MITRE-Lite has two versions. You're reading the plain English edition — written for business owners, no technical knowledge needed. MITRE ATT&CK is the gold standard framework used by cybersecurity professionals worldwide. It's also highly technical by design. We built both versions so everyone in your business can act on the same intelligence. View Technical Version →
MITRE-Lite Plain English Edition ● Updated This Week

Who is targeting your business right now — and what do they want?

This page translates real, active cyber threat intelligence into plain English for UK business owners. No acronyms. No jargon. Just what you need to know and what you should do about it.

What is MITRE ATT&CK — and why does it matter to you?

MITRE is an American non-profit research organisation that works with governments and security agencies worldwide. Their ATT&CK framework is a constantly updated library of every known attack technique used by criminal groups and state-sponsored hackers — built from real incident data, not theory.

Think of it as a documented playbook of everything attackers do. When a criminal group successfully breaks into a bank, a hospital, or a business like yours, their methods get analysed and added to this library. Security professionals use it to understand what they're up against.

MITRE-Lite takes that intelligence and cuts it down to what actually matters for UK SMEs. You don't need to read a 500-page framework. You need to know who is active this week, what they're doing, and whether your business is at risk.

Last updated: 25 August 2026  ·  August 2026 Edition  ·  Next update: September 2026

Current Status

What is the threat level for UK businesses like yours?

Every week we assess the overall risk level for UK small businesses in financial services — insurance brokers, financial advisers, mortgage intermediaries, and professional services firms. This is based on real intelligence from the UK's National Cyber Security Centre (NCSC), US cyber agencies, and industry reporting.

█ Threat Level: Elevated

Attacks on UK financial services businesses remain above normal levels this month

Seven criminal and state-sponsored groups continue running active operations targeting UK businesses in your sector. This month's confirmed vulnerabilities affect some of the most widely used software in UK offices — Apple Macs, Microsoft SharePoint, and Windows VPN services. The UK's National Cyber Security Centre also published its first dedicated guidance on AI-driven attacks this month, confirming that agentic AI is now an operational threat — not just a future concern. MITRE-Lite moves to monthly updates from this edition, published at the end of each month.

What do the three levels mean?
Normal — background level of threat activity, no significant increase in targeting of your sector.
Elevated — active campaigns confirmed against UK businesses in your sector. Increased vigilance recommended.
High — significant coordinated threat activity. Specific sectors or business types being actively targeted at scale.
Most Urgent This Week

The most important thing your staff need to know right now

Each week we identify the single highest-risk attack technique that is seeing a spike in use against UK businesses. This week:

► Highest Risk This Month — August 2026 Edition

If your office uses Apple Macs — someone on your network could access them remotely without a password

A confirmed vulnerability in Apple macOS (CVE-2026-65400) allows anyone on the same network as a Mac to connect to its Screen Sharing feature without entering a password. Screen Sharing is Apple's built-in remote desktop tool — the equivalent of someone sitting at that computer and seeing everything on screen, opening files, running applications, and reading emails.

The vulnerability was added to the US government's confirmed-exploited list on 18 August 2026, meaning it is being used in real attacks right now. You do not need to be on the internet to be at risk — anyone connected to the same office Wi-Fi or network as a Mac can potentially exploit this.

This is particularly relevant for businesses that run a mix of Macs and Windows machines. Windows devices are often more tightly managed by IT providers, with automatic updates and monitoring in place. Macs are sometimes treated as exceptions — especially if they belong to senior staff or creative roles — and may be running older software without anyone noticing.

At the same time, Microsoft SharePoint has received yet another confirmed vulnerability this month — its fourth in 2026. This one (CVE-2026-55040) allows an unauthenticated attacker to bypass SharePoint's security features entirely. If your business uses SharePoint for document storage, intranet pages, or team collaboration, your IT provider needs to have applied the August 2026 patches.

