■ NCSC UK ■ CISA KEV ■ FCA ScamSmart ■ ICO Enforcement ■ GET-IT Intelligence

Threat Advisory

Active vulnerability alerts, financial fraud warnings, and data protection enforcement notices for UK businesses — plus original analysis, commentary, and real-world case studies from GET-IT. Curated from NCSC, CISA, FCA ScamSmart, ICO intelligence feeds, and our own research.

[ LAST UPDATED: 11 October 2026 at 22:26 UTC ]
█ New — MITRE-Lite Weekly

Our plain-English translation of the MITRE ATT&CK framework — who is targeting UK businesses this week, how they operate, and what to do about it. Updated every Monday.

Business Owner Edition → Technical Edition →

Analysis, Commentary & Case Studies

Browse all GET-IT Reads →

Active UK Advisories

Why this matters to your business: The NCSC issues alerts when vulnerabilities are being actively exploited against UK organisations. If you use any of the affected products below, patching should be treated as urgent.
NCSC THU, 08 OCT 2026

China-linked malicious actors called out by UK and international partners for targeting sensitive data globally

Read NCSC Advisory →
NCSC TUE, 06 OCT 2026

Incident affecting ASOS customers

Read NCSC Advisory →
NCSC MON, 28 SEP 2026

Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

Read NCSC Advisory →
NCSC MON, 21 SEP 2026

One does not simply defend agentically

Read NCSC Advisory →
NCSC THU, 17 SEP 2026

Cyber Adversary Simulation (CyAS): scheme documents now available

Read NCSC Advisory →
NCSC THU, 17 SEP 2026

Adversary simulation: what you need to know

Read NCSC Advisory →

Known Exploited Vulnerabilities — Active in the Wild

What is the CISA KEV Catalog? The US Cybersecurity and Infrastructure Security Agency maintains a list of vulnerabilities with confirmed evidence of active exploitation globally. These are not theoretical risks — they are being used by attackers right now. Many affect common software used by UK SMEs.
CISA KEV CRITICAL 2026-10-08
CVE-2015-5477 — ISC | BIND

ISC BIND Vulnerability

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

View CISA Advisory →
CISA KEV CRITICAL 2026-10-08
CVE-2016-3081 — Apache | Struts

Apache Struts Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

View CISA Advisory →
CISA KEV CRITICAL 2026-10-08
CVE-2023-22894 — Strapi | Strapi

Strapi Strapi Vulnerability

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.

View CISA Advisory →
CISA KEV CRITICAL 2026-10-08
CVE-2021-3199 — ONLYOFFICE | Docs

ONLYOFFICE Docs Vulnerability

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

View CISA Advisory →
CISA KEV CRITICAL 2026-10-08
CVE-2015-3306 — ProFTPD | ProFTPD

ProFTPD ProFTPD Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

View CISA Advisory →
CISA KEV CRITICAL 2026-10-04
CVE-2026-88779 — Citrix | NetScaler

Citrix NetScaler Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.

View CISA Advisory →

Financial Fraud Warnings & Action Fraud Alerts

Why this matters to your business: The FCA ScamSmart programme and Action Fraud publish warnings about unauthorised firms, clone investment scams, and financial services impersonation attacks targeting UK consumers and businesses. If your employees handle payments, invoices, or client funds, these alerts are directly relevant.
FCA ScamSmart FINANCIAL FRAUD MONDAY, SEPTEMBE

FCA secures money back for victims of crypto fraud

Victims of a £1.5m crypto investment fraud will recover lost funds after the FCA obtained confiscation orders against Raymondip Bedi and Patrick Mavanga. At a hearing at Southwark Crown Court on 28 September 2026, Raymo...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD MONDAY, SEPTEMBE

InterestMe Financial Planning Limited (IMFP) and the appointed representative InterestMe Advisers Limited (IMA) enter administration

On 24 September 2026, IMFP and IMA entered administration. Robert Goodhew and Geoff Bouchier of Kroll Advisory Limited were appointed joint administrators for both firms. The joint administrators are responsible for man...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD WEDNESDAY, SEPTE

Firms crack down on money mules but need to do more

Financial firms are shutting down hundreds of thousands of suspected money mule accounts, but organised criminal groups are still shifting dirty money through multiple bank accounts before cashing out. An FCA survey fou...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD TUESDAY, SEPTEMB

Debt advice warning: spot the red flags

People seeking debt advice are being urged to watch out for red flags. Free debt advice is available to everyone. However, the FCA is concerned that some consumers are being steered towards fee-paying debt solutions tha...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD MONDAY, SEPTEMBE

FCA takes Hunter Jones to High Court over alleged unauthorised activity

The FCA has begun High Court proceedings against Osborne Baldwin Limited, which trades as Hunter Jones and Hunter Jones Group. The FCA alleges that Hunter Jones, which sells loan notes, carries out regulated activity wi...

Read FCA Warning →

ICO Enforcement Notices & Data Protection Penalties

What the ICO publishes: The Information Commissioner's Office issues enforcement notices, monetary penalty notices, and reprimands against organisations that have failed to protect personal data under UK GDPR. These cases set precedent for what the ICO expects — and what it will act on — for businesses of all sizes.
ICOENFORCEMENT

ICO Enforcement Notices & Monetary Penalties

The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.

View ICO Enforcement Register →

Is Your Business Exposed?

Many of these vulnerabilities affect software used by UK SMEs every day. The Cyber Resilience Review tells you where you stand and what to prioritise.

Explore the Cyber Resilience Review →

Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.