Jessica Entwistle
August 17 2026
Today's brief highlights the operational reality that even well-protected environments require layered defence and continuous review. A large-scale Azure data theft campaign affecting Fortune 500 organisations underscores the importance of cloud identity and access governance, while academic research into Windows 11 memory protections reminds us that hardware-level security assumptions can be challenged. Meanwhile, Wireshark's latest release addresses 28 vulnerabilities in widely used network analysis software, and a sustained DDoS attack against the secure messaging platform Threema demonstrates how availability risks remain a practical concern for organisations relying on third-party communication tools.
SecurityWeek reports that a threat actor is claiming to have exfiltrated millions of records from multiple large organisations, including McDonald's, Tata Consultancy Services (TCS), and Vodafone, as part of a coordinated campaign targeting Microsoft Azure environments. The attacker has published sample datasets and is offering access to stolen data, which is said to include customer records, internal documents, and operational information. The campaign appears to focus on organisations with significant Azure footprints, exploiting misconfigurations or compromised credentials to gain access to cloud-hosted data stores. The scope of the breach and the number of affected organisations is still being assessed, but the attacker's claims suggest a sustained and methodical approach to identifying and exploiting weaknesses in cloud identity and access management.
For UK businesses, this incident reinforces the operational importance of cloud security hygiene, particularly around identity governance, privileged access management, and monitoring for unusual data access patterns. Azure environments are widely used across UK organisations, and the risk of misconfigured permissions, overly permissive service accounts, or compromised credentials remains a common pathway for attackers. The incident also highlights the value of logging and alerting on bulk data access or unusual export activity, which can provide early warning of potential exfiltration. For organisations using Azure, this is a prompt to review whether identity and access policies are appropriately scoped, whether multi-factor authentication is enforced for privileged accounts, and whether monitoring is in place to detect anomalous data access patterns.
For UK businesses using Azure, this is a clear prompt to review cloud identity governance, access controls, and monitoring for unusual data export activity. Ensure privileged accounts are protected with multi-factor authentication, that permissions are scoped appropriately, and that logging is configured to detect bulk data access or exfiltration attempts.
Source: SecurityWeek
Help Net Security reports that researchers from the University of Birmingham and Durham University have demonstrated a technique to bypass some of Windows 11's strongest security protections without physically opening or modifying the target machine. The attack, named "Download More RAM," targets a small configuration chip found on Dual In-line Memory Modules (DIMMs), the RAM sticks inside most computers. The researchers found that this chip does not verify the identity of the system or user making configuration requests, allowing an attacker with privileged access to manipulate memory settings in ways that can undermine security features such as Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI). The attack assumes the attacker has already gained administrative or system-level access to the target machine, but it demonstrates that hardware-level security assumptions can be challenged in ways that are not immediately obvious to defenders.
For UK organisations, this research is a reminder that security protections are layered, and that even advanced features such as VBS and HVCI rely on assumptions about the integrity of underlying hardware and firmware. While the attack requires privileged access to the system, it highlights the importance of preventing attackers from gaining that level of access in the first place, and of monitoring for unusual system configuration changes. The research also underscores the value of defence in depth, where multiple layers of protection are in place so that the compromise of one layer does not lead to complete system failure. For organisations using Windows 11, this is a prompt to review whether endpoint detection and response (EDR) tools are configured to alert on unusual system configuration changes, and whether privileged access is appropriately controlled and monitored.
For UK organisations, this is a reminder that preventing privileged access in the first place remains the most effective defence. Review whether endpoint detection tools are configured to alert on unusual system configuration changes, and ensure privileged access is tightly controlled and monitored across Windows 11 estates.
Source: Help Net Security
The SANS Internet Storm Center reports that Wireshark version 4.6.8 has been released, addressing 28 vulnerabilities and 25 bugs. Wireshark is widely used network protocol analyser software, commonly deployed by security teams, network engineers, and IT operations staff for troubleshooting, monitoring, and forensic analysis. The vulnerabilities addressed in this release include issues that could allow an attacker to crash the application or potentially execute arbitrary code by sending specially crafted network traffic or by convincing a user to open a malicious packet capture file. While Wireshark is typically used in controlled environments, the software is often run with elevated privileges and has access to sensitive network traffic, making it a potential target for attackers seeking to compromise security analysis tools or gain insight into network activity.
For UK businesses, this release is a practical reminder that security and network analysis tools require the same patch discipline as any other software. Wireshark is commonly used across IT and security teams, and outdated versions can introduce risk, particularly if analysts are opening packet capture files from untrusted sources or analysing traffic from potentially hostile networks. The vulnerabilities addressed in this release could allow an attacker to disrupt analysis activity, compromise the analyst's workstation, or potentially gain access to sensitive network traffic data. For organisations using Wireshark, this is a prompt to review whether the software is kept up to date, whether users are opening packet capture files from untrusted sources, and whether Wireshark is run in a controlled environment with appropriate access controls.
For UK organisations using Wireshark, this is a straightforward prompt to update to version 4.6.8. Review whether the software is kept current across security and network teams, and ensure analysts are cautious about opening packet capture files from untrusted sources.
Source: SANS Internet Storm Center
Security Affairs reports that Threema, a Swiss-based secure messaging platform, suffered multiple large-scale distributed denial-of-service (DDoS) attacks that caused severe communication outages for users. The attacks disrupted the service for an extended period, preventing users from sending or receiving messages. Threema is used by organisations and individuals who prioritise privacy and secure communication, and the platform is particularly popular in sectors such as healthcare, legal services, and government. The attacks did not affect organisations using Threema On-Prem, a self-hosted version of the platform that runs on the customer's own infrastructure. The incident highlights the operational risk that DDoS attacks pose to cloud-based communication platforms, and the importance of having contingency plans in place for when primary communication channels are unavailable.
For UK businesses, this incident is a reminder that availability is a core component of security, and that reliance on any single communication platform introduces risk. Organisations that depend on Threema or similar secure messaging tools for business-critical communication should consider whether they have alternative communication channels available in the event of a service disruption, and whether staff are aware of how to escalate or communicate during an outage. The incident also underscores the value of understanding the resilience and availability commitments of third-party communication platforms, and of reviewing whether service level agreements and incident response processes are appropriate for the organisation's operational needs. For organisations using Threema, this is a prompt to review whether business continuity plans account for communication platform outages, and whether alternative channels are available and tested.
For UK organisations relying on Threema or similar secure messaging platforms, this is a prompt to review whether business continuity plans account for communication platform outages. Ensure alternative communication channels are available, tested, and that staff understand how to escalate during service disruptions.
Source: Security Affairs
Today's stories reflect the reality that mature security practice is built on layered defence, clear ownership, and habits that are already in place before incidents happen. Cloud security, endpoint protection, vulnerability management, and business continuity are not separate concerns, but interconnected disciplines that require consistent attention and clear accountability. The organisations that respond most effectively to incidents like these are those that have already established the governance, monitoring, and review processes needed to detect, respond to, and learn from security events. Good security is not about reacting to every headline, but about maintaining the discipline and clarity that allows organisations to adapt confidently as the threat landscape evolves.