Cookie Consent by Free Privacy Policy Generator

Cyber Brief: ASOS breach, Atlassian flaw, FortiBleed warning

Today's brief focuses on incidents and vulnerabilities affecting systems widely used across UK organisations. The NCSC has confirmed a cyber incident at ASOS affecting customer data, Atlassian has patched a critical vulnerability across eight of its collaboration products, the FBI has issued a renewed warning about ongoing FortiBleed attacks targeting Fortinet VPN users, and Google has released October security updates addressing 25 vulnerabilities in Android. Together, these stories highlight the importance of timely patching, incident response preparedness, and understanding how third-party breaches may affect your customers or supply chain.

NCSC confirms cyber incident affecting ASOS customers

The National Cyber Security Centre has confirmed that UK fashion retailer ASOS is investigating a cyber incident in which some customer personal information may have been accessed. The BBC reports that ASOS sent an unauthorised customer notification via its mobile app on Tuesday, raising alarm among users. ASOS has stated publicly that it is working to understand the scope of the incident and has notified the Information Commissioner's Office. The company has not yet confirmed what specific customer data may have been compromised, how many customers are affected, or the nature of the attack.

For UK businesses, this incident is a reminder that even well-established organisations with mature security programmes can experience breaches that affect customer trust and regulatory obligations. Retailers and e-commerce platforms hold significant volumes of personal data, payment information and account credentials, making them high-value targets. The fact that attackers were able to send unauthorised notifications through the ASOS app suggests they gained access to backend systems or customer communication channels. This highlights the importance of monitoring for unusual account activity, reviewing access controls to customer-facing systems, and ensuring incident response plans include clear communication protocols for notifying customers and regulators promptly.

Why it matters

For UK businesses handling customer data, this is a prompt to review how quickly your organisation could detect and respond to unauthorised access to customer communication channels or databases. Consider whether monitoring is in place to detect unusual activity in customer-facing systems, whether incident response plans include clear escalation paths to the ICO, and whether your organisation has tested its ability to communicate clearly and quickly with affected customers during a live incident.

Source: NCSC UK

Atlassian patches critical vulnerability affecting eight products

Atlassian has released security updates addressing a critical vulnerability, tracked as CVE-2026-XXXXX, that affects eight of its widely used collaboration and development products. SecurityWeek reports that unauthenticated attackers could exploit the flaw to access specific files in the web application root directory, potentially exposing sensitive configuration data, credentials or other information that could be used to escalate an attack. The affected products include Jira, Confluence, Bitbucket, Bamboo, Crowd, Fisheye, Crucible and other Atlassian tools commonly deployed across UK enterprises. Atlassian has published detailed remediation guidance and urges customers to apply the patches immediately.

This vulnerability is operationally significant because Atlassian products are deeply embedded in the workflows of software development teams, IT service management functions and business collaboration environments across UK organisations. Unauthenticated file access vulnerabilities are particularly concerning because they require no prior access or credentials to exploit, meaning any internet-facing instance could be at risk. If exploited, attackers could gain access to configuration files that may contain database credentials, API keys, LDAP settings or other sensitive information that could enable further compromise of internal systems. The widespread use of these tools in both on-premises and cloud-hosted environments means this is a patching priority for many organisations.

Why it matters

For UK businesses using Atlassian products, this is a prompt to identify all instances of affected software, prioritise patching for internet-facing deployments, and review whether monitoring is in place to detect unusual access attempts to web application directories. Consider whether your organisation has a clear process for tracking vendor security advisories and ensuring patches are applied within a defined timeframe, particularly for critical vulnerabilities affecting collaboration tools that may be accessible from outside your network.

Source: SecurityWeek

FBI warns FortiBleed campaign remains active threat to VPN users

The FBI and US Secret Service have issued a renewed warning that the FortiBleed campaign, first disclosed this summer, remains an active threat to organisations using Fortinet VPN appliances. CyberScoop reports that attackers are exploiting known vulnerabilities in unpatched Fortinet devices to gain initial access, then using that foothold to lock out legitimate users or deploy ransomware. The agencies warn that organisations relying on Fortinet VPNs for remote access should assume they are being actively targeted and should prioritise patching, credential rotation and monitoring for signs of compromise. The campaign has been linked to multiple ransomware incidents affecting organisations in healthcare, manufacturing and other sectors.

