This page translates real, active cyber threat intelligence into plain English for UK business owners. No acronyms. No jargon. Just what you need to know and what you should do about it.
Last updated: 25 August 2026 · August 2026 Edition · Next update: September 2026
Every week we assess the overall risk level for UK small businesses in financial services — insurance brokers, financial advisers, mortgage intermediaries, and professional services firms. This is based on real intelligence from the UK's National Cyber Security Centre (NCSC), US cyber agencies, and industry reporting.
Seven criminal and state-sponsored groups continue running active operations targeting UK businesses in your sector. This month's confirmed vulnerabilities affect some of the most widely used software in UK offices — Apple Macs, Microsoft SharePoint, and Windows VPN services. The UK's National Cyber Security Centre also published its first dedicated guidance on AI-driven attacks this month, confirming that agentic AI is now an operational threat — not just a future concern. MITRE-Lite moves to monthly updates from this edition, published at the end of each month.
Each week we identify the single highest-risk attack technique that is seeing a spike in use against UK businesses. This week:
A confirmed vulnerability in Apple macOS (CVE-2026-65400) allows anyone on the same network as a Mac to connect to its Screen Sharing feature without entering a password. Screen Sharing is Apple's built-in remote desktop tool — the equivalent of someone sitting at that computer and seeing everything on screen, opening files, running applications, and reading emails.
The vulnerability was added to the US government's confirmed-exploited list on 18 August 2026, meaning it is being used in real attacks right now. You do not need to be on the internet to be at risk — anyone connected to the same office Wi-Fi or network as a Mac can potentially exploit this.
This is particularly relevant for businesses that run a mix of Macs and Windows machines. Windows devices are often more tightly managed by IT providers, with automatic updates and monitoring in place. Macs are sometimes treated as exceptions — especially if they belong to senior staff or creative roles — and may be running older software without anyone noticing.
At the same time, Microsoft SharePoint has received yet another confirmed vulnerability this month — its fourth in 2026. This one (CVE-2026-55040) allows an unauthenticated attacker to bypass SharePoint's security features entirely. If your business uses SharePoint for document storage, intranet pages, or team collaboration, your IT provider needs to have applied the August 2026 patches.
The Apple macOS vulnerability confirmed this month (CVE-2026-65400) is fixed in the latest version of macOS. The fix exists — the risk is entirely in whether the update has been applied. On any Mac, click the Apple menu in the top-left corner → System Settings → General → Software Update. If an update is available, install it. If your IT provider manages your Macs, contact them and ask them to confirm all devices are on the latest macOS version. Pay particular attention to Macs belonging to senior staff — they often have more access to sensitive data and are less likely to have had recent IT attention. If your office uses Mac computers that no longer receive software updates (Apple typically supports devices for around seven years), those machines are a permanent security risk and should be considered for replacement.
Why now: CVE-2026-65400 was confirmed exploited on 18 August 2026. Any unpatched Mac on a shared office network is vulnerable to unauthenticated remote access right now.
Microsoft releases security patches on the second Tuesday of each month. August's round included fixes for SharePoint (CVE-2026-55040, authentication bypass) and Microsoft's Internet Key Exchange service (CVE-2026-33824, remote code execution via Windows VPN). Both are confirmed exploited this month. If your IT provider manages your Microsoft 365 environment and Windows devices, these patches should have been applied automatically — but it is worth confirming. Ask your IT provider: have all August 2026 Microsoft security patches been applied across our devices? If you manage your own Windows machines, go to Settings → Windows Update and check for updates. The SharePoint patch in particular matters if your business stores documents or runs any internal sites on SharePoint.
Why now: Both vulnerabilities confirmed exploited 18 August 2026. SharePoint has now had four separate confirmed exploited vulnerabilities in 2026 — the pattern makes it a priority patching target.
The NCSC published its first dedicated guidance on the cyber risks of agentic AI on 20 August 2026. Agentic AI refers to AI systems that do not just answer questions but take actions — booking appointments, sending emails, querying databases, making decisions. Many businesses are starting to use these tools without fully understanding the access they are granting. If an AI agent has access to your email, it has access to everything in your email. If it can access your client management system, it can read and write client data. The NCSC guidance covers the key questions to ask before deploying any AI agent in your business: what access does it need, what access is it actually being given, who can see what it does, and what happens if it is compromised. The guidance is practical and accessible — it is not written for technical audiences. Visit ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai.
Why now: NCSC published this guidance 20 August 2026 — their first formal treatment of AI agents as an operational risk. If your business is using or planning to use any AI tool with access to your systems or data, this guidance is directly relevant.
A GET-IT resilience scan maps your current defences against the active threat techniques on this page and tells you exactly where your gaps are — in plain English, with costs to fix them.
Book a Free Resilience Scan → View Technical Version