What Business Owners Need to Know This Week
Week 32 (26 July–2 August 2026) is a visibility week. Nothing new was posted against a South African target inside the window, yet the domestic picture worsened: four mid-July victims surfaced at once, headed by Fidelity Services Group, Southern Africa’s largest integrated security solutions provider. This is what the reporting lag costs in practice — leak-site monitoring gives South African defenders a two-to-three-week-old view, so a quiet week is a statement about the feed, not the threat. Domestically, the item to action is the SARS alert of 28 July: the revenue service formally confirmed that criminals are now using generative AI to write its impersonation phishing, at the peak of filing season.
The Bottom Line: SARS’s own words — scammers are “using AI to generate professional-looking email templates that are harder to identify as fraudulent”. This is the first time a South African public body has formally named generative AI as the reason its brand-impersonation fraud has become harder to spot, and it lands while millions of taxpayers are actively expecting SARS correspondence. The practical consequence is blunt: the single most widely taught consumer defence in South Africa — look for bad spelling and clumsy grammar — has stopped working. Change the advice you give your staff this week.
The Week in Numbers
- 116 cumulative SA ransomware victims — HIGH threat level for the 12th consecutive week.
- 4 SA victims surfaced at once — all claimed in mid-July, none visible when this report checked the same source a week earlier.
- 2–3 weeks — the demonstrated aggregator lag in the country feed most local teams watch. Treat any week’s SA count as a floor that will later be revised upward.
- ~142 points of presence — the Fidelity Services Group footprint across guarding, cash-in-transit and fire services.
- R48,900 — the refund figure in one SARS phishing specimen, designed to make the lure worth clicking.
- 3 new CISA KEV additions — the lowest count since W28, but two were already past their remediation date before this report reached a reader.
- CVSS 10.0 — Arista VeloCloud Orchestrator On-Prem CVE-2026-16812, a vendor-confirmed zero-day; KEV deadline 30 July, lapsed.
- CVSS 9.0, no patch — Fastjson 1.x CVE-2026-16723, exploited in the wild with no fix and no KEV listing.
- 4 overdue KEV carryovers — up from two the prior week.
- 9 weeks — since the Information Regulator last published anything.
Major Incidents: Who Was Hit and How
Four SA Victims Surface at Once — Fidelity Services Group Leads
The ransomware.live South African country map, retrieved 2 August, itemised four mid-July listings that were invisible a week earlier: Fidelity Services Group, claimed by RansomHouse on 15 July with an estimated attack date of 12 July; SuppCenter Global Services (M3rx, 17 July); Reatile Group, an energy investments holding company (IncRansom, 18 July); and CKR Consulting Engineers (Payload, 19 July). None has issued a public statement, so all four are rated CLAIMED. Fidelity is the most significant: Southern Africa’s largest integrated security solutions provider, running guarding, cash-in-transit and fire services across roughly 142 points of presence. A guarding-company breach is a physical-security problem as well as a POPIA one — access-control records, ID copies, biometric enrolments and site rosters are the typical holdings. If any of the four is your supplier, contractor or guarding provider, ask in writing what personal data they hold on your staff. Do not wait for an announcement that may never come.
SARS Names Generative AI in Its Own Phishing Alert
On 28 July the South African Revenue Service published a scam alert describing an SMS and
email wave telling recipients they are owed a refund — one specimen quoting
R48,900 — and directing them to a fraudulent site. The operative line
is the revenue service’s own: SARS “is noting with concern that the scammers are
now using AI to generate professional-looking email templates that are harder to identify as
fraudulent”. Correct grammar, genuine branding, real employee names. Tell staff the
spot-the-typo test is dead: the only safe action is to log in at the official eFiling
address typed by hand, never through a link, and to treat any refund figure quoted in
an email or SMS as unverified. Forward specimens to
phishing@sars.gov.za. Pair the warning with a technical control — block
newly registered lookalike domains containing sars or efiling at the
web proxy, and alert on inbound mail spoofing the sars.gov.za display name.
Edge and Management-Plane KEVs — Arista, Cisco, Fortinet
All three new KEV entries are network-edge or security-management products
— the category vendor research this week identified as the ransomware ecosystem’s
preferred front door. Arista VeloCloud Orchestrator On-Prem CVE-2026-16812
(CVSS 10.0, OS command injection) is a vendor-confirmed zero-day whose deadline was 30 July;
Arista published three attacker IPs (8.19.75.217, 206.72.242.124,
206.72.242.162) to block and retro-hunt in netflow. Cisco Secure Firewall
Management Center CVE-2026-20316 is a hard-coded credential with a 1 August deadline;
check for references to /var/tmp/license.tmp and treat them as possible
compromise. Fortinet FortiOS CVE-2025-68686 completes the set.
