| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Aug 27, 2026 | NCSC | Guidance | Disruptive cyber activity highlights risk from internet-exposed systems and edge devices The NCSC has seen increased targeting of operational technology (OT) systems across multiple sectors globally, including in the UK. This has been carried out by a range of threat actors and resulted in some limited real-world disruption. | NCSC-UK |
| Aug 26, 2026 | CISA | Advisory | CISA Vulnerability Review misuse, in accordance with applicable rules and procedures for public release. Information is subject to The information in this report is being provided “as is” for informational purposes only. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, 1re commendation, or favoring by CISA. | CISA |
| Aug 26, 2026 | NSA | Advisory | Joint CSA: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. | CNMF, FBI, NSA |
| Aug 25, 2026 | CISA | Advisory | A Tale of Two SOCs: Insights From Two Red Team Assessments identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model. This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments. ▪ Untuned detection tools lead to missed threats. | CISA |
| Aug 20, 2026 | NCSC | Guidance | Managing the cyber risk of agentic AI Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the Agentic AI systems have shown potential to transform how organisations work, at times delivering unparalleled productivity gains. They can automate complex workflows, reduce routine effort and enable people to focus on highervalue tasks. | NCSC-UK |
| Aug 19, 2026 | ASD/ACSC | Alert | HIGH ALERT: Active exploitation of remote monitoring and management platform within Australia Alert on active exploitation in Australia of N-able and N-central vulnerabilities CVE-2026-18556 and CVE-2026-18577. Assess exposure and apply mitigations. | ASD/ACSC |
| Aug 19, 2026 | CISA | Advisory | Defending Against an Active Threat to Siemens S7 Series PLCs However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. | CISA |
| Aug 19, 2026 | CERT-EU | Advisory | 2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway The vulnerability CVE-2026-19489 (CVSS: 8.8) is a memory overflow vulnerability that can lead to unpredictable behaviour or Denial of Service. The vulnerability CVE-2026-19490 (CVSS: 9.3) is an authentication bypass using an alternate The following supported versions of NetScaler ADC and NetScaler Gateway are affected: The vulnerability CVE-2026-19489 requires SIP ALG(Session Initiation Protocol Application Layer Gateway) to be enabled on a Large… | CERT-EU |
| Aug 13, 2026 | NCSC | Guidance | How BitLocker PINs help protect your data and devices This includes setting up BitLocker, which encrypts your device to protect the data and the operating system from tampering. Our guidance recommends that BitLocker be configured to require a PIN before decrypting your device. | NCSC-UK |
| Aug 12, 2026 | NCSC | Guidance | Help shape the future of resilient private 5G The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and The National Cyber Security Centre (NCSC) is seeking to engage with technology partners, innovators, and industry leaders to explore the next generation of resilient and secure private 5G capabilities. | NCSC-UK |
| Aug 12, 2026 | JPCERT/CC | Alert | Microsoft Releases August 2026 Security Updates Microsoft has released August 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication or elevate privileges locally after authentication, etc. According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. | JPCERT/CC |
| Aug 11, 2026 | ASD/ACSC | Guidance | When AI agents take unexpected actions Learn how AI agents can take unexpected actions, understand the risks of goal misalignment, and apply practical safeguards for safer AI adoption. | ASD/ACSC |
| Aug 11, 2026 | NCSC | Guidance | Water sector example added to the NCSC’s Secure connectivity principles The NCSC has published a new fictional worked example demonstrating how organisations can apply the Secure Connectivity Principles for Operational Technology (OT). The example explores how a regional water utility might approach the challenge of standardising digital connectivity across its OT environment while maintaining safety, reliability and cyber The aim of the example is not to prescribe a single architecture or implementation. | NCSC-UK |
| Aug 10, 2026 | CISA | Advisory | #StopRansomware: Gunra Ransomware Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. | CISA, DC3, FBI, KNPA, NSA, USSS |
| Aug 5, 2026 | ASD/ACSC | Guidance | Frontier AI cyber threat considerations for boards of directors Guidance developed with the AICD on questions for boards to ask about AI cyber threats. | ASD/ACSC |
| Aug 4, 2026 | NCSC | Guidance | NCSC statement in response to recent incidents resulting from frontier AI evaluations Ollie Whitehouse, NCSC Chief Technology Officer, said: “Recent incidents of frontier AI models carrying out unsanctioned actions and, in some cases, human-like deceptive behaviour on the open internet are a serious reminder of the risks AI capabilities pose. “These technologies must be developed and used from the outset with strong safeguards, real-time oversight, and clear plans for responding when the unexpected happens. | NCSC-UK |
| Aug 4, 2026 | ASD/ACSC | Guidance | Defending against AI-enabled cyber attacks: Guidance for medium-sized businesses Recommended immediate, short and medium-term actions for medium-sized businesses to defend against AI-enabled cyber attacks. | ASD/ACSC |