grc-scanSecurity & governance
News digest2 July 2026Archived edition

Cybersecurity News

This edition was published on 2 July 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

Today's stories share one thread: attackers are increasingly going after the infrastructure and tools you trust by default — the firewall protecting your office, the finance software your accountant uses, the load balancer your host runs, the AI assistant on your developer's laptop, even the web address an AI politely hands you. None of these are things a small business owner chose to expose directly; they're the plumbing underneath the services you already rely on. Three habits close most of that gap: first, know what's actually running your network and website (ask your IT provider or host by name — "do you use Fortinet?" is a fair question) and confirm patches get applied within days, not months. Second, treat any urgent message or confident AI answer with a beat of scepticism — verify through a channel you already trust rather than the one the message or tool just gave you. Third, since more attacks now steal and threaten to leak data rather than lock it, keep less sensitive data (especially about your own staff) sitting in any one system, and make sure MFA is switched on everywhere it can be. None of this requires deep technical skill — it requires asking the right questions of the people and vendors already holding your keys.

Cybersecurity News — 2026-07-02

Generated: 2026-07-02 | Sources: The Hacker News, BleepingComputer, SecurityWeek, Dark Reading, Unit 42 (Palo Alto Networks), NCSC


1. "FortiBleed" Campaign Has Quietly Harvested 110 Million Credentials — and Small Businesses Are the Main Target

A global campaign researchers are calling FortiBleed has compromised more than 430,000 Fortinet FortiGate firewalls — the box many small businesses use as their office's internet gateway and VPN — by abusing a built-in diagnostic command to silently "sniff" and copy usernames and passwords out of normal network traffic, no malware needed. Analysts have already verified over 86,000 working stolen logins, and around two-thirds of the affected organisations have fewer than 200 employees.

Why it matters for your business: if your office network runs a Fortinet FortiGate device (ask your IT provider or MSP — you may not know the brand yourself), assume its admin credentials could already be exposed and get them reset and its firmware patched immediately, rather than waiting for a symptom like unusual VPN logins.


2. Oracle E-Business Suite Under Active Attack Just Days After a Patch Shipped

Attackers began exploiting a critical, unauthenticated flaw (CVE-2026-46817) in Oracle's E-Business Suite finance/ERP software within days of Oracle releasing a fix, sending crafted requests designed to read sensitive files straight off the server. Security researchers logged hundreds of attack attempts in a single day, aimed at systems that hadn't yet installed the update.

Why it matters for your business: this is the pattern behind most breaches of internet-facing business software — a patch exists, but the window between "patch released" and "attackers exploiting it" is now measured in days, not weeks. If your bookkeeper, accountant, or a vendor runs Oracle EBS (or any similar finance system) on your behalf, ask them directly whether it's patched — don't assume.


3. Network Appliance Flaw (CVE-2026-8037) Lets Attackers Take Over Load Balancers With No Login

Researchers found active exploitation of a maximum-severity flaw (CVSS 9.6) in Progress Kemp LoadMaster, a device many businesses' hosting providers use to distribute web traffic. The bug is a case of command injection — malformed input tricks the device into running the attacker's own commands — and needs no username or password to trigger, handing an attacker root-level control.

Why it matters for your business: you likely don't run this hardware yourself, but your website host or cloud provider might. It's a good prompt to ask your hosting provider, in plain terms, how quickly they apply security patches to the infrastructure your site sits behind — a slow patcher upstream becomes your outage or breach.


4. Flaws in the Popular "Cursor" AI Coding Tool Could Let a Single Prompt Take Over a Developer's Computer

Researchers disclosed two critical flaws (nicknamed "DuneSlide") in Cursor, an AI-powered code editor used by many developers and small software teams. Cursor is meant to run AI-suggested commands inside a restricted "sandbox" so they can't touch the rest of the computer; the flaws let a hidden instruction — smuggled in through something as ordinary as a web search result the AI reads — break out of that sandbox and run any command as the developer, with no click or approval needed. Both are already patched in the current version; there's no evidence of real-world attacks yet.

Why it matters for your business: if you or anyone on your team uses an AI coding assistant, keep it set to auto-update and be wary of pointing it at code or content from sources you don't trust — "the AI is sandboxed" is not a guarantee once a flaw like this exists.


5. Attackers Are Buying Up Web Addresses That AI Tools Just Made Up

Researchers at Palo Alto Networks found that AI chatbots and coding assistants routinely invent plausible-looking web addresses for real brands that don't actually exist — a quirk they call "phantom squatting". Criminals have started registering those made-up domains before anyone else can, then building convincing fake login pages or app downloads on them, ready to catch the traffic when an AI tool confidently sends a user or a piece of software to the address it hallucinated.

Why it matters for your business: if you or your staff ask an AI assistant for a company's website, support link, or download URL, double-check it against a source you already trust (a saved bookmark, a search engine result, an email you know is genuine) before clicking or entering any details — don't treat an AI's answer as verified just because it sounds confident.


6. Kubota North America Breach Exposed a Month's Worth of HR Records

Farm-equipment maker Kubota disclosed that hackers had access to parts of its North American network for roughly five weeks in the spring, and that files held by its human resources team — containing personal information on employees and their dependents — were accessed. The company only confirmed the HR-data impact in mid-June and began notifying affected individuals at the end of the month.

Why it matters for your business: breaches at large suppliers and partners routinely expose the personal data of people who never dealt with the attacker directly, including via payroll or HR platforms you outsource to. Know which third parties hold your staff's personal data, and make sure your contracts with them require prompt breach notification so you're not the last to find out.


7. Ransomware Gang Skips the Encryption, Goes Straight to a $2 Million Extortion Demand

The Blackfield ransomware group breached a Taiwanese subsidiary of Japanese manufacturer Nidec and stole over two terabytes of corporate data — employee, financial, procurement and legal records — then gave the company roughly two weeks to pay $2 million or have the data published, alongside a cheaper option to just buy the stolen files outright. No mention of file-locking malware; the leverage is purely "pay or we leak it".

Why it matters for your business: this is now a common playbook — the threat is exposure and reputational damage, not a locked hard drive, so backups won't stop it. The defence is preventing the break-in in the first place (MFA, patched systems, phishing-aware staff) and minimising how much sensitive data — especially about your own employees — you keep in one place.


8. UK Regulator Warns Phishing Scams Impersonating HMRC and Banks Are Moving Faster With AI

The UK's National Cyber Security Centre has flagged a rise in convincing phishing campaigns impersonating HMRC, high-street banks and NHS digital services, warning that AI tools have shortened the time from a victim clicking a link to their account being taken over to just minutes. Recent examples reported to Action Fraud include fake NatWest emails about "mandatory" biometric logins and spoofed Barclays texts about direct debits, both designed to get a call-back to a scammer.

Why it matters for your business: if a message claiming to be from HMRC, your bank, or a supplier creates urgency ("verify now", "your payment failed"), stop and contact them directly using a number or address you already have on file — never one in the message itself — before clicking, calling back, or entering any details. Report anything suspicious to Action Fraud (0300 123 2040) so others get warned too.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.