| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Jul 30, 2026 | CISA | Alert | CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. | CISA, EPA, FBI |
| Jul 30, 2026 | CISA | Advisory | Open Source Software: Security Principles and Practices These recommendations are rooted in software development and software supply chain risk management best practices and are tailored to address the benefits and risks unique to OSS. Agencies should implement the practices and processes outlined in this guidance Key Actions to improve risk management of OSS and more effectively use open source software solutions to meet mission needs. | CISA |
| Jul 29, 2026 | CISA | Advisory | 2026 Minimum Elements for a Software Bill of Materials (SBOM) The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the co-authoring organizations, updated the Minimum Elements for a Software Bill of Materials (SBOM) to reflect current SBOM needs, while preserving the core principles of the document published in 2021 by the National Telecommunications and Information Administration (NTIA). | ASD/ACSC, CISA, FBI, NSA, NTIA |
| Jul 29, 2026 | NCSC | Guidance | Making forensic observability the norm for network devices This creates a shared challenge for both the vendors that build these products and the organisations that buy and operate them. When incidents occur, organisations need reliable ways to understand what happened and assess whether a device can still be trusted. | NCSC-UK |
| Jul 28, 2026 | ASD/ACSC | Guidance | CI Fortify – Advice for isolating vital systems Learn practical approaches to isolating operational technology (OT) and critical systems from other networks to reduce cyber risk and support ongoing service delivery. | ASD/ACSC |
| Jul 28, 2026 | ASD/ACSC | Guidance | New advice to help organisations isolate their vital OT and enabling systems from other networks Learn how to isolate vital OT and enabling systems from all other networks. This proactive measure can disrupt adversaries' ability to carry out cyber attacks, contain attacks already in progress, and maintain essential services during periods of crisis or service disruption. | ASD/ACSC |
| Jul 28, 2026 | CISA | Advisory | CI Fortify – Advice for isolating vital systems This guidance contains practical steps for critical infrastructure (CI) organizations to isolate vital operational technology and enabling systems from all other networks in the event of disruption or crisis and operate in isolation for an extended period. Developed to address escalating cyber threats, the guidance outlines key steps for identifying critical systems, mapping connections, and implementing effective separation points. | ASD/ACSC, CISA, FBI |
| Jul 28, 2026 | NCSC | Guidance | When cyber attacks happen: helping organisations recover New guidance provides a framework for response and recovery. However it hits you, finding out that your organisation is the victim of a highly disruptive cyber attack is a real blow. And as technology evolves and cyber threats continue to grow in scale and sophistication, more organisations are having to prepare for the possibility of serious disruption. | NCSC-UK |
| Jul 24, 2026 | ASD/ACSC | Guidance | Careful adoption of Agentic AI in cyber defence Latest events highlight the growing capabilities of agentic AI, and reinforce that organisations must adopt agentic AI cautiously with strong security, monitoring and oversight. | ASD/ACSC |
| Jul 24, 2026 | ASD/ACSC | Advisory | Joint advisory on Russian cyber actors exploiting Zimbra Collaboration Suite This joint advisory outlines an ongoing campaign by Russian state-sponsored cyber actors exploiting Zimbra Collaboration Suite to steal sensitive email data and maintain access. | ASD/ACSC |
| Jul 23, 2026 | NSA | Advisory | Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Read our joint advisory on LAUNDRY BEAR's exploitation of Zimbra Collaboration Suite. | AISE, AISI, AIVD, ANSSI, ASD/ACSC, AW, CCCS, CISA, CNI, DC3, DCSA, DDIS, DGSI, EFIS, FBI, FDI, MIVD, NCIS, NCSC-NZ, NCSC-SE, NCSC-UK, NSA, NUKIB, SIS RM, SKW, SUPO, Treasury |
| Jul 23, 2026 | NCSC | Guidance | UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations campaign targeting Western organisations GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign Russian state-supported actors develop new technique to target Western email platforms and gain persistent access to compromised networks Organisations provided with trusted advice and support to protect sensitive… | NCSC-UK |
| Jul 23, 2026 | CERT-EU | Advisory | 2026-009: Critical Vulnerabilities in Microsoft SharePoint On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522 [2], a vulnerability part of an ongoing series of actively exploited flaws [3] affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE2026-45659, CVE-2026-56164, and CVE-2026-58644. | CERT-EU |
| Jul 22, 2026 | NCSC | Analysis Report | Post-quantum cryptography (PQC) migration workshop report In December 2025, the NCSC and Vodafone, with the National Cyber Advisory Board, hosted the first UK government and industry workshop focused on post-quantum cryptography (PQC) migration. The event brought together security leaders and those responsible for PQC in their organisations from across industry, academia and government. | NCSC-UK |
