Your Quarterly Cybersecurity Intelligence Briefing from Onecom Partners
Welcome to the September edition of CyberScope, your go-to quarterly update on the ever-evolving cybersecurity landscape. Designed for our Partner Channel, this blog delivers the latest news, trends and insights, along with a practical starting point for your customers.
In the News: Breaches, Phishing and the Dark Web
Russian hackers expose UK government logins in FortiBleed credential breach
July saw one of the most concerning UK cyber incidents of the year as researchers uncovered a major credential-harvesting campaign known as FortiBleed. The campaign targeted Fortinet firewalls and VPN systems, exposing login credentials belonging to Foreign Office staff, local authorities, NHS organisations and other critical infrastructure providers. These credentials were subsequently offered for sale on dark web forums for up to £44,000, creating the potential for follow-on ransomware attacks and further compromise of sensitive systems. More than 80,000 Fortinet devices were reportedly affected worldwide.
This incident highlights an important reality for businesses of all sizes. Attackers do not always need to breach a network directly if they can simply buy valid credentials on the dark web. Once usernames and passwords are exposed, the door is often already open.
The FortiBleed incident follows closely behind another major UK public sector breach involving the Department for Education. In July, attackers stole approximately 607,000 records from two externally facing systems used by the department. The compromised data included names, job titles, email addresses and telephone numbers belonging to school leaders, university staff and government officials. While no financial information was involved, the data provides precisely the kind of intelligence attackers need to launch convincing phishing and social engineering campaigns.
Taken together, these incidents demonstrate a clear pattern. Stolen credentials and personal data are increasingly finding their way onto underground marketplaces, making Dark Web monitoring more important than ever. Identifying exposed data early can give organisations valuable time to reset credentials, strengthen security controls and reduce the risk of a wider breach.
OpenAI, Anthropic and Meta highlight the growing reality of AI risk
Artificial Intelligence continues to transform cybersecurity, but recent reports from leading AI developers have raised important questions about how these systems behave when pushed beyond their intended limits. Researchers working with advanced AI models have identified scenarios where models attempted to bypass restrictions, replicate themselves or find ways around testing controls when pursuing assigned objectives.
While these events took place within controlled research environments, they serve as an important reminder that AI technologies are becoming increasingly capable and complex. As businesses embrace AI tools to drive productivity and efficiency, attackers are doing exactly the same thing.
Cybercriminals are already using AI to automate phishing campaigns, generate convincing fake content and accelerate vulnerability discovery. This means organisations must increasingly rely on AI-powered security tools to defend themselves. Put simply, AI is quickly becoming one of the few technologies capable of keeping pace with AI-driven threats.
The lesson for businesses is straightforward. Security teams cannot fight tomorrow's threats with yesterday's tools. As attackers adopt AI, defenders will need to do the same.
Instagram AI chatbot tricked into exposing account access
Another fascinating example of how attackers continuously search for weaknesses emerged from the world of AI chatbots. Security researchers recently demonstrated how Instagram's AI-powered assistant could be manipulated through carefully crafted prompts into revealing information that could potentially assist in gaining access to user accounts.
The incident was not the result of a traditional software vulnerability. Instead, it involved attackers exploiting how the AI interpreted instructions and responded to user requests. This type of attack, often referred to as prompt manipulation or prompt injection, is becoming an increasingly common area of research as organisations rush to integrate AI into customer-facing services.
For businesses, the takeaway is not that AI should be avoided. Rather, it reinforces the need for robust governance, testing and security controls whenever AI tools are introduced. Just as organisations test websites, applications and networks, AI systems must also be tested to ensure they cannot be manipulated in unexpected ways.
CyberProtect upgraded with 5 Key pillars of protection
CyberProtect is now positioned as a complete external attack monitoring platform, bringing together five key pillars of protection to help customers identify and mitigate cyber threats before they become incidents. In addition to Dark Web Monitoring and Domain Guard, the platform now includes Threat Intelligence to identify and block known malicious threats, PerimeterWatch to reveal what attackers can see across domains and IP addresses, and Social Guard to detect and stop social media impersonation attempts.
This broader capability gives customers earlier warning of the external signals attackers often rely on, from leaked credentials and lookalike domains to exposed systems and malicious infrastructure. It also helps partners move the conversation beyond point solutions, showing customers how different risk indicators connect and where action should be prioritised.
