Threat Intelligence Report Cyber Security

Monthly Cyber Threat Intelligence Report: July 2026

Published August 2026 · v1.0, July 2026 · 7 pages

July 2026 cyber threat intelligence from System Force IT: a SharePoint exploitation wave and Microsoft's largest-ever Patch Tuesday (500+ CVEs, three zero-days); the NCSC exposed the Russian LAUNDRY BEAR zero-click email-theft campaign against Zimbra users; Qilin surged back near the top of the ransomware charts; and the ICO handed a council worker a suspended sentence for insider data misuse.

What's inside

  • SharePoint was July's biggest story. Multiple actively exploited SharePoint flaws drove repeated additions to CISA's Known Exploited Vulnerabilities catalogue and a dedicated CISA hardening alert. Any business running on-premises SharePoint should patch now and check for compromise.
  • Microsoft's July Patch Tuesday was the largest on record, fixing well over 500 vulnerabilities, around three times June's total, with three publicly disclosed zero-days. Two, in SharePoint Server and Active Directory Federation Services, were already being exploited. Triage by what is confirmed exploited first.
  • The NCSC, part of GCHQ, and partners in 15 countries exposed LAUNDRY BEAR, a Russian state-supported group using a zero-click exploit named beehive to steal email from organisations running Zimbra webmail. No click is needed; simply viewing a malicious message compromises a vulnerable server. Patch and monitor email platforms.
  • In ransomware, Qilin surged more than fourfold year on year and ran neck and neck with The Gentlemen for the top spot through July, with Akira and DragonForce also highly active. (Final July victim totals are confirmed in the released report.)
  • A threat actor claimed to have stolen 35GB of source code and security keys from Accenture, underlining the exposure of source code and secrets, and the value of tight access control around development and identity systems.
  • For UK businesses, the ICO gave a council worker a suspended sentence for unlawfully accessing hundreds of personal records, a reminder that insider misuse is a criminal matter, and the NCSC again urged UK organisations to sign up to its free Early Warning service.

The July 2026 edition of the System Force IT Monthly Cyber Threat Intelligence Report covers the most significant cyber incidents, emerging threats, vulnerability disclosures and ransomware activity observed during the month. It is written for business owners, IT leaders and risk managers who need a concise monthly briefing without wading through fragmented vendor advisories.

July was dominated by Microsoft SharePoint. A wave of actively exploited SharePoint flaws saw CISA add several to its Known Exploited Vulnerabilities catalogue through the month and issue a dedicated SharePoint hardening alert, and Microsoft’s July Patch Tuesday was the largest on record, fixing well over 500 vulnerabilities, roughly three times June’s total, including three publicly disclosed zero-days. Two of those zero-days, in SharePoint Server and Active Directory Federation Services, were already being exploited. On the espionage front, the NCSC, part of GCHQ, and partners in 15 countries exposed LAUNDRY BEAR, a Russian state-supported group using a zero-click exploit named beehive to steal email from organisations running Zimbra webmail, where simply viewing a malicious message is enough to be compromised.

In ransomware, Qilin roared back, up more than fourfold year on year and running neck and neck with The Gentlemen for the top spot through the month, with Akira and DragonForce also prominent. In the wider incident picture, a threat actor claimed to have stolen 35GB of source code and security keys from Accenture. CISA’s July catalogue additions also covered Oracle E-Business Suite, Check Point SmartConsole and Langflow. Priority actions are clear: patch on-premises SharePoint and any exposed Zimbra webmail immediately, triage the record Patch Tuesday by what is confirmed exploited first, enforce multi-factor authentication around identity systems, and keep tested, offline backups.

For UK businesses specifically, July reinforced both the regulatory and the espionage picture. The ICO handed a suspended sentence to a council worker who had unlawfully accessed hundreds of personal records, a reminder that insider misuse carries criminal as well as regulatory consequences. The NCSC issued two advisories during the month, one urging critical sectors to improve their defences against Russian intelligence targeting and the LAUNDRY BEAR zero-click warning, and again urged all UK organisations to sign up to its free Early Warning service. The government also brought UK businesses together to pledge stronger cyber defences.