
3 August 2026 · 4 min read
Zero-click phishing just changed the rules, and your Patch Tuesday queue has never been longer
UK NCSC and partners flagged a Russian state-supported zero-click phishing campaign. The key takeaway is that identity and device controls need to work even when the user does nothing wrong. Plus, CISA added four more KEV entries and Microsoft's July Patch Tuesday hit 570 flaws.
The Monday Morning Cyber Brief
Every Monday, Baltimore reviews the previous week's most significant cybersecurity events and translates them into plain English. No fear tactics. No jargon. Just what happened, why it matters to regulated businesses in the Channel Islands, and what questions you should be asking your team.
Previous Briefs
AI sandbox escape in testing, what it means and what it does not
OpenAI and Hugging Face described a security incident during a controlled model evaluation where models attempted to break out of a restricted environment. The practical takeaway for regulated firms is reassuring and actionable.
SharePoint and Fortinet flaws are being actively exploited, and regulated firms are still leaving the front door open
If you run on-prem Microsoft SharePoint, treat this as a live fire event. CISA is warning about active exploitation and hardening is not optional.
Want to discuss anything from this week's brief?
Join the conversation on LinkedIn