grc-scanSecurity & governance
News digest1 July 2026Archived edition

Cybersecurity News

This edition was published on 1 July 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

This week the way in was almost always someone else's software you rely on: a remote-support tool, a SaaS platform's API, a third-party email system, an authorised integration's tokens. Two lessons follow. First, your security now depends on your suppliers' hygiene — keep an inventory of the tools and cloud services that hold your data, patch anything internet-facing fast, and periodically prune the "connected apps" and old credentials that quietly hold keys to your accounts. Second, with ransomware pivoting to stealing data rather than just locking it, prevention beats recovery: MFA everywhere, prompt patching, phishing-aware staff, and collecting less data in the first place. The unglamorous basics still decide who has a bad day and who has a catastrophe.

Cybersecurity News — 2026-07-01

Generated: 2026-07-01 | Sources: The Hacker News, SecurityWeek, Infosecurity Magazine, BleepingComputer, Check Point Research, CISA, TechCrunch, World Economic Forum


1. SimpleHelp Remote-Support Flaw (CVE-2026-48558, CVSS 10) Exploited to Push Malware

Attackers exploited a maximum-severity flaw in SimpleHelp, a remote-support (RMM) tool, to gain a trusted technician session on an internet-facing server and then use the platform's own tools to push malware — a loader called "TaskWeaver" and an infostealer, "Djinn Stealer". CISA added the flaw to its Known Exploited Vulnerabilities catalog on 29 June.

Why it matters for your business: Remote-support and remote-management tools are a favourite target because compromising one gives an attacker a legitimate-looking way into every machine it manages. If your IT provider or MSP uses an RMM tool, ask them to confirm it's patched and that its console isn't exposed to the open internet.


2. Microsoft Defender Zero-Day (CVE-2026-33825) Exploited Before a Fix

Microsoft's latest patch round addressed a large batch of flaws — around 15 rated critical and dozens more high severity — including a Microsoft Defender vulnerability (CVE-2026-33825) that was already being exploited in the wild as a zero-day before the patch shipped.

Why it matters for your business: "Zero-day" means attackers were using it before a fix existed, so the only defence is applying updates fast once they land. If your Windows machines and servers aren't set to install security updates automatically, turning that on is the single highest-return thing you can do today.


3. ServiceNow Discloses June Security Incident via an Exposed API

ServiceNow disclosed a June 2026 incident after attackers exploited an unauthenticated-access flaw in an API endpoint used by hosted customer instances. Malicious activity reportedly began in early June and was surfaced through bug-bounty reports days later.

Why it matters for your business: Even large, trusted SaaS platforms have flaws — and if you keep data in one, their incident becomes your incident. Keep an inventory of the cloud services that hold your data, watch for their security notices, and know who to contact if one reports a breach.


4. Klue Supply-Chain Breach Reaches Salesforce Data via Stolen OAuth Tokens

Klue confirmed a June supply-chain breach in which attackers used compromised legacy credentials to reach its integration environment and steal OAuth tokens connected to customer platforms — giving unauthorised access to Salesforce CRM data across multiple customers.

Why it matters for your business: The "connected apps" you authorise (an integration clicking Allow access to your CRM/email) hold long-lived tokens that are effectively keys to your data. Periodically review the third-party apps connected to your Google/Microsoft/Salesforce accounts and remove any you no longer use.


5. KDDI Email Breach — Up to 14.2 Million Addresses and Passwords Exposed

Japanese telecoms group KDDI disclosed a breach of an email platform it provides to several ISPs, detected in mid-June, in which attackers exploited a vulnerability in third-party software. Up to 14.22 million email addresses and passwords may have been exposed.

Why it matters for your business: Breached email/password pairs get reused by attackers against every other site — "credential stuffing". This is exactly why a unique password per site plus MFA matters: a password leaked from one provider shouldn't unlock anything else you own.


6. Ransomware Up 48% Year-on-Year — and Shifting to Pure Data Theft

Check Point reports ransomware attacks jumped 48% year over year even as overall cyberattack volume dipped. The bigger shift: many crews are abandoning file-encryption in favour of data theft and extortion — steal the data, threaten to leak it, demand payment.

Why it matters for your business: If the threat is "we'll publish your data" rather than "we've locked your files", backups alone won't save you — the data's already gone. That raises the value of the basics that stop the initial break-in (MFA, patching, phishing awareness) and of collecting less sensitive data in the first place.


7. AI-Related Weaknesses Named the Fastest-Growing Cyber Risk

The World Economic Forum's Global Cybersecurity Outlook found the overwhelming majority of organisations (~87%) now rate AI-related vulnerabilities as the fastest-growing cyber risk — from AI-supercharged phishing to insecure AI tools and integrations.

Why it matters for your business: You don't need to run AI models to be exposed — attackers use AI to make phishing more convincing, and the AI tools your team adopts add new places to leak data. Treat AI-tool logins and configs as sensitive, and keep reminding staff that a polished, personalised message can still be a scam.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.