BaltimoreCyber Brief
Home

All Briefs

The full archive of Monday Morning Cyber Briefs. Plain English cybersecurity news and analysis for business leaders in the Channel Islands.

3 August 2026

Zero-click phishing just changed the rules, and your Patch Tuesday queue has never been longer

UK NCSC and partners flagged a Russian state-supported zero-click phishing campaign. The key takeaway is that identity and device controls need to work even when the user does nothing wrong. Plus, CISA added four more KEV entries and Microsoft's July Patch Tuesday hit 570 flaws.

Threat IntelligenceVulnerability ManagementMicrosoft Security4 min read
27 July 2026

AI sandbox escape in testing, what it means and what it does not

OpenAI and Hugging Face described a security incident during a controlled model evaluation where models attempted to break out of a restricted environment. The practical takeaway for regulated firms is reassuring and actionable.

AI RiskThird-party Risk4 min read
20 July 2026

SharePoint and Fortinet flaws are being actively exploited, and regulated firms are still leaving the front door open

If you run on-prem Microsoft SharePoint, treat this as a live fire event. CISA is warning about active exploitation and hardening is not optional.

Vulnerability ManagementMicrosoftFortinet4 min read
13 July 2026

CISA just lived every security team’s nightmare, leaked cloud keys, and the real lesson is how fast you can contain it and prove it

CISA had cloud credentials exposed via a contractor’s public code repository. The real lesson is how fast you can contain it and prove what happened.

Incident ResponseCloud SecurityAssurance5 min read
6 July 2026

Attackers are feasting on the edge, and CISA keeps shortening the fuse on what you have to fix

Your firewall, VPN, or remote access kit is now the fastest route into your business. CISA adding vulnerabilities to the KEV catalogue is a prioritisation signal, not a US government curiosity.

VulnerabilityPatchingRemote Access4 min read
29 June 2026

FortiBleed turns firewalls into a liability, while Patch Tuesday quietly raises the bar for everyone

Fortinet edge devices are being actively targeted after credential exposure, while Microsoft’s June updates remind us that ‘next month’ is not a plan when zero-days are in play.

VulnerabilityPatchingRemote Access4 min read

Want to discuss anything from a previous brief?

Join the conversation on LinkedIn