Cookie Consent by Free Privacy Policy Generator

Cyber Brief: NCSC launches red team scheme, Cisco zero-day

Today's brief focuses on practical developments affecting how UK organisations test, defend and govern their security posture. The NCSC has launched a new assurance scheme for adversary simulation providers, Cisco has patched a second actively exploited zero-day in two days, Meta has been ordered to remove deepfake content targeting UK figures, and researchers have disclosed a critical vulnerability affecting AI coding agents widely used in software development.

NCSC launches adversary simulation assurance scheme to raise red teaming standards

The National Cyber Security Centre has published the scheme documents for its new Cyber Adversary Simulation (CyAS) assurance programme, alongside updated guidance on what organisations should expect from adversary simulation exercises. The NCSC reports that the scheme is designed to help organisations identify qualified providers capable of delivering realistic, intelligence-led testing that simulates how actual threat actors operate. The scheme sets out clear standards for red team exercises, including scoping, methodology, reporting and ethical conduct, and provides a framework for organisations to assess whether a provider's approach aligns with their risk appetite and operational context.

For UK businesses, this matters because adversary simulation, often called red teaming, is one of the most effective ways to test whether existing defences can detect and respond to realistic attack techniques. However, the quality and rigour of red team exercises varies significantly across the market. The NCSC's assurance scheme provides a benchmark that helps organisations commission exercises that deliver genuine insight rather than superficial testing. It also clarifies what good adversary simulation looks like, including how exercises should be planned, conducted and reported to support meaningful improvement in detection, response and resilience.

Why it matters

For UK businesses commissioning red team exercises, this is a prompt to review whether your current or prospective providers align with the NCSC's published standards. The scheme documents provide a clear framework for evaluating provider capability, scoping exercises appropriately and ensuring that testing delivers actionable findings that improve your organisation's ability to prevent, detect and respond to real-world threats.

Source: NCSC UK

Cisco patches second actively exploited zero-day in two days

Cisco has issued an emergency patch for a critical zero-day vulnerability in its Identity Services Engine (ISE), tracked as CVE-2026-76460, which is being actively exploited in the wild. CyberScoop reports that the flaw carries a maximum severity rating and allows an unauthenticated attacker to execute arbitrary code on affected systems. This is the second actively exploited Cisco zero-day disclosed in as many days, and the third vulnerability affecting ISE since June 2025. Cisco has confirmed exploitation activity and is urging customers to apply the patch immediately. The vulnerability affects ISE deployments used for network access control, device profiling and policy enforcement across enterprise environments.

For UK organisations, this matters because Cisco ISE is widely deployed in enterprise networks to manage authentication, authorisation and compliance for users and devices connecting to corporate infrastructure. Active exploitation of a maximum-severity vulnerability in a core identity and access control platform represents significant operational risk. Attackers with access to ISE can potentially bypass network segmentation, escalate privileges, manipulate access policies or establish persistent access to internal systems. The fact that this is the third ISE vulnerability in just over a year suggests that the platform is an attractive and recurring target for threat actors.

Why it matters

For UK businesses running Cisco ISE, this is a prompt to apply the emergency patch as a priority and review whether your ISE deployments are appropriately segmented, monitored and protected. Organisations should also consider whether ISE activity is sufficiently logged and reviewed, and whether your incident response plans account for compromise of identity and access control infrastructure.

Source: CyberScoop

Meta ordered to remove deepfake videos targeting UK councillor and Muslim campaigner

Meta's Oversight Board has ruled that the company must remove AI-generated deepfake videos of a UK Labour councillor and a young Muslim woman from Facebook, and has criticised Meta's safeguards against fake content as inadequate. The Guardian reports that one video falsely depicted a Scottish Labour councillor making inflammatory comments about refugees, while another targeted a Muslim campaigner. The Oversight Board found that Meta was wrong to leave the content online and has called on the company to strengthen its policies and enforcement mechanisms for identifying and removing AI-generated misinformation. The ruling highlights ongoing concerns about the effectiveness of platform moderation in the face of increasingly sophisticated synthetic media.

