Cookie Consent by Free Privacy Policy Generator

Cyber Brief: NCSC warns on China-linked targeting, ASOS breach

Today's brief brings together four developments that highlight the breadth of security challenges UK organisations are managing right now. From coordinated nation-state targeting and supply chain compromise affecting a major UK retailer, to critical infrastructure vulnerabilities requiring immediate patching and evolving compliance expectations for NHS suppliers, these stories reflect the operational reality that security risk comes from multiple directions at once. What connects them is the need for clear ownership, timely action and proportionate response across technical, governance and third-party risk management.

NCSC and international partners warn of China-linked targeting of sensitive data globally

The National Cyber Security Centre has published a joint advisory with international partners, including the FBI and agencies from Australia, Canada, Germany, Japan and New Zealand, warning that China-linked threat actors have been targeting organisations across multiple sectors globally to steal sensitive data. The NCSC reports that the activity, attributed to actors associated with Chinese cybersecurity company Integrity Technology Group, involved scanning websites for vulnerabilities and exploiting weaknesses to gain access to email systems and other sensitive information. Targets included government organisations, law enforcement agencies, healthcare systems and religious institutions, primarily in Southeast Asia. The advisory states that the threat actors operated a portal allowing third parties to access stolen data, and that the activity has been ongoing for several years.

For UK organisations, particularly those operating internationally or holding sensitive data, this advisory reinforces the persistent and coordinated nature of nation-state targeting. The fact that compromised data was made accessible through a shared platform suggests a commercialised model of cyber espionage, where stolen information may be distributed beyond the original attackers. This increases the risk that UK organisations with operations or partnerships in affected regions may find their data exposed through supply chain or partner compromise, even if they were not directly targeted. The advisory highlights the importance of understanding where sensitive data sits, who has access to it, and how third-party relationships may introduce risk.

Why it matters

For UK businesses, this is a prompt to review how email security, web application security and access controls are managed, particularly for systems that handle sensitive or commercially valuable information. Organisations should consider whether they have visibility of scanning activity against public-facing systems, whether multi-factor authentication is enforced for email and administrative access, and whether threat intelligence about targeting patterns is being used to inform defensive priorities.

Source: NCSC UK

ASOS confirms customer data breach linked to compromised employee credentials

The NCSC has confirmed that UK fashion retailer ASOS is investigating a cyber incident in which some customer personal information may have been accessed. Infosecurity Magazine reports that the breach was linked to stolen employee credentials, and that the attackers gained access through the compromise of Simon AI, an agentic marketing platform used by ASOS. The attackers reportedly alerted ASOS customers directly through a rogue push notification sent via the company's mobile app, stating they had "fully compromised" the retailer's cloud storage. ASOS has confirmed it is working with law enforcement and cybersecurity specialists to investigate the incident and assess the scope of data accessed.

This incident illustrates how supply chain compromise, particularly of third-party platforms with access to customer data or internal systems, can create direct risk to UK businesses and their customers. The fact that attackers were able to send a notification through ASOS's own app suggests they gained significant access to backend systems, likely through compromised credentials rather than a technical vulnerability in ASOS's own infrastructure. For many organisations, marketing platforms, customer engagement tools and analytics services sit outside the core IT estate but often hold privileged access to customer data, content management systems or cloud environments. When these platforms are compromised, the impact can be immediate and highly visible.

Why it matters

For UK businesses, this is a reminder to review what access third-party platforms have to customer data, internal systems and communication channels. Organisations should consider whether privileged access is appropriately scoped, whether credential hygiene and multi-factor authentication are enforced for third-party integrations, and whether monitoring is in place to detect unusual activity from trusted platforms.

Source: NCSC UK and Infosecurity Magazine

Citrix urges immediate patching of critical NetScaler vulnerability

Citrix has issued an urgent advisory calling for immediate patching of a critical vulnerability in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-107406. SecurityWeek reports that the flaw could allow remote code execution or denial of service on affected systems. Citrix has released patches and is urging organisations to apply them as a priority. NetScaler appliances are widely used across UK enterprises for application delivery, load balancing and secure remote access, making them a common target for attackers seeking initial access to corporate networks.