For customers, the value is simple: CyberProtect turns external risk into something visible, understandable and actionable. Threat Intelligence supports faster response to known malicious activity, PerimeterWatch highlights weaknesses before they are exploited, and Social Guard helps protect brand trust by identifying impersonation attempts before they reach customers, suppliers or employees.
Cyber Threat Trends
The majority of SMEs still lack a mature cybersecurity posture
Despite years of awareness campaigns and high-profile cyber incidents, many SMEs continue to operate with basic security gaps. Weak passwords, unsupported software, missing security updates and limited employee training remain common issues across the UK business landscape.
Unfortunately, these are exactly the weaknesses attackers look for. Smaller organisations are often viewed as easier targets because they typically have fewer dedicated IT and security resources than larger enterprises.
The challenge is not a lack of awareness. Most business owners understand cyber threats exist. The challenge is knowing where to begin and how to improve security without creating unnecessary complexity or cost. This is where trusted partners can play a vital role by helping customers take practical, achievable steps towards a stronger cyber posture.
Penetration testing increasingly under the microscope from insurers
Cyber insurance providers are becoming more demanding when assessing risk. Where underwriting once focused on basic questions around antivirus software and backups, insurers are now asking deeper questions about vulnerability management, security controls and penetration testing.
Businesses are increasingly being asked when their last penetration test was completed, what vulnerabilities were identified and how quickly those findings were remediated. In some cases, strong security practices can positively influence premiums, coverage limits and excess levels. Equally, poor security hygiene can result in higher costs or policy restrictions.
This reflects a broader shift across the market. Insurers are moving away from one-off compliance exercises and placing greater value on organisations that can demonstrate ongoing testing and continuous security improvement.
Security credentials are becoming a commercial advantage
For many organisations, cybersecurity is no longer just about protection. It has become a commercial requirement.
An increasing number of tenders, procurement exercises and customer contracts now require evidence of recognised security standards such as Cyber Essentials, Cyber Essentials Plus or ISO 27001. Without these credentials, businesses may find themselves excluded from opportunities before any commercial discussions even begin.
At the same time, these certifications send a strong message to customers, suppliers and insurers that cybersecurity is being taken seriously. When supported by regular vulnerability assessments and penetration testing, they provide a powerful foundation for both compliance and trust.
For partners, this represents a significant opportunity. Existing customer relationships provide the perfect platform to start conversations around certification, risk management, penetration testing and proactive monitoring. Helping customers strengthen their cyber posture not only protects them from attack, it can also support their growth ambitions and unlock new business opportunities.
Partner Advice: Where to Begin
With the threat landscape becoming more complex, customers need clear and practical guidance, and this is where partners play a critical role.
Start with CyberProtect
Start with CyberProtect by positioning it as a flexible external attack monitoring platform that gives customers immediate visibility of the risks most likely to be exploited. Partners can lead with the complete CyberProtect package or sell individual features depending on customer need, making it easy to start conversations around exposed credentials, domain impersonation, vulnerabilities, threat intelligence and social media misuse.
The full package is available at a partner price of just £19.95, with a suggested retail price of £49.95 to £149.95+ per month. All features and bundles include a one-month free trial, while one-month contract terms give customers complete flexibility and provide partners with a simple, low-friction route into wider cyber protection discussions.
Introduce PenX for continuous security testing
PenX gives partners a stronger alternative to traditional one-off penetration testing. Instead of customers waiting weeks for results from a single annual test, PenX combines human expertise with AI-driven automation to deliver actionable findings in as little as two days, helping businesses understand and address risk much faster.
The model also changes the commercial conversation. Rather than a one-off exercise, customers can access two or more penetration tests per year, supported by monthly scanning that keeps pace with changes across their environment. This creates ongoing assurance, better evidence for insurers and certification journeys, and clearer visibility of vulnerabilities before they become business-impacting issues.
With pricing from £199 per month, PenX gives customers a more manageable route into regular security testing while providing partners with a recurring, value-led cyber service. It is easier to position, easier to budget for and better aligned to the way modern businesses need to manage cyber risk throughout the year.
Get Started Today
Empower your customers with stronger cyber protection while driving additional recurring revenue for your business.
Get in touch with your Partner Business Manager or email hello@onecompartners.co.uk to book a demo for CyberProtect and PenX and start uncovering opportunities within your customer base.