| Jul 16, 2026 | ASD/ACSC | Guidance | Post-quantum questions to ask your vendors Learn how to evaluate vendor readiness for post-quantum cryptography and support your organisation’s transition to quantum-resistant security. | ASD/ACSC |
| Jul 16, 2026 | ASD/ACSC | Guidance | New guidance helps organisations assess vendor readiness for post-quantum cryptography Learn how to evaluate vendor readiness for post-quantum cryptography and support your organisation’s transition to quantum-resistant security. | ASD/ACSC |
| Jul 15, 2026 | CISA | Advisory | Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers This guidance outlines best practices for suppliers to design and implement a coordinated vulnerability disclosure (CVD) program to effectively and transparently collaborate with security researchers to report and remediate vulnerabilities. | CISA, NCSC-NL, NCSC-UK, NSA |
| Jul 15, 2026 | NCSC | Guidance | Helping small businesses with free, hands-on cyber consultancy If you’re a small business, cyber attacks may feel like something that only large companies need to worry about. Companies with bigger budgets, more customers – and more to lose. | NCSC-UK |
| Jul 15, 2026 | JPCERT/CC | Alert | Microsoft Releases July 2026 Security Updates Microsoft has released July 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication, etc. According to Microsoft, among the vulnerabilities, the following vulnerabilities have been confirmed to be exploited in the wild. | JPCERT/CC |
| Jul 14, 2026 | ASD/ACSC | Advisory | Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting This joint advisory outlines persistent and ongoing malicious cyber activity conducted by Russian state-sponsored cyber actors. | ASD/ACSC |
| Jul 14, 2026 | ASD/ACSC | Advisory | Joint advisory on the exploitation of network devices by Russian state-sponsored cyber actors This joint advisory outlines a persistent and enduring campaign of malicious cyber activity carried out by Russian state-sponsored cyber actors. | ASD/ACSC |
| Jul 14, 2026 | CISA | Alert | CISA Urges SharePoint Hardening After New Exploitations CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026. CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , CVE-2026-56164 , and CVE-2026-58644 , enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. | CISA |
| Jul 13, 2026 | NCSC | Guidance | UK and Allies urge critical sectors to improve defences against Russian intelligence targeting Organisations in critical infrastructure sectors are being supported to better understand and defend against malicious activity, as the UK and international partners today call out techniques used by Russian Intelligence Services Alongside 18 agencies from 12 countries, the National Cyber Security Centre (NCSC) – a part of GCHQ – has published a new advisory highlighting the methods of Federal Security Service (FSB) Centre 16 cyber actors, who ar… | NCSC-UK |
| Jul 13, 2026 | ASD/ACSC | Guidance | Frontier AI models and their impact on cyber security – an update on AI model harnesses Understand how AI model harnesses are shaping cyber security outcomes for organisations. | ASD/ACSC |
| Jul 13, 2026 | NSA | Advisory | Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. | ASD/ACSC, CCCS, CISA, FBI, NCSC-NZ, NCSC-UK, NSA |
| Jul 9, 2026 | NCSC | Guidance | Cyber Essentials Pathways: from proof of concept to cyber confidence “We want to achieve Cyber Essentials Plus, but the way we operate does not align with the technical controls that Cyber Essentials Plus requires.” Complex architectures, legacy systems, and layered security requirements mean that a purely prescriptive approach can sometimes feel more like a constraint than something that enables better security outcomes. | NCSC-UK |
| Jul 9, 2026 | ASD/ACSC | Alert | CRITICAL ALERT: Large-scale exploitation campaign targeting website content management systems (CMS) The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) is tracking a large-scale exploitation campaign targeting various vulnerabilities in web content management systems (CMS) globally, including in Australia. | ASD/ACSC |
| Jul 7, 2026 | NCSC | Guidance | Cyber Shield: The path to an agentic AI future for cyber defence Why the UK is pioneering an initiative to develop a national scale, sovereign defence capability In her recent inaugural GCHQ Annual Lecture at Bletchley Park, Director GCHQ announced that: we need to reimagine cyber security in the AI world. In the past few months, GCHQ has developed the blueprint for a new national cyber defence capability that will hardwire cutting-edge agentic AI into machine speed cyber defence. | NCSC-UK |
| Jul 1, 2026 | NCSC | Guidance | Building more resilient CNI: what industry pen testers told us For those of us working in operational technology here at the NCSC, part of our job is to engage with penetration testers. Also known as ‘pen testers’, it’s their job to try to break into systems, poke holes in your infrastructure and find any weak spots. | NCSC-UK |
| Jul 1, 2026 | ASD/ACSC | Guidance | New video series supports cyber security training for privileged users Access short, clear video modules to build practical cyber security awareness and skills for privileged ICT users. | ASD/ACSC |