Jessica Entwistle
July 28 2026
Today's stories highlight the operational security challenges that come with rapid technology adoption and evolving attacker techniques. From AI chatbot data exposure affecting hundreds of users to active exploitation of network infrastructure vulnerabilities, these developments remind us that security maturity requires clear visibility, timely patching and well-rehearsed response processes. For UK organisations, the common thread is the need to understand where sensitive data flows, how quickly vulnerabilities can be weaponised, and what defensive controls are actually in place when attackers arrive.
The BBC reports that hundreds of conversations with Anthropic's Claude AI chatbot were discovered publicly accessible through Google search results. The issue originated from Claude's "share chat" feature, which allows users to create shareable links for conversations and projects. These links, intended for controlled sharing, were being indexed by search engines and made discoverable to anyone searching for related content. Anthropic has since addressed the indexing issue, but the incident highlights how easily shared AI content can become unintentionally public when default privacy settings are not clearly understood by users.
For UK organisations using AI chatbots for internal work, customer support, research or content creation, this incident is a practical reminder that "share" features often mean "publish" in ways users may not expect. Employees may be using AI tools to draft sensitive documents, analyse confidential data, troubleshoot technical issues or discuss business strategy without realising that shared links can be indexed, forwarded or discovered by unintended audiences. The risk is not theoretical—it is about real business information, customer data or intellectual property becoming searchable and accessible outside the organisation's control.
For UK businesses, this is a prompt to review how AI tools are being used across the organisation and what controls are in place around data sharing. Consider whether employees understand the difference between sharing a link internally and making content publicly discoverable, and whether acceptable use policies clearly address AI chatbot usage, data handling and sharing practices.
Source: BBC Technology
CISA and multiple security vendors report that a maximum-severity vulnerability in Arista VeloCloud Orchestrator on-premises deployments is being actively exploited in the wild. The flaw, tracked as CVE-2026-16812 with a CVSS score of 10.0, is an operating system command injection vulnerability that allows attackers to execute arbitrary code on affected systems. The vulnerability affects the on-premises version of VeloCloud Orchestrator, a platform used to manage SD-WAN infrastructure. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalogue, indicating confirmed exploitation activity. Arista has released patches and organisations running on-premises VeloCloud Orchestrator are advised to apply updates immediately.
For UK organisations using SD-WAN infrastructure, particularly those with on-premises VeloCloud Orchestrator deployments, this represents an immediate and serious risk. SD-WAN platforms sit at the centre of network connectivity, managing traffic routing, security policies and access controls across distributed sites. A command injection vulnerability with a severity score of 10.0 means attackers can gain full control of the orchestrator, potentially allowing them to intercept traffic, modify routing policies, access connected networks or use the compromised platform as a pivot point into the wider environment. The fact that active exploitation is already occurring means this is not a theoretical risk—it is happening now, and unpatched systems are exposed.
For UK businesses running Arista VeloCloud Orchestrator on-premises, this is a prompt to treat patching as an immediate priority and to review whether the platform is appropriately segmented, monitored and protected. Consider whether you have visibility into access logs, configuration changes and unusual activity on the orchestrator, and whether incident response plans account for compromise of core network infrastructure.
Source: CISA Advisories
Infosecurity Magazine reports that ransomware groups are increasingly using EDR kill techniques to disable endpoint detection and response tools before deploying file encryption. According to Halcyon's latest quarterly ransomware report covering Q2 2026, while overall ransomware attack volumes are declining, attackers are adopting more sophisticated obfuscation and evasion techniques that make detection and response significantly harder. EDR kill techniques involve using legitimate drivers, privilege escalation or kernel-level access to terminate or disable security software before the ransomware payload is executed. This trend reflects a broader shift towards more technically capable ransomware operations that invest in bypassing defensive controls rather than relying on volume or opportunistic targeting.
For UK organisations, this development underscores a fundamental challenge in endpoint security: detection tools are only effective if they remain running and capable of reporting when an attack occurs. Ransomware groups understand this, which is why disabling EDR has become a standard step in many attack chains. The operational impact is that organisations can no longer assume their endpoint security stack will alert them to ransomware activity in time to intervene. If attackers successfully disable EDR before encryption begins, the first indication of compromise may be encrypted files and a ransom note rather than a security alert. This makes pre-ransomware detection, network segmentation, offline backups and resilience planning even more critical than they already were.
For UK businesses, this is a prompt to review whether endpoint protection strategies account for the possibility that EDR may be disabled during an attack. Consider whether you have layered detection across network, identity and endpoint layers, whether tamper protection is enabled and monitored, and whether backup and recovery processes can function independently of endpoint security tools.
Source: Infosecurity Magazine
CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalogue based on evidence of active exploitation in the wild. The first, CVE-2025-68686, is a Fortinet FortiOS vulnerability involving exposure of sensitive information to unauthorised actors. The second, CVE-2026-16812, is the Arista VeloCloud Orchestrator command injection flaw discussed earlier. Both vulnerabilities are being actively exploited, and CISA's Binding Operational Directive requires US federal agencies to patch known exploited vulnerabilities within prescribed timescales. While the directive applies to federal agencies, CISA's KEV catalogue is widely used by organisations globally as a prioritisation tool for vulnerability management, reflecting vulnerabilities that are confirmed to be under active attack rather than theoretical risks.
For UK organisations, CISA's KEV catalogue provides a practical and evidence-based prioritisation framework for patch management. When a vulnerability appears on the KEV list, it means attackers are already using it in real-world operations, which makes it a higher priority than vulnerabilities that are merely disclosed or theoretically exploitable. The inclusion of both Fortinet and Arista vulnerabilities in the same update highlights that network infrastructure and security appliances remain high-value targets for attackers. These are the platforms that control access, enforce security policies and manage connectivity across the organisation, which makes them attractive targets for initial access, lateral movement and persistence.
For UK businesses, this is a prompt to review whether vulnerability management processes actively monitor CISA's KEV catalogue and prioritise patching for known exploited vulnerabilities ahead of other updates. Consider whether you have visibility into which network infrastructure, security appliances and edge devices are deployed across the organisation, and whether patching timescales reflect the operational risk of active exploitation.
Source: CISA Advisories
Good security practice is built on understanding where data flows, knowing what is deployed across the network, and having clear processes for responding when things go wrong. The stories today reflect challenges that many organisations face: technology adoption outpacing governance, attackers moving faster than patch cycles, and defensive tools that can be bypassed if attackers gain sufficient access. Mature security comes from treating these as operational realities rather than surprises, and from building habits around visibility, prioritisation and resilience that are already in place before incidents occur. The organisations that respond well to these challenges are the ones that have already done the work to understand their environment, assign clear ownership, and practise the processes they will need when pressure arrives.