In 30 seconds
- UK NCSC and partners flagged a Russian state-supported "zero-click" phishing campaign. The key takeaway is not "train users harder". It is that identity and device controls need to work even when the user does nothing wrong.
- CISA added four more vulnerabilities to the KEV catalogue last week. Treat KEV as your regulated-firm patch priority list for anything exposed to the internet.
- Microsoft's July 2026 Patch Tuesday is unusually large, 570 flaws and 3 zero-days. That is not a reason to delay. It is a reason to triage, test, deploy, then verify with evidence.
Why it matters
For Channel Islands regulated firms, the operational risk this week is not "a clever new hack". It is the gap between what we think is protected and what is actually enforced.
Zero-click phishing is the uncomfortable bit. Traditional phishing relies on someone clicking a link, opening an attachment, or entering credentials on a fake page. Zero-click tradecraft bypasses all of that. The user does not need to do anything wrong. That fundamentally reduces the value of user awareness training as a primary control. It does not make training pointless, but it means you cannot rely on it as your main line of defence.
What does work is layered identity and device controls. Phishing-resistant MFA (hardware keys or passkeys, not SMS codes). Conditional access policies that restrict logins to compliant, managed devices. Strong logging that lets you spot anomalous access patterns quickly. If a user does nothing wrong and an attacker still gets in, these are the controls that stop the blast radius from growing.
At the same time, CISA's KEV catalogue keeps growing. For those less familiar, CISA is the US Cybersecurity and Infrastructure Security Agency, and their KEV (Known Exploited Vulnerabilities) catalogue is a public register of software flaws confirmed to be actively exploited in the wild. It is not a theoretical risk list. Every entry means someone, somewhere, is already using that vulnerability to break into organisations. The reason it matters outside the US is simple: attackers do not respect borders.
If a KEV-listed product is in your estate, especially if it is internet-facing or used by privileged users, it should jump the queue. Four new additions last week is a practical signal that exploitation is happening now, not "might happen eventually".
Then there is Patch Tuesday. 570 flaws and 3 zero-days in a single release is unusually large. For organisations that run Microsoft heavily, and that is most of the Channel Islands, this is not background noise. It is a capacity planning problem. You need to triage, test, deploy, and then verify, not just "install updates and hope". The organisations that handle this well are the ones with a repeatable process, clear ownership, and a short list of systems that always get patched first.
Questions to ask your team this week
- 1.If a user does nothing wrong, what controls do we have that still stop account takeover, for example conditional access, device compliance, and phishing-resistant MFA?
- 2.Who owns the KEV queue, and what is our target time to remediate KEV items on internet-facing systems?
- 3.Do we have a repeatable "patch then prove" process, including vulnerability scanning and log review, for critical updates?
- 4.If we had to evidence our controls to a regulator next week, could we show configuration and logs, not just policy documents?
One thing to do this week
Pick your top 10 most exposed systems and accounts (internet-facing services, admin accounts, remote access, core SaaS). For each, confirm: MFA strength, conditional access coverage, patch level against KEV, and that logging is enabled and reviewed.
Sources
- UK NCSC, "UK and partners expose Russian state-supported actors for new zero-click phishing campaign":
ncsc.gov.uk - CISA, "CISA Adds Four Known Exploited Vulnerabilities to Catalog" (21 July 2026):
cisa.gov - Microsoft MSRC, July 2026 Security Updates:
msrc.microsoft.com - BleepingComputer, "Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days":
bleepingcomputer.com

