Cookie Consent by Free Privacy Policy Generator

Cyber Brief: NCSC water sector guidance, Microsoft patches 421 flaws

Today's brief highlights the practical side of operational technology security, vulnerability management at scale, and the continuing reality of ransomware targeting critical infrastructure. The NCSC has published its first water sector guidance on secure connectivity for industrial control systems, Microsoft has released patches for over 400 vulnerabilities including one already under active exploitation, Cisco has addressed a firewall zero-day being used in denial of service attacks, and new intelligence shows the Gunra ransomware operation successfully bypassing multi-factor authentication on Fortinet devices. Together, these stories reflect the breadth of security work UK organisations are managing right now, from OT environments through to enterprise patching and perimeter defence.

NCSC publishes first water sector guidance on secure connectivity for industrial control systems

The NCSC has published new guidance specifically for the water sector, adding a worked example to its existing Secure Connectivity Principles framework. The NCSC reports that this is the first content authored by the Industrial Control System Community of Interest to appear on ncsc.gov.uk. The guidance provides practical advice on how water companies should approach secure connectivity in operational technology environments, addressing the specific challenges of industrial control systems that manage critical water infrastructure. The publication reflects the NCSC's recognition that OT security requires sector-specific context rather than generic IT security advice applied to industrial environments.

For UK water companies and other critical infrastructure operators, this guidance represents a clear signal that OT security is now a priority area for national resilience. Water sector organisations operate industrial control systems that are often decades old, run on legacy protocols, and were designed for reliability rather than security. The NCSC's decision to publish sector-specific connectivity guidance acknowledges that securing these environments requires understanding operational constraints, safety requirements, and the practical realities of systems that cannot simply be patched or replaced. This is particularly relevant given the regulatory attention on water companies and the operational impact that connectivity decisions have on both security posture and system availability.

Why it matters

For UK businesses operating industrial control systems, particularly in regulated sectors, this is a prompt to review how secure connectivity principles are being applied in OT environments. The guidance provides a practical framework for making defensible decisions about network segmentation, remote access, and monitoring in environments where traditional IT security controls may not be appropriate or safe to deploy.

Source: NCSC UK

Microsoft addresses 421 vulnerabilities in August Patch Tuesday including actively exploited zero-day

Microsoft has released its August 2026 Patch Tuesday updates, addressing 421 CVEs across Windows and supported software. SecurityWeek reports that the patches include one zero-day vulnerability, CVE-2026-68820, which is already being exploited in the wild. The vulnerability is a use-after-free flaw in the afd.sys Windows kernel-mode driver that handles network socket operations. An attacker who has already gained code execution on a system can exploit this flaw to escalate privileges to SYSTEM level. The Register notes that North Korean threat actors have already been observed attacking this vulnerability, and that the scale of this month's release continues the pattern of very large patch volumes that have become the norm for Microsoft's monthly security updates.

The operational challenge for UK IT teams is not just the presence of an actively exploited zero-day, but the sheer volume of vulnerabilities requiring assessment and prioritisation. 421 CVEs in a single month is a significant workload for any organisation, and the reality is that most IT teams cannot test and deploy every patch immediately. The actively exploited kernel driver vulnerability should be prioritised, particularly for systems that are accessible to users who may already be compromised or where privilege escalation would have significant impact. However, organisations also need to consider the two other vulnerabilities that were publicly disclosed before patches became available, as public knowledge typically accelerates exploitation timelines.

Why it matters

For many organisations, this is a reminder that patch management at this scale requires clear prioritisation frameworks and realistic expectations about what can be achieved in the first 24 to 48 hours. Focus initial efforts on the actively exploited zero-day, systems exposed to untrusted users, and any environments where privilege escalation would enable lateral movement to sensitive data or critical systems.

Source: SecurityWeek

Cisco patches firewall zero-day exploited for denial of service attacks

Cisco has released patches for a zero-day vulnerability in its Secure Firewall ASA and Firepower Threat Defense (FTD) devices that has been exploited in denial of service attacks. SecurityWeek reports that the vulnerability, tracked as CVE-2026-20349, can be exploited remotely without authentication. The flaw allows an attacker to cause the firewall to reload, resulting in a denial of service condition. Cisco has confirmed that the vulnerability is being actively exploited, though the company has not disclosed details about the scope or targeting of the attacks. The patches are available now for affected ASA and FTD software versions.

