
Weekly Roundup · Week of 10 to 16 August 2026
The week in business IT & comms
Two of this week's stories point at the same question: who is actually applying your updates. The Information Commissioner's Office reprimanded the UK's criminal records office after an attacker sat inside its website for seven months, and the failing it named was accountability rather than technology. Microsoft then shipped 421 fixes in one release, including a flaw already being used in attacks. Elsewhere, the market that sells business connectivity and IT support carried on merging into fewer, bigger suppliers.
- 01Compliance & Data
ICO reprimands criminal records office over patching gaps and unread alerts
The regulator found an attacker had access to ACRO's website and content management system between August 2022 and March 2023, with up to 10,920 people potentially affected. Nobody had clear responsibility for spotting which updates were needed, and the malware alerts that did fire were never reviewed.
Read the full story - 02Microsoft & Cloud
Microsoft's August update fixes 421 flaws, one already being exploited
The 11 August release covers 421 CVEs by SecurityWeek's count, the bulk of them in Windows and Office. CVE-2026-68820, a use-after-free bug in the Windows sockets driver, is being used in the wild to take a low-privilege local account up to SYSTEM.
- 03Cyber Security
Ransomware group Gunra is getting in through unpatched Fortinet firewalls
A joint advisory from the FBI, CISA and South Korea's National Police Agency describes attacks using two Fortinet flaws first disclosed in 2024 and 2025. The group works between 10pm and 6am in the victim's timezone and pulls data out of Microsoft 365 after bypassing MFA.
- 04Cyber Security
Half of UK manufacturers have no cyber incident response plan
Make UK published its Cyber Security in Manufacturing report on 10 August. It found 30% had a cyber incident in the past year, directly or through their supply chain, that only around half hold a response plan, and that almost a third have no cyber insurance or are unsure whether they are covered.
- 05Connectivity & Broadband
TalkTalk Business and ARO merge into a £200m connectivity and IT group
The merger announced on 14 August brings together around 650 staff and more than 70,000 business customers, pairing TalkTalk Business connectivity with ARO's cloud, cyber security and managed IT. Both brands stay in place while the deal clears National Security and Investment Act approval.
Read the full story - 06Connectivity & Broadband
UK lands 33rd out of 34 in Kearney's telecom health index
The consultancy's annual index put the UK in the bottom 10 markets, scoring poorly on customer sentiment and in the bottom half on technology deployment and commercial measures. It singled out mid-contract price rises becoming the norm, and the value gap that leaves when the service has not improved.
What we’re watching
Two to keep an eye on. The TalkTalk Business and ARO merger still needs National Security and Investment Act clearance, expected by the end of the summer, and on 10 August Ofcom opened investigations into whether Zayo Group UK and Tata Communications gave complete and accurate answers to a statutory information request about their network security duties. In the background the analogue phone network still retires on 31 January 2027, with no extension.
#WEARECOBALT
Got a question this raises?
If anything here makes you wonder where your business stands, ask us. We'll give you a straight answer for your setup, with no obligation.