patch was made available. CyberScoop reports that the flaw allows attackers to bypass security controls and gain unauthorised access to email gateway systems, though Cisco has not disclosed the specific nature of the attacks, the scope of impact across its customer base, or the identity of the threat actors involved. A patch has now been released, and Cisco is urging customers to apply it immediately. The company has also published indicators of compromise and guidance to help organisations determine whether their systems have been affected.
For UK organisations using Cisco Secure Email Gateway, this is a high-priority issue that requires immediate attention. Email gateways sit at a critical point in the security architecture, handling inbound and outbound email traffic, filtering malicious content and enforcing data loss prevention policies. A compromised email gateway can provide attackers with access to sensitive communications, the ability to intercept or modify messages, and a foothold for further network compromise. The fact that this vulnerability was exploited before disclosure means that some organisations may already have been affected without knowing it. The operational priority is to patch quickly, review logs for signs of compromise, and ensure that email gateway security is part of regular monitoring and incident response processes.
For UK businesses, this is a prompt to review whether Cisco Secure Email Gateway is deployed in your environment, ensure the patch is applied as a matter of urgency, and check logs for unusual activity or indicators of compromise. If your email gateway is managed by a third party or service provider, confirm that they are aware of the issue and have taken action. Email security is a foundational control, and ensuring it is properly maintained and monitored is essential.
Source: CyberScoop
A new report from Infosecurity Magazine highlights a significant and growing insider threat challenge: the majority of fraudulent job candidates are successfully hired and receive corporate credentials, system access and sensitive data before their deception is detected. The report, based on research into hiring fraud trends, found that attackers are using increasingly sophisticated methods to pass background checks, fake references and identity verification processes. In many cases, fraudulent hires gain access to email, collaboration tools, customer data and internal systems before red flags are raised. The report warns that this trend presents a serious risk to organisations, as these individuals may be working on behalf of criminal groups, nation-state actors or competitors seeking to steal intellectual property, conduct espionage or facilitate ransomware attacks.
For UK organisations, this is a reminder that insider threat does not only come from disgruntled employees or accidental mistakes. It can also come from individuals who were never legitimate employees in the first place. The operational challenge is that traditional hiring processes, particularly in remote or hybrid work environments, may not be sufficient to detect sophisticated identity fraud. Once a fraudulent hire has credentials, they have the same access as any other employee, and their activity may not trigger immediate suspicion. The risk is compounded in organisations with rapid hiring cycles, high turnover, or reliance on contractors and third-party workers. The report underscores the need for stronger identity verification, continuous monitoring of user behaviour, and clear processes for revoking access quickly when concerns are raised.
For UK businesses, this is a prompt to review hiring and onboarding processes, particularly for remote workers, contractors and roles with access to sensitive systems or data. Consider whether identity verification is robust enough, whether background checks are being conducted by trusted providers, and whether user behaviour analytics or insider threat monitoring tools are in place to detect unusual activity after someone is hired. Ensuring that access is granted on a least-privilege basis and that offboarding processes are clear and consistently followed are also practical steps that reduce risk.
Source: Infosecurity Magazine
Today's stories reflect the reality that security risk comes from multiple directions at once: state-sponsored targeting, supply chain vulnerabilities, zero-day exploitation and insider threats that begin before someone even joins the organisation. The common thread is that mature security practice depends on clear processes, consistent monitoring and the ability to respond quickly when something changes. Good security is not about reacting to every headline; it is about having the right controls in place, knowing who is responsible for them, and ensuring that those controls are tested, maintained and understood across the organisation. The organisations that manage these risks well are the ones that treat security as a continuous discipline rather than a series of urgent responses.