This Week In Cyber
14th July – 21st July 2026

This is the Cyber Toolkit weekly roundup of key cyber security news, covering the most relevant vulnerabilities, breaches and incidents affecting organisations in the UK and beyond over the past week (14th July – 21st July 2026).

Japan's largest taxi operator was forced to shut down multiple internal systems following a cyber attack that disrupted business operations across parts of its network. While investigations into the incident remain ongoing, the attack highlights how ransomware and other disruptive cyber incidents continue to impact organisations providing essential public services.

Security researchers disclosed a new OAuth client ID spoofing technique that allows attackers to abuse weaknesses in OAuth implementations to trick users into authorising malicious applications. Rather than exploiting the OAuth protocol itself, the attack targets incorrect implementations, making it difficult for users to distinguish between legitimate and malicious consent requests. Organisations relying on third-party authentication should review their OAuth configurations, validate redirect URI handling and ensure users are educated to scrutinise application consent prompts before granting access.

SonicWall issued urgent security updates after two critical zero-day vulnerabilities affecting SMA 1000 secure remote access appliances were found to be under active exploitation. The flaws could allow remote attackers to gain elevated privileges and execute arbitrary code, with security researchers warning that internet-facing appliances are already being targeted. Organisations using affected SonicWall appliances should apply the latest security updates immediately, review systems for signs of compromise and ensure remote access infrastructure remains a high priority within vulnerability management.

Microsoft's July Patch Tuesday delivered one of its largest security releases, addressing more than 570 vulnerabilities, including three actively exploited zero-day flaws. The update includes fixes across Windows, Microsoft Office, Azure, SQL Server and numerous other products relied upon by organisations worldwide. Given the scale of the release and the presence of exploited vulnerabilities, organisations should prioritise testing and deploying these updates as quickly as possible while monitoring for any signs of attempted exploitation.

Zoom warned customers of a critical account takeover vulnerability that could allow attackers to compromise user accounts under specific conditions. Successful exploitation could enable unauthorised access to meetings, recordings and other sensitive organisational data. Organisations using Zoom should ensure the latest security updates have been applied and continue enforcing multi-factor authentication to reduce the impact of credential-related attacks.

Researchers also disclosed a newly discovered WordPress vulnerability, dubbed WP2Shell, which could allow unauthenticated attackers to achieve remote code execution on vulnerable websites under certain conditions. Given WordPress' widespread adoption, attackers are expected to rapidly incorporate the exploit into automated scanning and exploitation campaigns. Organisations operating WordPress sites should apply available patches immediately, minimise unnecessary plugins and monitor internet-facing web servers for suspicious activity.

This week, Cyber Toolkit demonstrated its pivotal role by issuing 140 technical alerts, enabling organisations to stay ahead of emerging threats and respond promptly. Furthermore, our system identified 57 critical vulnerabilities across various systems. These figures highlight the importance of proactive measures and, as cyber threats continue to evolve, it is crucial for organisations to stay vigilant and utilise effective and FREE tools like Cyber Toolkit to manage their cyber security risks.

We'll see what next week brings.