🛡️ UK Cyber Incident Digest

13 August 2026 — last 24 hours

Our monitoring pipelines (DarkWatch dark-web monitoring, URLScan.io, ransomware.live and threat-intel RSS feeds) logged 586 new threats in the last 24 hours, 579 of them high-severity. Here is what matters for UK families and businesses.

1. UK phishing storm — 574 high-severity domains

The biggest UK-relevant story today is a sustained wave of fake domains impersonating UK banks and public services. Criminals register lookalike domains daily and use them in texts, emails and adverts.

Brands being impersonated right now:

Target What we saw
Barclays Largest cluster — dozens of .ph domains (barclays-bankplc.ph, barclays-b2b.ph, barclaysmoodoflondon.ph…)
HSBC Fake "personal banking verify" login pages (hsbcpersonalbankingverifyagreement.ph…)
Lloyds / TSB Offshore banking lookalikes + api.lloydsbank.com impersonation
Nationwide Card-processing phishing pages
NHS NHS-branded banking scam (nhsbc.com.ph) — the double-trust trick
Royal Mail New parcel-delivery cluster (royalmail.io, royalmailtewantin.com.au)

Ongoing waves are also targeting BT (64 lookalikes), Sky (61), Amazon (50).

⚠️ The rule: a text or email containing a link to "your bank / your parcel / your account" is the #1 delivery method. If in doubt, don't tap the link — go to the official app or website yourself, or call the number on the back of your card.

2. Enterprise threats — patch these now

  • 🔴 Lazarus Group Windows zero-day — exploited for SYSTEM access and backdoor deployment. North-Korea-linked APT; patch priority.
  • 🔴 VMware vCenter vulnerability — actively exploited for persistent remote access.
  • 🔴 Adobe patches 3× CVSS 10.0 flaws — ColdFusion and Campaign Classic. ColdFusion is widely used in UK government and enterprise.
  • 🔴 "ShieldBreak" zero-day PoC — claims a Microsoft Defender patch bypass with SYSTEM access.
  • 🟠 SAP Commerce Cloud RCE — unauthenticated attackers can execute arbitrary code.
  • 🟠 Cisco ASA/FTD flaw — exploited in the wild for remote denial of service.
  • 🟠 Malicious LiteLLM packages — tied to the Trivy hack; 2,100+ organisations may be exposed.

3. Consumer alert — Chrome VPN extensions

737 Chrome VPN extensions were caught routing user traffic through proxies. If you installed a VPN extension recently, check it — uninstall anything you don't recognise and review your permissions.

Bottom line

  • UK families: the immediate risk is bank-brand phishing — texts, emails and lookalike domains. Slow down, verify, never tap.
  • UK businesses: prioritise patching VMware vCenter, Adobe ColdFusion, and monitor for the Lazarus zero-day and the ShieldBreak Defender bypass PoC.

Stay safe. WE FEAR NO ONE.