Jessica Entwistle
August 12 2026
Today's brief highlights the practical side of operational technology security, vulnerability management at scale, and the continuing reality of ransomware targeting critical infrastructure. The NCSC has published its first water sector guidance on secure connectivity for industrial control systems, Microsoft has released patches for over 400 vulnerabilities including one already under active exploitation, Cisco has addressed a firewall zero-day being used in denial of service attacks, and new intelligence shows the Gunra ransomware operation successfully bypassing multi-factor authentication on Fortinet devices. Together, these stories reflect the breadth of security work UK organisations are managing right now, from OT environments through to enterprise patching and perimeter defence.
The NCSC has published new guidance specifically for the water sector, adding a worked example to its existing Secure Connectivity Principles framework. The NCSC reports that this is the first content authored by the Industrial Control System Community of Interest to appear on ncsc.gov.uk. The guidance provides practical advice on how water companies should approach secure connectivity in operational technology environments, addressing the specific challenges of industrial control systems that manage critical water infrastructure. The publication reflects the NCSC's recognition that OT security requires sector-specific context rather than generic IT security advice applied to industrial environments.
For UK water companies and other critical infrastructure operators, this guidance represents a clear signal that OT security is now a priority area for national resilience. Water sector organisations operate industrial control systems that are often decades old, run on legacy protocols, and were designed for reliability rather than security. The NCSC's decision to publish sector-specific connectivity guidance acknowledges that securing these environments requires understanding operational constraints, safety requirements, and the practical realities of systems that cannot simply be patched or replaced. This is particularly relevant given the regulatory attention on water companies and the operational impact that connectivity decisions have on both security posture and system availability.
For UK businesses operating industrial control systems, particularly in regulated sectors, this is a prompt to review how secure connectivity principles are being applied in OT environments. The guidance provides a practical framework for making defensible decisions about network segmentation, remote access, and monitoring in environments where traditional IT security controls may not be appropriate or safe to deploy.
Source: NCSC UK
Microsoft has released its August 2026 Patch Tuesday updates, addressing 421 CVEs across Windows and supported software. SecurityWeek reports that the patches include one zero-day vulnerability, CVE-2026-68820, which is already being exploited in the wild. The vulnerability is a use-after-free flaw in the afd.sys Windows kernel-mode driver that handles network socket operations. An attacker who has already gained code execution on a system can exploit this flaw to escalate privileges to SYSTEM level. The Register notes that North Korean threat actors have already been observed attacking this vulnerability, and that the scale of this month's release continues the pattern of very large patch volumes that have become the norm for Microsoft's monthly security updates.
The operational challenge for UK IT teams is not just the presence of an actively exploited zero-day, but the sheer volume of vulnerabilities requiring assessment and prioritisation. 421 CVEs in a single month is a significant workload for any organisation, and the reality is that most IT teams cannot test and deploy every patch immediately. The actively exploited kernel driver vulnerability should be prioritised, particularly for systems that are accessible to users who may already be compromised or where privilege escalation would have significant impact. However, organisations also need to consider the two other vulnerabilities that were publicly disclosed before patches became available, as public knowledge typically accelerates exploitation timelines.
For many organisations, this is a reminder that patch management at this scale requires clear prioritisation frameworks and realistic expectations about what can be achieved in the first 24 to 48 hours. Focus initial efforts on the actively exploited zero-day, systems exposed to untrusted users, and any environments where privilege escalation would enable lateral movement to sensitive data or critical systems.
Source: SecurityWeek
Cisco has released patches for a zero-day vulnerability in its Secure Firewall ASA and Firepower Threat Defense (FTD) devices that has been exploited in denial of service attacks. SecurityWeek reports that the vulnerability, tracked as CVE-2026-20349, can be exploited remotely without authentication. The flaw allows an attacker to cause the firewall to reload, resulting in a denial of service condition. Cisco has confirmed that the vulnerability is being actively exploited, though the company has not disclosed details about the scope or targeting of the attacks. The patches are available now for affected ASA and FTD software versions.
For UK organisations using Cisco firewalls at the network perimeter, this represents a direct operational risk. Firewalls that can be remotely crashed without authentication create an availability problem that attackers can exploit either for disruption or as part of a broader attack sequence. The fact that this vulnerability is already being exploited means that proof-of-concept code or exploitation techniques are likely in circulation. Organisations should assume that any internet-facing Cisco ASA or FTD device is a potential target. The remote, unauthenticated nature of the vulnerability means that traditional perimeter controls will not prevent exploitation, the patch is the primary mitigation.
For UK businesses relying on Cisco firewalls for perimeter security, this is a prompt to prioritise patching of internet-facing ASA and FTD devices. Where immediate patching is not possible, organisations should review monitoring for unexpected firewall reboots and ensure that firewall availability is being tracked as part of operational monitoring, as repeated exploitation could indicate targeting or reconnaissance activity.
Source: SecurityWeek
Dark Reading reports that the Gunra ransomware gang, operating as a ransomware-as-a-service model, has been successfully exploiting known vulnerabilities in Fortinet firewalls and VPN appliances to gain initial access to target networks. The group is using leaked Conti ransomware code and has demonstrated the ability to bypass multi-factor authentication protections. Security researchers note that Gunra has been particularly successful against critical infrastructure targets, suggesting a focus on organisations where operational disruption creates significant pressure to pay ransoms. The attacks rely on older, publicly known vulnerabilities in Fortinet devices, indicating that many organisations have not yet applied available patches or implemented compensating controls.
The operational concern here is not the novelty of the attack techniques, but the effectiveness of well-understood methods against organisations that should have patched these vulnerabilities months or years ago. Fortinet has been a consistent target for ransomware groups because VPN and firewall appliances provide direct access to internal networks, and because many organisations treat these devices as set-and-forget infrastructure. The fact that Gunra is bypassing MFA suggests they are either exploiting session handling flaws, using stolen session tokens, or leveraging vulnerabilities that allow authentication bypass entirely. For UK organisations in critical infrastructure sectors, this is a reminder that perimeter devices require the same patch discipline and monitoring as any other critical system.
For UK businesses using Fortinet devices, particularly in critical infrastructure or operational technology environments, this is a prompt to review the patch status of all internet-facing VPN and firewall appliances. Organisations should also verify that MFA is correctly configured, that session timeout policies are appropriate, and that logging is enabled and monitored for authentication anomalies or unusual access patterns from VPN endpoints.
Source: Dark Reading
The stories today reflect the reality that security is not a single discipline but a collection of overlapping responsibilities, from OT connectivity through to enterprise patch management and perimeter defence. The organisations that manage this well are those that have already established clear ownership, realistic prioritisation frameworks, and the operational discipline to treat perimeter devices and industrial systems with the same care as core infrastructure. Good security comes from habits that are in place before incidents happen, not from reactive responses to the latest vulnerability disclosure. The NCSC's decision to publish sector-specific OT guidance is a useful reminder that mature security practice means understanding the specific operational context of the systems you are protecting, not simply applying generic controls and hoping for the best.