What to do right now: If your office has any Apple Macs, ask your IT provider to confirm that macOS has been updated to the latest version and that Screen Sharing is either disabled or restricted to specific users only. For SharePoint, ask whether all August 2026 Microsoft patches have been applied. Both of these are straightforward IT maintenance tasks — they should be confirmable within the day.
Also this month — the UK government's cyber security agency has published its first formal guidance on AI-driven attacks: The NCSC published dedicated guidance on 20 August 2026 on managing the cyber risk from agentic AI — AI systems that can take actions on your behalf, make decisions, and operate without constant human supervision. This is the first time the NCSC has treated AI agents as an operational threat rather than a theoretical future risk. If your business is using AI tools that have access to your data, email, calendar, or financial systems, this guidance is worth reading. The link is ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai.
Also this month — FCA warns about mini-bonds and loan notes being marketed to consumers: The FCA has issued two separate warnings this month about unregulated loan notes and mini-bonds being promoted to retail consumers with promises of high returns. For insurance brokers and financial advisers, this is worth noting: if a client mentions they have invested in or been approached about a mini-bond or loan note from an unregulated company, this is a red flag. The FCA is actively monitoring this space. Knowing your client's other financial exposures — including high-risk unregulated products — is increasingly part of the due diligence picture.
A note on MITRE-Lite updates: From this edition, MITRE-Lite moves from weekly to monthly updates. The content will be refreshed at the end of each month based on the month's threat intelligence. The quality and depth of analysis remains the same — the cadence is simply more sustainable and still gives you the current threat picture for any given month.
1
Get all Apple Macs in your office updated to the latest macOS version this week

The Apple macOS vulnerability confirmed this month (CVE-2026-65400) is fixed in the latest version of macOS. The fix exists — the risk is entirely in whether the update has been applied. On any Mac, click the Apple menu in the top-left corner → System Settings → General → Software Update. If an update is available, install it. If your IT provider manages your Macs, contact them and ask them to confirm all devices are on the latest macOS version. Pay particular attention to Macs belonging to senior staff — they often have more access to sensitive data and are less likely to have had recent IT attention. If your office uses Mac computers that no longer receive software updates (Apple typically supports devices for around seven years), those machines are a permanent security risk and should be considered for replacement.

Why now: CVE-2026-65400 was confirmed exploited on 18 August 2026. Any unpatched Mac on a shared office network is vulnerable to unauthenticated remote access right now.

2
Confirm August Microsoft patches have been applied — particularly for SharePoint and Windows VPN

Microsoft releases security patches on the second Tuesday of each month. August's round included fixes for SharePoint (CVE-2026-55040, authentication bypass) and Microsoft's Internet Key Exchange service (CVE-2026-33824, remote code execution via Windows VPN). Both are confirmed exploited this month. If your IT provider manages your Microsoft 365 environment and Windows devices, these patches should have been applied automatically — but it is worth confirming. Ask your IT provider: have all August 2026 Microsoft security patches been applied across our devices? If you manage your own Windows machines, go to Settings → Windows Update and check for updates. The SharePoint patch in particular matters if your business stores documents or runs any internal sites on SharePoint.

Why now: Both vulnerabilities confirmed exploited 18 August 2026. SharePoint has now had four separate confirmed exploited vulnerabilities in 2026 — the pattern makes it a priority patching target.

3
Read the NCSC's new guidance on AI agents — especially if your business is starting to use AI tools

The NCSC published its first dedicated guidance on the cyber risks of agentic AI on 20 August 2026. Agentic AI refers to AI systems that do not just answer questions but take actions — booking appointments, sending emails, querying databases, making decisions. Many businesses are starting to use these tools without fully understanding the access they are granting. If an AI agent has access to your email, it has access to everything in your email. If it can access your client management system, it can read and write client data. The NCSC guidance covers the key questions to ask before deploying any AI agent in your business: what access does it need, what access is it actually being given, who can see what it does, and what happens if it is compromised. The guidance is practical and accessible — it is not written for technical audiences. Visit ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai.

Why now: NCSC published this guidance 20 August 2026 — their first formal treatment of AI agents as an operational risk. If your business is using or planning to use any AI tool with access to your systems or data, this guidance is directly relevant.

Want to know how exposed your business actually is?

A GET-IT resilience scan maps your current defences against the active threat techniques on this page and tells you exactly where your gaps are — in plain English, with costs to fix them.

Book a Free Resilience Scan → View Technical Version
Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, FCA ScamSmart, and the MITRE ATT&CK framework (CC BY 4.0). All figures are sourced from published industry data and government reporting — see the technical version for full source references. This page is updated every Monday. GET-IT Solutions Ltd is not responsible for inaccuracies in third-party source data. Nothing on this page constitutes legal or regulatory advice.