Exploited With No Patch — Fastjson and a Fresh Check Point PoC
Fastjson 1.x CVE-2026-16723 (CVSS 9.0, remote code execution) is being exploited in the wild with no fix available and no KEV listing — a category that catalogue-driven patching cannot address at all. Separately, Rapid7 published a working proof-of-concept on 29 July for the already-exploited Check Point SmartConsole flaw covered in W31, which materially lowers the barrier to entry for that attack and should push any outstanding remediation to the front of the queue.
POPIA and Regulatory
The Information Regulator’s media-statements index carries nothing later than 2 June — nine weeks of public silence across a period containing a confirmed provincial-government identity-document breach, a confirmed national distributor breach with acknowledged notification, and now four unacknowledged ransomware claims against South African companies. A sharper issue arises this week: four South African companies are publicly named on leak sites and none has made any statement. Section 22 obliges notification as soon as reasonably possible after there are reasonable grounds to believe personal information has been accessed by an unauthorised person — and a public listing naming the organisation is, at minimum, a trigger to investigate whether those grounds exist. On the FIC side, the Directive 11 second Risk and Compliance Return deadline closed at 17:00 on 31 July for legal practitioners, estate agents, non-casino gambling institutions and high-value goods dealers. A separate return is required per accountable institution against its own organisation identity number. Institutions that did not submit should not wait to be contacted — prompt voluntary regularisation is the posture that mitigates sanction.
Full Intelligence Report
The complete Week 32 technical report covers all four newly surfaced victim records with confidence ratings, the aggregator-lag methodology and what it means for domestic monitoring, the SARS AI-phishing analysis, full remediation guidance for the Arista, Cisco and Fortinet KEV entries with attacker infrastructure, the unpatched Fastjson exposure, threat-actor profiles, the sector heatmap, structured hunt missions with IOC tables and the full source list.
What Your Business Should Do Right Now
- Send a SARS-specific warning to every employee this week — and change the advice: The old spot-the-typo test is dead. Tell staff the only safe action is to log in at the official eFiling address typed by hand, never through a link, and to treat any refund figure quoted in an email or SMS as unverified. Forward specimens to phishing@sars.gov.za.
- Back the warning with technical controls: Block newly registered lookalike domains containing “sars” or “efiling” at the web proxy, and alert on inbound mail spoofing the sars.gov.za display name. Awareness alone does not survive well-written, correctly branded lures.
- Treat Arista VeloCloud CVE-2026-16812 as a suspected compromise, not a patch: It is a vendor-confirmed zero-day at CVSS 10.0 whose KEV deadline lapsed on 30 July. Block and retro-hunt the three published attacker IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) in netflow, then apply the fixed VCO builds (5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1 or later).
- Check Cisco Secure FMC for the hard-coded credential: CVE-2026-20316’s deadline was 1 August. In expert mode, check the message log for license references and treat any reference to /var/tmp/license.tmp as possible compromise — then rotate all credentials, keys and certificates on the appliance as Cisco advises.
- Run a supplier check against the four newly surfaced listings: Fidelity Services Group, Reatile Group, CKR Consulting Engineers and SuppCenter Global Services. If any is your supplier, contractor or guarding provider, ask in writing what personal data they hold on your staff — access-control records, ID copies, biometric enrolments and site rosters are the typical holdings for a physical-security provider.
- Mitigate Fastjson CVE-2026-16723 without a patch: It is exploited in the wild with no fix and no KEV entry. Inventory Fastjson 1.x usage, disable autotype where it is enabled, restrict deserialisation of untrusted input, and plan migration off the 1.x branch. Catalogue-driven patching will never flag this one.
- Re-prioritise any outstanding Check Point SmartConsole remediation: Rapid7’s 29 July proof-of-concept materially lowers the barrier to entry for a flaw that was already being exploited.
- Stop reading a quiet week as good news: The two-to-three-week aggregator lag means this week’s SA count is a floor that will be revised upward. Build that caveat into any internal reporting that uses leak-site totals, so a flat number is not presented to the board as an improving threat environment.