For UK organisations, this matters because deepfake technology is becoming more accessible, realistic and harder to detect. While this case involves political figures, the same techniques can be used to impersonate executives, manipulate business communications, undermine trust in video evidence or support social engineering attacks. The ruling also underscores that platform moderation remains inconsistent and reactive, meaning organisations cannot rely solely on social media companies to identify and remove malicious or misleading content targeting their staff, brands or stakeholders. This creates reputational, operational and security risks that organisations need to anticipate and prepare for.

Why it matters

For UK businesses, this is a prompt to review whether your organisation has considered the risk of deepfake impersonation targeting senior leaders, customer-facing staff or brand reputation. Organisations should ensure that staff are aware of deepfake risks, that verification processes exist for high-stakes communications, and that incident response plans account for synthetic media being used in attacks or disinformation campaigns.

Source: The Guardian

Critical vulnerability in AI coding agents could allow remote code execution

Security researchers have disclosed a critical zero-click remote code execution vulnerability affecting all major AI coding agents, including widely used tools for automated software development. The Register reports that the flaw, dubbed Plugin4Shell, allows attackers to execute arbitrary code on systems running vulnerable AI coding assistants without requiring user interaction. The vulnerability arises from how these tools process and execute code suggestions, and could allow an attacker to compromise developer workstations, access source code repositories, or pivot into broader development and production environments. Researchers say the flaw affects all major AI coding platforms and have urged vendors and users to apply patches and review their configurations.

For UK organisations, this matters because AI-powered coding assistants have been rapidly adopted across software development teams to improve productivity and automate repetitive tasks. However, these tools often operate with elevated privileges, have access to sensitive codebases and credentials, and are integrated into development pipelines and cloud environments. A zero-click RCE vulnerability in these tools represents a significant supply chain and insider risk, particularly if attackers can compromise developer environments and inject malicious code into applications before they reach production. The speed of AI tool adoption has often outpaced security review, configuration hardening and monitoring.

Why it matters

For UK businesses using AI coding agents, this is a prompt to review whether these tools are patched, appropriately configured and monitored, and whether their use is governed by clear policies covering access, permissions and code review. Organisations should also consider whether developer environments are sufficiently segmented from production systems and whether security teams have visibility into how AI tools are being used across the development lifecycle.

Source: The Register

Today's Key Actions

  • Review whether your organisation's approach to commissioning red team exercises aligns with the NCSC's published CyAS standards, and ensure that future adversary simulation work is scoped to deliver actionable insight into detection and response capability.
  • Apply Cisco's emergency patch for CVE-2026-76460 immediately if you run ISE, and review whether ISE deployments are appropriately segmented, monitored and included in incident response planning.
  • Assess whether your organisation has considered the risk of deepfake impersonation targeting executives or staff, and ensure that verification processes and awareness training account for synthetic media being used in attacks or disinformation.
  • Review whether AI coding agents used across development teams are patched, configured securely and governed by clear policies, and ensure that security teams have visibility into how these tools are used and what access they have.
  • Ensure that ownership and accountability for these areas, including red team commissioning, identity infrastructure patching, deepfake preparedness and AI tool governance, is clearly assigned and understood across the organisation.

Secarma Insight

Today's stories reflect a recurring theme in mature security practice: the importance of testing, visibility and governance across the technologies and processes that underpin organisational resilience. Whether it's commissioning adversary simulation that genuinely tests your defences, patching critical infrastructure before exploitation occurs, preparing for emerging threats like deepfakes, or governing the adoption of AI tools in development environments, good security comes from discipline, clear ownership and habits that are already in place before incidents happen. Organisations that invest in these fundamentals, and ensure that security is embedded into how decisions are made and work is done, are better positioned to respond confidently and proportionately when risks materialise.

News and blog posts
The National Cyber Security Centre has published the scheme documents for its...
Cisco has issued an emergency patch for a critical zero-day vulnerability in...
Meta's Oversight Board has ruled that the company must remove AI-generated...
Security researchers have disclosed a critical zero-click remote code execution...