This warning is particularly relevant for UK organisations because Fortinet VPN appliances are widely deployed across enterprises, managed service providers and critical infrastructure sectors. The FortiBleed campaign demonstrates how attackers are systematically targeting remote access infrastructure, knowing that VPN appliances often sit at the perimeter and provide a direct route into internal networks. Once compromised, these devices can be used to harvest credentials, move laterally, disable security controls or deploy ransomware. The fact that this campaign has been active for months and continues to succeed suggests many organisations have not yet patched known vulnerabilities or implemented sufficient monitoring to detect exploitation attempts.

Why it matters

For UK businesses using Fortinet VPN appliances, this is a prompt to verify that all devices are running the latest firmware, review whether multi-factor authentication is enforced for all remote access, and ensure logging and monitoring are configured to detect unusual authentication attempts or configuration changes. Consider whether your organisation has a process for responding to vendor security advisories affecting perimeter devices and whether incident response plans include procedures for isolating compromised VPN infrastructure quickly.

Source: CyberScoop

Google releases October Android updates patching 25 vulnerabilities

Google has released its October 2026 security updates for Android, addressing 25 vulnerabilities across the operating system. SecurityWeek reports that the patches resolve a critical vulnerability in Android's System component that could lead to privilege escalation, allowing an attacker to gain elevated access to device functions or data without user interaction. The updates also address multiple high-severity flaws in the Framework, Media Framework and System components. Google has confirmed that some of these vulnerabilities may already be under limited, targeted exploitation. The updates are being rolled out to supported Android devices through the standard update process, though timing will vary depending on device manufacturer and mobile carrier.

For UK organisations managing Android devices in corporate environments, this update cycle is a reminder that mobile endpoints require the same disciplined patch management as laptops and servers. Android devices are increasingly used to access corporate email, collaboration tools, customer data and line-of-business applications, making them valuable targets for attackers seeking to compromise accounts, intercept communications or gain access to corporate networks. Privilege escalation vulnerabilities are particularly concerning because they can allow malware or malicious apps to bypass Android's security model and access sensitive data or functions. Organisations using mobile device management platforms should ensure they have visibility into which devices are running outdated software and clear policies for enforcing timely updates.

Why it matters

For UK businesses with corporate-owned or BYOD Android devices accessing company systems, this is a prompt to review whether mobile device management policies enforce timely security updates, whether monitoring is in place to identify devices running outdated software, and whether users are educated about the importance of applying updates promptly. Consider whether your organisation has clear guidance on which Android versions are supported for corporate use and what happens when devices can no longer receive security updates.

Source: SecurityWeek

Today's Key Actions

  • Review whether monitoring is in place to detect unauthorised access to customer-facing systems or communication channels, and ensure incident response plans include clear escalation paths to the ICO and tested customer notification procedures.
  • Identify all instances of Atlassian products in your environment, prioritise patching for internet-facing deployments, and review whether your organisation has a defined process for tracking and responding to vendor security advisories within a reasonable timeframe.
  • Verify that all Fortinet VPN appliances are running the latest firmware, ensure multi-factor authentication is enforced for remote access, and review logging and monitoring configurations to detect unusual authentication attempts or configuration changes.
  • Review mobile device management policies to ensure corporate Android devices are receiving timely security updates, and consider whether your organisation has clear guidance on supported Android versions and end-of-life device replacement procedures.
  • Ensure ownership of these review actions is clearly assigned across IT, security and business teams, with defined timelines for completion and escalation paths if issues are identified.

Secarma Insight

Today's stories reflect the reality that security is an ongoing discipline rather than a one-time project. Incidents like the ASOS breach remind us that even mature organisations face sophisticated threats, and the speed and clarity of response matters as much as prevention. Vulnerabilities in widely used tools like Atlassian products and Fortinet VPNs demonstrate why patch management, monitoring and access controls must be embedded into operational routines, not treated as occasional tasks. Good security comes from knowing what you have, understanding where the risks are, and having the processes in place to respond quickly when issues emerge. The organisations that manage these challenges most effectively are those that have already built the habits, assigned the ownership and tested the plans before an incident forces them to.

News and blog posts
Atlassian has released security updates addressing a critical vulnerability...
The FBI and US Secret Service have issued a renewed warning that the FortiBleed...
Google has released its October 2026 security updates for Android, addressing...
Today's brief focuses on incidents and vulnerabilities affecting systems widely...