For UK organisations using Cisco firewalls at the network perimeter, this represents a direct operational risk. Firewalls that can be remotely crashed without authentication create an availability problem that attackers can exploit either for disruption or as part of a broader attack sequence. The fact that this vulnerability is already being exploited means that proof-of-concept code or exploitation techniques are likely in circulation. Organisations should assume that any internet-facing Cisco ASA or FTD device is a potential target. The remote, unauthenticated nature of the vulnerability means that traditional perimeter controls will not prevent exploitation, the patch is the primary mitigation.

Why it matters

For UK businesses relying on Cisco firewalls for perimeter security, this is a prompt to prioritise patching of internet-facing ASA and FTD devices. Where immediate patching is not possible, organisations should review monitoring for unexpected firewall reboots and ensure that firewall availability is being tracked as part of operational monitoring, as repeated exploitation could indicate targeting or reconnaissance activity.

Source: SecurityWeek

Gunra ransomware operation exploits Fortinet vulnerabilities and bypasses multi-factor authentication

Dark Reading reports that the Gunra ransomware gang, operating as a ransomware-as-a-service model, has been successfully exploiting known vulnerabilities in Fortinet firewalls and VPN appliances to gain initial access to target networks. The group is using leaked Conti ransomware code and has demonstrated the ability to bypass multi-factor authentication protections. Security researchers note that Gunra has been particularly successful against critical infrastructure targets, suggesting a focus on organisations where operational disruption creates significant pressure to pay ransoms. The attacks rely on older, publicly known vulnerabilities in Fortinet devices, indicating that many organisations have not yet applied available patches or implemented compensating controls.

The operational concern here is not the novelty of the attack techniques, but the effectiveness of well-understood methods against organisations that should have patched these vulnerabilities months or years ago. Fortinet has been a consistent target for ransomware groups because VPN and firewall appliances provide direct access to internal networks, and because many organisations treat these devices as set-and-forget infrastructure. The fact that Gunra is bypassing MFA suggests they are either exploiting session handling flaws, using stolen session tokens, or leveraging vulnerabilities that allow authentication bypass entirely. For UK organisations in critical infrastructure sectors, this is a reminder that perimeter devices require the same patch discipline and monitoring as any other critical system.

Why it matters

For UK businesses using Fortinet devices, particularly in critical infrastructure or operational technology environments, this is a prompt to review the patch status of all internet-facing VPN and firewall appliances. Organisations should also verify that MFA is correctly configured, that session timeout policies are appropriate, and that logging is enabled and monitored for authentication anomalies or unusual access patterns from VPN endpoints.

Source: Dark Reading

Today's Key Actions

  • Review the NCSC's new water sector guidance on secure connectivity for industrial control systems, even if you are not in the water sector, the principles are applicable to any organisation managing OT environments and provide a useful framework for making defensible connectivity decisions.
  • Prioritise deployment of Microsoft's August patches, focusing first on CVE-2026-68820, the actively exploited kernel driver zero-day, particularly on systems accessible to users who may already be compromised or where privilege escalation would enable lateral movement.
  • Patch internet-facing Cisco ASA and FTD devices to address CVE-2026-20349, and review monitoring for unexpected firewall reboots that could indicate exploitation attempts or reconnaissance activity.
  • Verify that all Fortinet VPN and firewall appliances are fully patched, that MFA is correctly configured, and that session handling and authentication logging are being actively monitored for anomalies.
  • Ensure that responsibility for patching perimeter devices, OT connectivity decisions, and vulnerability prioritisation is clearly assigned and that these areas are included in regular security governance reviews.

Secarma Insight

The stories today reflect the reality that security is not a single discipline but a collection of overlapping responsibilities, from OT connectivity through to enterprise patch management and perimeter defence. The organisations that manage this well are those that have already established clear ownership, realistic prioritisation frameworks, and the operational discipline to treat perimeter devices and industrial systems with the same care as core infrastructure. Good security comes from habits that are in place before incidents happen, not from reactive responses to the latest vulnerability disclosure. The NCSC's decision to publish sector-specific OT guidance is a useful reminder that mature security practice means understanding the specific operational context of the systems you are protecting, not simply applying generic controls and hoping for the best.

News and blog posts
The Gunra ransomware gang, operating as a ransomware-as-a-service model, has...
Today's brief highlights the practical side of operational technology security,...
The NCSC has published new guidance specifically for the water sector, adding a...
Microsoft has released its August 2026 Patch Tuesday updates, addressing 421...