🛡️ UK Cyber Incident Digest
13 August 2026 — last 24 hours
Our monitoring pipelines (DarkWatch dark-web monitoring, URLScan.io, ransomware.live and threat-intel RSS feeds) logged 586 new threats in the last 24 hours, 579 of them high-severity. Here is what matters for UK families and businesses.
1. UK phishing storm — 574 high-severity domains
The biggest UK-relevant story today is a sustained wave of fake domains impersonating UK banks and public services. Criminals register lookalike domains daily and use them in texts, emails and adverts.
Brands being impersonated right now:
| Target | What we saw |
|---|---|
| Barclays | Largest cluster — dozens of .ph domains (barclays-bankplc.ph, barclays-b2b.ph, barclaysmoodoflondon.ph…) |
| HSBC | Fake "personal banking verify" login pages (hsbcpersonalbankingverifyagreement.ph…) |
| Lloyds / TSB | Offshore banking lookalikes + api.lloydsbank.com impersonation |
| Nationwide | Card-processing phishing pages |
| NHS | NHS-branded banking scam (nhsbc.com.ph) — the double-trust trick |
| Royal Mail | New parcel-delivery cluster (royalmail.io, royalmailtewantin.com.au) |
Ongoing waves are also targeting BT (64 lookalikes), Sky (61), Amazon (50).
⚠️ The rule: a text or email containing a link to "your bank / your parcel / your account" is the #1 delivery method. If in doubt, don't tap the link — go to the official app or website yourself, or call the number on the back of your card.
2. Enterprise threats — patch these now
- 🔴 Lazarus Group Windows zero-day — exploited for SYSTEM access and backdoor deployment. North-Korea-linked APT; patch priority.
- 🔴 VMware vCenter vulnerability — actively exploited for persistent remote access.
- 🔴 Adobe patches 3× CVSS 10.0 flaws — ColdFusion and Campaign Classic. ColdFusion is widely used in UK government and enterprise.
- 🔴 "ShieldBreak" zero-day PoC — claims a Microsoft Defender patch bypass with SYSTEM access.
- 🟠 SAP Commerce Cloud RCE — unauthenticated attackers can execute arbitrary code.
- 🟠 Cisco ASA/FTD flaw — exploited in the wild for remote denial of service.
- 🟠 Malicious LiteLLM packages — tied to the Trivy hack; 2,100+ organisations may be exposed.
3. Consumer alert — Chrome VPN extensions
737 Chrome VPN extensions were caught routing user traffic through proxies. If you installed a VPN extension recently, check it — uninstall anything you don't recognise and review your permissions.
Bottom line
- UK families: the immediate risk is bank-brand phishing — texts, emails and lookalike domains. Slow down, verify, never tap.
- UK businesses: prioritise patching VMware vCenter, Adobe ColdFusion, and monitor for the Lazarus zero-day and the ShieldBreak Defender bypass PoC.
Stay safe. WE FEAR NO ONE.
