Cybersecurity Threat Report — July 2026

A 29-slide briefing on what is actually hitting small and mid-size businesses this month: ransomware economics, AI-driven phishing and deepfake fraud, the supply-chain breaches that reached SMBs through their vendors, the six edge-device flaws under active exploitation, and what insurers and regulators now expect. Written by engineers, not marketers, and it ends with eight prioritized moves you can act on.

Published by NetSys Group engineers · July 2026 edition · Updated October 4, 2026

This month at a glance

Bottom line up front

Ransomware crews are hunting smaller organizations on purpose, attackers now break in through unpatched software more often than stolen passwords, and AI has collapsed the cost of a convincing attack. Threat level: Elevated, driven by identity-based intrusions and edge-device exploitation. The three highest-value fixes:

  1. Phishing-resistant MFA on email, VPN and every admin account.
  2. Backups you have actually restored from, tested on a schedule.
  3. Same-week patching of anything facing the internet.

Ransomware & digital extortion

Ransomware now appears in 48% of confirmed breaches, and average recovery cost reached $1.7 million. Smaller teams stop attacks before encryption 34% of the time, against 46% at large enterprises (Sophos, The State of Ransomware 2026). The gap is detection speed, not effort; managed detection and tested backups close it.

What we're watching: Qilin and fast-rising "The Gentlemen" are neck-and-neck for the top spot, and Akira is deploying ransomware in under an hour against unpatched SonicWall VPNs. Nearly every major intrusion this month traced back to an unpatched gateway, and attacks are timed for evenings and weekends. Wins: two Scattered Spider members were sentenced to 5.5 years each, and police dismantled a "bulletproof" VPN service used across dozens of ransomware operations.

AI-driven threats

AI has removed the cost and skill needed to run old attacks at scale. AI-written phishing went from 4% to 56% of reported phishing in one month (Hoxhunt 2026 Phishing Trends Report), and the FBI logged $893M in AI-enabled fraud losses. Spelling mistakes and odd grammar are no longer a reliable warning sign.

Deepfakes are a working criminal tool: one firm lost $25.6M to a video call of AI clones. The defense is procedural: a mandatory call-back to a known number stops it.

"Shadow AI" is already inside your business: 45% of employees use AI tools at work, and 63% of organizations have no AI policy (Industry survey data, 2026). A one-page policy plus an approved business-tier tool solves most of it.

Breaches & headlines

Your vendors are now your attack surface: more than half the time, a small-business breach starts with someone else's failure.

  • DentaQuest: a dental-benefits administrator breach exposed 2.6 million accounts, including 1.7M Social Security numbers.
  • Oracle 0-day: one PeopleSoft zero-day targeted 100+ organizations, and Nissan confirmed employee records were taken.
  • Salesforce: CRM-integration thefts showed how one platform's OAuth tokens sweep up unrelated companies.
  • Nayax: a cashless-payment terminal provider used by small retailers and laundromats, meaning direct SMB exposure.

Three numbers set the tone: 24B stolen credential records in one exposed database (Cybernews, June 2026), a 60% year-over-year jump in third-party and supply-chain breaches (Verizon 2026 DBIR), and a record 570 flaws in Microsoft's July Patch Tuesday (BleepingComputer, July 2026).

Vulnerabilities & phishing

Exploited flaws now drive 31% of breaches, up from 20%, beating stolen credentials for the first time; stolen credentials fell to 13% from 22% (Verizon 2026 DBIR). Yet only 26% of known-exploited flaws had been fully fixed. The average window from disclosure to exploitation fell to about five days in 2023, down from 63 in 2018 (Mandiant / industry exploitation analysis), and 28% of new flaws are exploited within 24 hours.

ProductIssueStatusDo this
MS SharePointActively exploited remote-code-execution chainExploitedPatch now; take the server off the public internet
Fortinet FortiGateFortiBleed: ~86,000 devices' credentials exposedExploitedReset all VPN and admin passwords
SonicWall SMA1000Unauthenticated flaw, CVSS 10.0ExploitedApply the vendor patch immediately
MS ExchangeTriggered by viewing a malicious email in OWAExploitedApply June/July cumulative updates
Palo Alto GlobalProtectAuthentication bypass into VPN sessionsHighPatch; review VPN logs
Citrix NetScaler"CitrixBleed"-style memory disclosureExploitedPatch and rotate session tokens

The inbox got harder to defend: 8.3B email phishing threats in a single quarter and a 146% rise in QR-code "quishing" (Microsoft Threat Intelligence, Q1 2026). 43% of BEC emails are now a simple request to get in touch, moving the conversation to text or another channel (LevelBlue, 2026). MFA-bypass kits routinely defeat SMS and app-push, so move privileged accounts to passkeys or FIDO2.

Compliance, insurance & the bottom line

Regulators and insurers are converging on the same short list of controls, so doing the work once satisfies both. What changed in 2026:

  • Privacy: new state laws took effect Jan 1 in Indiana, Kentucky and Rhode Island.
  • FTC Safeguards: now expects documented proof (written program, tested IR plan, MFA) from tax preparers, auto dealers, lenders and advisers.
  • PCI 4.0.1: first full enforcement cycle; MFA into any card-data environment and 12-character passwords are mandatory for every merchant.
  • CIRCIA: federal 72-hour incident reporting is targeted to finalize in September.

Carriers now require MFA, managed detection, immutable backups, a rehearsed IR plan and formal patching; one insurer reported zero Akira ransomware claims among clients running managed detection. The average claim hit a record $221K in 2025, 1 in 4 small businesses said an attack threatened survival, and only 47% carry cyber insurance, against 76% of large corporations (NAIC / Munich Re data, compiled 2026).

The NetSys action plan

Eight moves, ranked by impact for a business with 10 to 250 people. The first three remove most of the risk.

  1. Turn on phishing-resistant MFA everywhere.
  2. Put managed detection on every endpoint, not DIY antivirus.
  3. Fix immutable backups and restore-test them quarterly.
  4. Patch internet-facing devices within days and rotate credentials.
  5. Mandate call-back verification for money and access.
  6. Inventory vendors and app integrations; revoke stale OAuth access.
  7. Refresh awareness training for 2026 threats.
  8. Get, or right-size, cyber insurance.

Sources and method: figures are drawn from industry and government sources published in 2026: Verizon 2026 Data Breach Investigations Report; Sophos State of Ransomware 2026; CrowdStrike 2026 Global Threat Report; FBI IC3 2025 Internet Crime Report; Mandiant M-Trends 2026; Microsoft Threat Intelligence; Hoxhunt 2026 Phishing Trends; Coveware, Black Kite and ReliaQuest ransomware tracking; Cybernews; Hiscox Cyber Readiness 2026; At-Bay 2026 InsurSec Report; IBM Cost of a Data Breach; and CISA advisories. Where trackers differ in methodology, we cite the most directly verifiable figure.

The designed PDF edition, with charts, is free. One short form on the main report page unlocks this edition and every other one. Get the PDF

Beyond the report

Discuss the security controls behind the headlines.

Share the systems, data and risks your business needs to protect. A NetSys engineer can discuss monitoring, identity protection, backups and incident response within an agreed scope.

Explore Cybersecurity Services 845-203-3914