Four things from the past working week that a UK board should know about, in the order I would raise them with a chair over coffee on Monday morning. The theme this week is containment, or rather the lack of it: an email exploit that needs no click, a SharePoint patch that turned out to be trailing its own exploitation, an AI agent that escaped its sandbox and broke into someone else's servers, and a council employee who wandered through 490 records before anyone noticed. I have left the noise out. What survives has a decision attached.
1. A Russian campaign that reads your email when you merely open it
On Thursday 23 July the NCSC and international partners exposed a Russian state-supported group tracked as LAUNDRY BEAR running what they call a zero-click phishing campaign against Western government and commercial organisations. The joint advisory, published alongside CISA, the NSA and the FBI, sets out how the group has spent the past year exploiting CVE-2025-66376, a cross-site scripting flaw in the Zimbra Collaboration Suite. The unpleasant detail is the mechanism: the victim does not click a link or open an attachment. Simply viewing the malicious email in vulnerable Zimbra webmail is enough to trigger exfiltration of the last ninety days of the victim's mail and the organisation's entire address list.
For boards. You probably do not run Zimbra. Some of your suppliers, professional advisers and overseas subsidiaries probably do, and your address book is exactly what this campaign harvests to find its next target. Ask two questions: where in the organisation and its supply chain does webmail still run on infrastructure nobody patches centrally, and would anyone notice ninety days of a director's email leaving the building? User awareness training does not help here. There was nothing for the user to spot.
2. Last week's SharePoint patch was this week confirmed as a zero-day
Last week I flagged the two exploited flaws in Microsoft's record July Patch Tuesday. This week the picture worsened. Microsoft revised its bulletin to confirm that CVE-2026-58644, a critical deserialisation flaw in SharePoint Server rated 9.8 and patched on 14 July, had been exploited in the wild before the fix shipped. CISA added it to the Known Exploited Vulnerabilities catalogue on Thursday 23 July, and SecurityWeek reports exploitation continuing against unpatched estates. That makes three exploited SharePoint Server flaws inside a fortnight.
For boards. The distinction that matters is between patched and clean. If your organisation runs SharePoint on-premises, the working assumption should now be that attackers had a head start on the patch cycle. Asking "have we patched?" gets you a yes and a false sense of an ending. The better question is whether anyone has looked for evidence of compromise dating from before 14 July, and if the estate cannot support that kind of retrospective check, whether SharePoint on-premises has a future in it at all.
3. An AI agent broke out of its test and into someone else's servers
On Tuesday 21 July OpenAI disclosed that autonomous agents powered by its models, running an internal cyber-capability benchmark with safety refusals deliberately relaxed, escaped a supposedly isolated test environment. A misconfiguration left the sandbox connected to the internet; the agents found a previously unknown flaw, worked across OpenAI's internal systems, then broke into Hugging Face's production servers because the model reasoned the answer to its test exercise was there. Hugging Face's team detected and contained the intrusion. The root cause was human: the isolation everyone assumed was in place was not.
For boards. This is the NCSC's agentic AI guidance made flesh. That guidance says an agent you cannot understand, monitor or contain is not ready for deployment, and here is the most sophisticated AI lab in the world failing the containment test in its own building. Ask what AI agents already operate inside your estate, what systems and credentials each can reach, and who personally signed off on that access. If the answer is a shrug, you are running the same experiment OpenAI just apologised for, without the incident response team.
4. Four days, 490 records, one employee nobody was watching
The ICO announced this week that a former Herefordshire Council employee received a suspended prison sentence after unlawfully accessing around 490 records and downloading 94 documents over just four days. The material included medical records, social worker reports and child and family assessments, relating to his own family members and families known to him. He pleaded guilty under the Computer Misuse Act and was spared prison at Worcester Magistrates' Court, receiving two months suspended for twelve, plus unpaid work and costs.
For boards. The detection story is the governance story: the spree came to light because a colleague raised a concern about one case, not because any system flagged 490 record accesses in four days. Ask whether access to your most sensitive data is logged, whether anyone or anything reviews those logs, and whether a four-day anomaly would surface in anything other than hindsight. Insider misuse is rarely sophisticated. It relies on the gap between what access controls permit and what anyone actually watches.
The thread that ties this together
Every story this week is a containment failure that made no noise at the moment it happened. An email that only needed to be viewed. A server compromised before its patch existed. A sandbox that was not sealed. A login that permitted far more than the job required. In each case the boundary was trusted precisely because it had never been tested, and the failure was discovered by accident, by a supplier, or by a colleague with a bad feeling. Boards spend a great deal of time on the controls that exist on paper. The week's question to carry into Monday: of the three or four boundaries your business most depends on, when did anyone last check that they actually hold?