Leave passwords in the past – passkeys are the future
Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers. The NCSC (a part of GCHQ) has officially declared a new era for digital security, announcing that passkeys are now ready for mass adoption and should be the primary login choice for all consumers. The End of […]
Defending against China-nexus covert networks of compromised devices
What happened? China-linked cyber actors have evolved their strategy, shifting from custom-built infrastructure to the use of massive “covert networks.” These are sophisticated botnets composed of hijacked routers and various edge devices. The Role of Covert Networks These botnets are integrated into every stage of the Cyber Kill Chain, supporting: The Tactical Advantage This infrastructure […]
APT28 exploit routers to enable DNS hijacking operations
Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens. What happened? Russian state-sponsored actors, identified as APT28, are actively compromising routers to manipulate DHCP and DNS settings. By hijacking these protocols, attackers redirect network traffic through servers they control. The Attack Mechanism: Adversary-in-the-Middle (AitM) […]
NCSC warns of messaging app targeting
Alongside international partners, the NCSC has issued actions for individuals at risk of targeted attacks against messaging apps. What has happened? While apps like WhatsApp, Messenger, and Signal are essential tools for our daily communication, they have become prime targets for cyber threats. The NCSC, alongside international security partners, has observed an increase in malicious […]
Vulnerability affecting F5 BIG-IP APM
Organisations have been encouraged to take action against a vulnerability affecting F5 BIG-IP Access Policy Manager. The NCSC is urging UK organizations to immediately address a critical unauthenticated remote code execution (RCE) vulnerability (CVE-2025-53521) impacting F5 BIG-IP Access Policy Manager (APM). Because the BIG-IP APM is a widely used component—particularly across large enterprise networks—this vulnerability […]
Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
UK organisations encouraged to take immediate action to mitigate two recently disclosed vulnerabilities, CVE-2026-3055 and CVE-2026-4368, that affect Citrix NetScaler ADC and Citrix NetScaler Gateway. What has happened? Citrix has issued a security bulletin regarding two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Vulnerability Details CVE-2026-3055 (Memory Overread): Caused by insufficient input validation. This […]
NCSC advises UK organisations to take action following conflict in the Middle East
In response to the evolving events in the Middle East, the NCSC is advising that UK organisations review their cyber security posture. How has the cyber threat changed? While the ongoing conflict in the Middle East hasn’t yet triggered a major shift in the direct cyber threat from Iran to the UK, the situation is […]
Exploitation of Cisco Catalyst SD-WAN
Agencies strongly encourage immediate investigation of potential compromise of Cisco Catalyst SD-WAN, and full updating and hardening. What has happened? International cybersecurity agencies have issued a joint alert regarding active attacks on Cisco Catalyst SD-WAN systems worldwide. Malicious actors are infiltrating these networks by inserting “rogue peers,” allowing them to gain root control and maintain […]