Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • UK and allies publish cyber vulnerability fixes

Security

UK and allies publish cyber vulnerability fixes

The National Cyber Security Centre (NCSC), Cybersecurity and Infrastructure Security Agency (CISA), Australian Cyber Security Centre (ACSC) and the Federal Bureau of Investigation (FBI) have published advice on countering the most publicly known — and often dated — software vulnerabilities, for private and public sector organisations worldwide.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
By Simone Flamigni / copyright Shutterstock

Last Wednesday, the NCSC, CISA, ACSC and FBI published a joint advisory highlighting 30 vulnerabilities routinely exploited by cyber actors in 2020 and those being exploited in 2021.

Advertisement
Tritax 300x250

In 2021, malicious cyber actors continued to target vulnerabilities in perimeter-type devices. Today’s advisory lists the vendors, products, and CVEs, and recommends that organisations prioritise patching those listed.

NCSC Director for Operations, Paul Chichester, said: “We are committed to working with allies to raise awareness of global cyber weaknesses – and present easily actionable solutions to mitigate them.

“The advisory published today puts the power in every organisation’s hands to fix the most common vulnerabilities, such as unpatched VPN gateway devices.

“Working with our international partners, we will continue to raise awareness of the threats posed by those that seek to cause harm."

As well as alerting organisations to the threat, this advisory directs public and private sector partners to the support and resources available to mitigate and remediate these vulnerabilities.

Guidance for organisations on how to protect themselves in cyberspace can be found on the NCSC website. Our 10 Steps to Cyber Security collection provides a summary of advice for security and technical professionals.

On the mitigation of vulnerabilities, network defenders are encouraged to familiarise themselves with guidance on establishing an effective vulnerability management process. Elsewhere, the NCSC’s Early Warning Service also provides vulnerability and open port alerts.

CISA Executive Assistant Director for Cybersecurity, Eric Goldstein, said: “Organisations that apply the best practices of cyber security, such as patching, can reduce their risk to cyber actors exploiting known vulnerabilities in their networks.

“Collaboration is a crucial part of CISA’s work and today we partnered with ACSC, NCSC and FBI to highlight cyber vulnerabilities that public and private organisations should prioritise for patching to minimise risk of being exploited by malicious actors.”

Advertisement
ODU RT

FBI Cyber Assistant Director, Bryan Vorndran, said: “The FBI remains committed to sharing information with public and private organisations in an effort to prevent malicious cyber actors from exploiting vulnerabilities.

“We firmly believe that coordination and collaboration with our federal and private sector partners will ensure a safer cyber environment to decrease the opportunity for these actors to succeed.”

Head of the ACSC, Abigail Bradshaw CSC, said: “This guidance will be valuable for enabling network defenders and organisations to lift collective defences against cyber threats.

“This advisory complements our advice available through cyber.gov.au and underscores the determination of the ACSC and our partner agencies to collaboratively combat malicious cyber activity.”

 

 

Advertisement
Babcock LB
SIA satisfaction hits record high among employers

Security

SIA satisfaction hits record high among employers

25 November 2025

The annual independent Security Industry Authority (SIA) customer satisfaction survey saw levels of satisfaction in the SIA’s licensing process among employers rise from 89% in 2024 to 93% in 2025, which is the highest level recorded since the SIA began tracking customer satisfaction among employers in 2013.

WHIS presented with King’s Award for Enterprise

Aerospace Security Events

WHIS presented with King’s Award for Enterprise

21 November 2025

Somerset based specialist in safety-critical embedded software, WITTENSTEIN high integrity systems (WHIS), has been officially presented with the King's Award for Enterprise for International Trade in a ceremony at its Long Ashton headquarters.

Tyron Runflat appoints Dr Stuart Turner as Director

Defence Security

Tyron Runflat appoints Dr Stuart Turner as Director

21 November 2025

As it enters a new phase of growth and business expansion, Tyron Runflat is welcoming the latest addition to its team with the appointment of technically experienced Director, Dr Stuart Turner.

Britten-Norman and WMS demo remote 5G connectivity

Aerospace Security

Britten-Norman and WMS demo remote 5G connectivity

21 November 2025

Britten-Norman is working with World Mobile Stratospheric (WMS) to demonstrate a pioneering airborne 5G communication system using a BN2T-4S Islander aircraft.

Advertisement
ODU RT
Spaceflux awarded UK Government space surveillance and tracking contracts

Defence Security Space

Spaceflux awarded UK Government space surveillance and tracking contracts

20 November 2025

UK-based specialist in space domain awareness (SDA) and space intelligence, Spaceflux Ltd, has won all three major multimillion-pound, multiyear UK government contracts to provide advanced space surveillance and tracking (SST) data across multiple orbital regimes.

Smiths Detection

Aerospace Security

Smiths Detection's IONSCAN 600 achieves ECAC/EU G1 approval

20 November 2025

Smiths Detection today announced that its IONSCAN 600 explosives trace detector (ETD) has achieved ECAC/EU G1 approval, ensuring that all ECAC-approved units equipped with the new Control Parameter (CP) set are fully compliant with the latest G1 standards for passengers/cargo.

Advertisement
Tritax 300x250