Critical vulnerabilities in internet-facing infrastructure such as NetScaler represent a high-priority risk because they are often exploited quickly once details become public. For organisations that rely on NetScaler for remote access or application delivery, a successful exploit could provide attackers with a foothold into internal networks, access to sensitive traffic or the ability to disrupt services. The fact that Citrix has specifically urged immediate action suggests the vendor assesses the risk of exploitation as significant. For many UK organisations, NetScaler appliances sit at the network edge and are managed by infrastructure or networking teams rather than security teams, which can sometimes mean patching cycles are slower than for other critical systems.

Why it matters

For UK businesses using Citrix NetScaler, this is a prompt to confirm whether patches have been applied, whether vulnerable systems are exposed to the internet, and whether monitoring is in place to detect exploitation attempts. Organisations should also consider whether responsibility for patching network appliances is clearly assigned and whether these systems are included in regular vulnerability management cycles.

Source: SecurityWeek

NHS DSPT compliance expectations for 2026/27 published

IT Governance UK has published guidance on the NHS Data Security and Protection Toolkit (DSPT) requirements for the 2026/27 submission period. The DSPT is the mandatory self-assessment framework that all organisations processing NHS patient data must complete annually to demonstrate they are meeting data security and protection standards. The guidance outlines updated expectations, key deadlines and areas where organisations commonly struggle to meet compliance requirements. For many UK businesses that provide services to the NHS, including IT suppliers, managed service providers, software vendors and outsourced support organisations, DSPT compliance is a contractual and regulatory requirement.

The DSPT is not a one-off exercise but an ongoing governance commitment that requires organisations to demonstrate they have appropriate policies, training, technical controls and incident response processes in place. For businesses new to NHS work or those that have struggled with previous submissions, understanding what evidence is required and where gaps exist is essential to maintaining contracts and avoiding compliance issues. The toolkit covers areas including access controls, data protection impact assessments, staff training, incident management and business continuity, many of which align with broader good practice but require specific evidence and documentation for NHS purposes.

Why it matters

For UK businesses that supply or support the NHS, this is a prompt to review whether DSPT submission plans are in place, whether evidence gathering has started, and whether the organisation has the governance, technical controls and documentation required to meet the standards. Organisations should consider whether responsibility for DSPT compliance is clearly assigned and whether internal teams understand what is expected.

Source: IT Governance UK

Today's Key Actions

  • Review whether email security, web application security and access controls are sufficient to defend against scanning and credential-based attacks, particularly for systems holding sensitive data or supporting international operations.
  • Confirm what access third-party platforms have to customer data, internal systems and communication channels, and whether credential hygiene and monitoring are in place for these integrations.
  • Check whether Citrix NetScaler systems have been patched for CVE-2026-107406, whether vulnerable appliances are exposed to the internet, and whether responsibility for patching network infrastructure is clearly assigned.
  • For organisations supplying the NHS, confirm whether DSPT submission plans are in place, whether evidence gathering has started, and whether governance and technical controls meet the required standards.
  • Ensure that ownership of vulnerability management, third-party risk, compliance obligations and incident response is clearly defined and understood across technical, governance and operational teams.

Secarma Insight

The stories in today's brief reflect the reality that security risk is rarely about a single threat or a single system. It comes from nation-state actors, supply chain compromise, unpatched infrastructure and evolving compliance expectations, often at the same time. What makes the difference is whether organisations have the habits, ownership and visibility in place to respond proportionately when these issues arise. Good security is not about reacting to every headline, but about knowing where the risk sits, who is responsible for managing it, and having the processes in place to act when it matters. That discipline is what allows organisations to stay confident and resilient, even when the threat landscape is complex and constantly shifting.

News and blog posts
The NCSC has confirmed that UK fashion retailer ASOS is investigating a cyber...
Citrix has issued an urgent advisory calling for immediate patching of a...
IT Governance UK has published guidance on the NHS Data Security and Protection...
Today's brief brings together four developments that highlight the breadth of...