𝗣𝗮𝘁𝗰𝗵𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗲 𝗶𝘀𝗻'𝘁 𝗲𝗻𝗼𝘂𝗴𝗵
Attackers are moving to new exploits within days of a warning, so monitoring and response speed now matter as much as the patch itself.

27th July - 2nd August 2026
Each week, Cyber Radar brings together the latest cyber security, resilience and regulatory developments, with clear insight into what they mean for organisations.
This week's developments show why organisations need faster patching discipline, tighter oversight of trusted suppliers and platforms, and stronger governance around AI-driven attack tools.
Subscribe to receive the weekly highlights and scroll down to explore this week's stories.
Social engineering on a support desk exposed 600,000+ records of school and university staff.
The department has notified the Information Commissioner's Office after confirming the breach.
Test whether your service desk staff can be tricked into resetting access without verification.
State-linked hackers switched from a Zimbra webmail flaw to a new Outlook Web Access exploit.
The backdoor grants itself mailbox-owner rights, so it survives a full device re-image.
Patch Exchange Outlook Web Access promptly and audit mailbox folders for unusual permission changes.
Hackers locked out operators at US utilities by hijacking exposed industrial controllers.
Over 4,000 exposed Rockwell controllers were found reachable from the open internet.
Take stock of any internet-facing industrial controllers and remove direct exposure where possible.
A hacker let an artificial intelligence model scan, choose and attack targets with barely any human input.
The AI compressed hours of manual reconnaissance into minutes, researchers confirmed.
Start reviewing how your AI governance policy addresses autonomous, agent-driven threats.
𝗣𝗮𝘁𝗰𝗵𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗲 𝗶𝘀𝗻'𝘁 𝗲𝗻𝗼𝘂𝗴𝗵
Attackers are moving to new exploits within days of a warning, so monitoring and response speed now matter as much as the patch itself.
𝗧𝗿𝘂𝘀𝘁𝗲𝗱 𝗿𝗼𝘂𝘁𝗲𝘀 𝗻𝗲𝗲𝗱 𝘁𝗶𝗴𝗵𝘁𝗲𝗿 𝗼𝘃𝗲𝗿𝘀𝗶𝗴𝗵𝘁
Support desks, suppliers and third-party platforms are now common entry points, so access and verification controls deserve the same scrutiny as core systems.
𝗔𝗜 𝗶𝘀 𝗿𝗮𝗶𝘀𝗶𝗻𝗴 𝘁𝗵𝗲 𝘀𝗽𝗲𝗲𝗱 𝗼𝗳 𝗲𝘀𝗰𝗮𝗹𝗮𝘁𝗶𝗼𝗻
Automated tools can now find and exploit basic weaknesses in minutes, making internet exposure and default credentials more urgent to close.
RightCue has delivered cyber security compliance and assurance since 2009. We are an NCSC Assured Service Provider, CREST accredited, and a Government Commercial Agency supplier. We work across Defence, Healthcare, Financial Services and Technology, helping organisations meet today’s regulatory requirements and prepare for what comes next.

.png?width=1000&height=1000&name=headshot_3_branded%20(1).png)
%20Act%202025.jpg?width=1924&height=1012&name=Data%20(Use%20and%20Access)%20Act%202025.jpg)
The Data (Use and Access) Act 2025, known as the DUAA, has changed the UK's data protection rules. Not dramatically enough to replace UK GDPR, but meaningfully enough that small and medium-sized businesses should take notice.

Cyber resilience starts at the top. RightCue is proud to have signed the UK Government's Cyber Resilience Pledge, joining organisations across Britain in making a clear, public commitment to stronger cyber defences.