Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • UK and allies publish cyber vulnerability fixes

Security

UK and allies publish cyber vulnerability fixes

The National Cyber Security Centre (NCSC), Cybersecurity and Infrastructure Security Agency (CISA), Australian Cyber Security Centre (ACSC) and the Federal Bureau of Investigation (FBI) have published advice on countering the most publicly known — and often dated — software vulnerabilities, for private and public sector organisations worldwide.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
By Simone Flamigni / copyright Shutterstock

Last Wednesday, the NCSC, CISA, ACSC and FBI published a joint advisory highlighting 30 vulnerabilities routinely exploited by cyber actors in 2020 and those being exploited in 2021.

Advertisement
Tritax 300x250

In 2021, malicious cyber actors continued to target vulnerabilities in perimeter-type devices. Today’s advisory lists the vendors, products, and CVEs, and recommends that organisations prioritise patching those listed.

NCSC Director for Operations, Paul Chichester, said: “We are committed to working with allies to raise awareness of global cyber weaknesses – and present easily actionable solutions to mitigate them.

“The advisory published today puts the power in every organisation’s hands to fix the most common vulnerabilities, such as unpatched VPN gateway devices.

“Working with our international partners, we will continue to raise awareness of the threats posed by those that seek to cause harm."

As well as alerting organisations to the threat, this advisory directs public and private sector partners to the support and resources available to mitigate and remediate these vulnerabilities.

Guidance for organisations on how to protect themselves in cyberspace can be found on the NCSC website. Our 10 Steps to Cyber Security collection provides a summary of advice for security and technical professionals.

On the mitigation of vulnerabilities, network defenders are encouraged to familiarise themselves with guidance on establishing an effective vulnerability management process. Elsewhere, the NCSC’s Early Warning Service also provides vulnerability and open port alerts.

CISA Executive Assistant Director for Cybersecurity, Eric Goldstein, said: “Organisations that apply the best practices of cyber security, such as patching, can reduce their risk to cyber actors exploiting known vulnerabilities in their networks.

“Collaboration is a crucial part of CISA’s work and today we partnered with ACSC, NCSC and FBI to highlight cyber vulnerabilities that public and private organisations should prioritise for patching to minimise risk of being exploited by malicious actors.”

Advertisement
Security & Policing Rectangle

FBI Cyber Assistant Director, Bryan Vorndran, said: “The FBI remains committed to sharing information with public and private organisations in an effort to prevent malicious cyber actors from exploiting vulnerabilities.

“We firmly believe that coordination and collaboration with our federal and private sector partners will ensure a safer cyber environment to decrease the opportunity for these actors to succeed.”

Head of the ACSC, Abigail Bradshaw CSC, said: “This guidance will be valuable for enabling network defenders and organisations to lift collective defences against cyber threats.

“This advisory complements our advice available through cyber.gov.au and underscores the determination of the ACSC and our partner agencies to collaboratively combat malicious cyber activity.”

 

 

Advertisement
Tritax leaderboard 728x90 Tritax leaderboard 728x90
NCA helps target people smuggling supplies

Security

NCA helps target people smuggling supplies

13 November 2025

National Crime Agency (NCA) officers have led the biggest international collaboration of its kind at the Bulgarian border targeting people smuggling and the transportation of small boats equipment.

New laws set to strengthen UK

Aerospace Defence Security

New laws set to strengthen UK's cyber attack defences

12 November 2025

UK hospitals, energy and water supplies, as well as transport networks, will be better protected from the threat of cyber attacks under new laws being introduced in Parliament today.

Skyports commences BlueWater 2 drone demonstrator

Aerospace Security

Skyports commences BlueWater 2 drone demonstrator

11 November 2025

Skyports Drone Services (Skyports) has commenced operations of its UK clean maritime drone demonstrator BlueWater 2, which is designed to advance green, smart shipping in the UK, supported by Innovate UK’s CMDC 6.

Boeing to display range of defence solutions at Dubai Airshow

Defence Security Events

Boeing to display range of defence solutions at Dubai Airshow

7 November 2025

Boeing will be bringing its defence and services solutions to the Dubai Airshow later this month, with the F-15 Eagle, the CH-47 Chinook, KC-46 Pegasus, AH-64 Apache and the C-17 Globemaster on static display.

Advertisement
ODU RT
BMT and Teledyne Marine to advance maritime autonomy programmes

Defence Security

BMT and Teledyne Marine to advance maritime autonomy programmes

6 November 2025

BMT has signed a Memorandum of Understanding (MoU) with The Teledyne Marine Vehicles group which includes Iceland-based Teledyne Gavia and North Falmouth, MA based Teledyne Webb Research, laying the foundation for strategic alignment and close collaboration on future projects in the maritime autonomy space.

Blighter to debut radar solutions at Defense & Security event in Bangkok

Defence Security Events

Blighter to debut radar solutions at Defense & Security event in Bangkok

6 November 2025

Blighter will be showcasing its smart radars and AI-assisted BlighterNexus software in the UK pavilion at Defense & Security 2025 taking place at the IMPACT Exhibition & Convention Centre, Bangkok, Thailand from the 10th-13th November 2025.

Advertisement
Tritax 300x250