
All Briefs
The full archive of Monday Morning Cyber Briefs. Plain English cybersecurity news and analysis for business leaders in the Channel Islands.
Patch Tuesday just got heavier, and your browser is still a frontline risk
CISA added CVE-2026-85706 to the KEV catalogue. Microsoft's September 2026 Patch Tuesday is unusually large. Google is still patching exploited Chrome zero-days. This week: tighten patch discipline and browser hardening.
One more KEV entry, finance phishing still live in the islands, and edge devices remain the fastest way in
CVE-2026-85046 is confirmed exploited, QuickBooks phishing continues to target Channel Islands finance teams, and SonicWall SMA1000 zero-day reports put edge appliances back in the spotlight. This week: patch the KEV item, tighten payment controls, and check your remote access kit.
QuickBooks phishing is hitting the islands, and exploited vulnerabilities are still the fastest way in
Guernsey has flagged a QuickBooks themed phishing campaign, while CISA KEV additions and PaperCut exploitation show how fast attackers weaponise common systems. This week: stop payment fraud, close the obvious doors.
Actively exploited vulnerabilities keep stacking up, and the bar for asset ownership just got higher
Emergency patching and industrial control warnings raise the bar for asset ownership and patch discipline. KEV additions, TrueConf Server exploitation, ASP.NET emergency patches, and Siemens S7 PLC advisories.
Clop is back, vCenter is under fire, and your supplier register just became urgent
Clop's latest data theft claims, critical VMware vCenter RCE exploitation, and a new CISA KEV addition. This week is about patching crown jewels and tightening third-party assurance.
Exploited vulnerabilities are piling up, and the patching window just got shorter
CISA added multiple actively exploited vulnerabilities to the KEV catalogue. The UK NCSC reiterated urgent action for on-premises SharePoint Server exploitation. Cisco SD-WAN exploitation is driving very short remediation windows.
Zero-click phishing just changed the rules, and your Patch Tuesday queue has never been longer
UK NCSC and partners flagged a Russian state-supported zero-click phishing campaign. The key takeaway is that identity and device controls need to work even when the user does nothing wrong. Plus, CISA added four more KEV entries and Microsoft's July Patch Tuesday hit 570 flaws.
AI sandbox escape in testing, what it means and what it does not
OpenAI and Hugging Face described a security incident during a controlled model evaluation where models attempted to break out of a restricted environment. The practical takeaway for regulated firms is reassuring and actionable.
SharePoint and Fortinet flaws are being actively exploited, and regulated firms are still leaving the front door open
If you run on-prem Microsoft SharePoint, treat this as a live fire event. CISA is warning about active exploitation and hardening is not optional.
CISA just lived every security team's nightmare, leaked cloud keys, and the real lesson is how fast you can contain it and prove it
CISA had cloud credentials exposed via a contractor's public code repository. The real lesson is how fast you can contain it and prove what happened.
Want to discuss anything from a previous brief?
Join the conversation on LinkedIn