grc-scanSecurity & governance
News digest3 July 2026Archived edition

Cybersecurity News

This edition was published on 3 July 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

Every story today involves an attacker going after something a business trusts by default and rarely double-checks: office software patched months ago somewhere but not everywhere, a phone system, a network appliance, a shared industry platform, an insurer holding your data, or a helpdesk trained to be helpful rather than suspicious. None of it required the business itself to make an obvious mistake — it required nobody asking a specific question of the vendor, provider, or partner actually holding the risk. Four habits close most of that gap. First, treat any patch advisory for software you or a supplier uses as a countdown, not a someday task — "the fix has existed for two months" is exactly the gap attackers are exploiting right now. Second, ask named, specific questions of your web host, IT provider, and insurer ("do you run X, and is it patched?") rather than assuming someone else is handling it — a vague reassurance isn't an answer. Third, fix one non-negotiable rule for password and access resets: verify the requester through a channel you already trust, every time, no matter how convincing or urgent they sound. Fourth, know which outside organisations — insurers, IT providers, shared platforms — hold data about your business and staff, and expect prompt notification from every one of them if something goes wrong. None of this requires technical expertise; it requires treating "someone else must be checking this" as the riskiest assumption you make.

Cybersecurity News — 2026-07-03

Generated: 2026-07-03 | Sources: The Hacker News, BleepingComputer, SecurityWeek, CISA, Huntress


1. A Widely Used Office Filing System Has a Flaw Hackers Are Already Exploiting

Microsoft SharePoint Server — the version many businesses install and run themselves for internal file-sharing and intranets, separate from the cloud SharePoint bundled into Microsoft 365 — has a flaw that lets even a low-privileged logged-in user trick the server into running commands it shouldn't. The technique is called deserialization: feeding the server a corrupted data package that it unpacks and blindly trusts, rather than checking first. Microsoft patched it back in May, but the US government's cyber agency (CISA) confirmed this week that hackers are now actively exploiting unpatched copies and gave federal agencies until July 4 to fix it.

Why it matters for your business: if your business or an IT contractor runs an on-premises SharePoint server (not the Microsoft 365 cloud version), confirm today that May's update is actually installed — a two-month-old patch is already a long window for something now under active attack, and "we'll get to it" is no longer good enough once a flaw is on a government exploited-vulnerabilities list.


2. Office Phone Systems Are Being Hijacked Through a Feature Most Businesses Never Use

Cisco confirmed that hackers are exploiting a flaw in Unified Communications Manager, the software behind many businesses' office phone and voicemail systems, when a rarely-used "click to dial from a webpage" feature called WebDialer is switched on. The bug is a case of server-side request forgery — tricking the phone system into fetching a web address the attacker chooses on their behalf — which lets an outsider plant a file that can later be used to seize full administrator control of the whole system.

Why it matters for your business: ask whoever manages your office phone system whether it runs Cisco Unified Communications Manager and whether WebDialer is switched on; if nobody in your business uses click-to-dial-from-a-webpage, have it disabled, and confirm June's patch is installed either way.


3. Citrix Patches Six Flaws in Gear That Sits in Front of Many Business Websites

Citrix released patches for six flaws in NetScaler, hardware and software that many web hosts and IT providers use to manage traffic into a company's website or remote-access portal. One, in the "CitrixBleed" family of bugs (a known pattern where the device is tricked into leaking supposedly-private session data straight out of its own memory), can hand an attacker enough information to hijack an already-logged-in session with no password needed. Another, nicknamed "HTTP/2 Bomb," can knock a web server offline using only a small number of specially-crafted requests.

Why it matters for your business: you probably don't manage this appliance yourself, but ask your website host, VPN provider, or IT support company by name whether they run Citrix NetScaler and, if so, whether it's on the July 2026 patched release — get the answer in writing rather than assuming someone else already checked.


4. Adobe Rushes Out Fixes for Seven "Perfect Score" Flaws in Business Web and Marketing Software

Adobe issued emergency patches for seven flaws rated the maximum possible severity (10 out of 10) across ColdFusion, a platform used to build business web applications, and Campaign Classic, marketing-email software. Each flaw needs no user interaction to trigger and could let an attacker run their own code directly on the server — serious enough that Adobe is telling customers to patch within 72 hours instead of its usual timeline.

Why it matters for your business: if any part of your website, customer portal, or email marketing runs on Adobe ColdFusion or Campaign Classic, ask your web developer or agency by name whether they've already applied this month's update — this is one of the rare cases where "patch it this week" genuinely means this week, not next quarter.


5. A US Government Security-Sharing Network Sat Breached for Weeks Before Anyone Noticed

The US Department of Homeland Security confirmed that hackers had access to the Homeland Security Information Network — a platform federal, state, and private-sector partners use to share threat and event-security information — for several weeks between late May and June before the intrusion was detected and disclosed. Investigators still don't know who was behind it or exactly what data was taken.

Why it matters for your business: the "shared portal" model many industries rely on — supplier extranets, franchise or trade-association platforms, joint client databases — is only as safe as its slowest member to notice a break-in. Ask any shared platform you or your staff log into how quickly they'd tell you if it were breached, and don't read silence as proof nothing happened.


6. Insurance Giant Aflac Breached Again — 4.4 Million Customers' Details Stolen

Aflac's Japanese life-insurance arm disclosed that hackers accessed its systems repeatedly over roughly ten days in June before being caught, stealing names, addresses, dates of birth, and insurance account details belonging to 4.38 million customers — the company's second major hacking incident inside a year.

Why it matters for your business: many small businesses hold cyber, liability, or health insurance policies with large insurers who store exactly this kind of personal data about your business and staff. You can't secure the insurer's systems yourself, but you can ask what personal data they hold on you, avoid handing over more than a policy strictly requires, and treat any breach notice from them as something to act on immediately, not file away.


7. A Teenage Hacker Behind Attacks on UK Retailers Is Extradited to Face US Charges

A 19-year-old accused member of the hacking group Scattered Spider — linked to attacks on UK names including Marks & Spencer, Co-op, and Harrods, plus Transport for London — was extradited from Finland to the US to face fraud and computer-intrusion charges. The group's signature move isn't sophisticated malware; it's calling a company's IT helpdesk or an employee directly, impersonating someone with legitimate access, and talking their way past security checks to get a password or MFA device reset.

Why it matters for your business: an arrest slows one person down, not the playbook — make sure whoever handles password or MFA resets for your business (an IT provider, or a named staff member) has a fixed verification step, such as calling back a number you already have on file, before resetting access for anyone who simply sounds legitimate on the phone or in a chat.


8. Most IT Support Companies Have Been Breached at Least Once in the Past Year

A new industry survey found that roughly three in four managed service providers (MSPs) — the outsourced IT companies many small businesses rely on for email, backups, and day-to-day support — reported at least one breach in the past year, with more than half breached two or more times. Ransomware groups increasingly target MSPs on purpose, because compromising one gives them a foothold into every client it supports at once.

Why it matters for your business: if you outsource your IT, ask your provider directly what happened the last time they were breached (or how they'd know if they haven't been), whether your business's access is kept isolated from their other clients, and whether they use MFA on their own admin tools — the same questions you'd want a customer asking you.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.