■ NCSC UK ■ CISA KEV ■ FCA ScamSmart ■ ICO Enforcement ■ GET-IT Intelligence

Threat Advisory

Active vulnerability alerts, financial fraud warnings, and data protection enforcement notices for UK businesses — plus original analysis, commentary, and real-world case studies from GET-IT. Curated from NCSC, CISA, FCA ScamSmart, ICO intelligence feeds, and our own research.

[ LAST UPDATED: 04 August 2026 at 22:26 UTC ]
█ New — MITRE-Lite Weekly

Our plain-English translation of the MITRE ATT&CK framework — who is targeting UK businesses this week, how they operate, and what to do about it. Updated every Monday.

Business Owner Edition → Technical Edition →

Analysis, Commentary & Case Studies

Browse all GET-IT Reads →

Active UK Advisories

Why this matters to your business: The NCSC issues alerts when vulnerabilities are being actively exploited against UK organisations. If you use any of the affected products below, patching should be treated as urgent.
NCSC TUE, 04 AUG 2026

NCSC statement in response to recent incidents resulting from frontier AI evaluations

Read NCSC Advisory →
NCSC WED, 29 JUL 2026

Making forensic observability the norm for network devices

Read NCSC Advisory →
NCSC TUE, 28 JUL 2026

When cyber attacks happen: helping organisations recover

Read NCSC Advisory →
NCSC THU, 23 JUL 2026

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations

Read NCSC Advisory →
NCSC WED, 22 JUL 2026

Post-quantum cryptography (PQC) migration workshop report

Read NCSC Advisory →
NCSC WED, 15 JUL 2026

Helping small businesses with free, hands-on cyber consultancy

Read NCSC Advisory →

Known Exploited Vulnerabilities — Active in the Wild

What is the CISA KEV Catalog? The US Cybersecurity and Infrastructure Security Agency maintains a list of vulnerabilities with confirmed evidence of active exploitation globally. These are not theoretical risks — they are being used by attackers right now. Many affect common software used by UK SMEs.
CISA KEV CRITICAL 2026-08-04
CVE-2026-18556 — N-able | N-central

N-able N-central Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

View CISA Advisory →
CISA KEV CRITICAL 2026-08-04
CVE-2026-34486 — Apache | Tomcat

Apache Tomcat Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

View CISA Advisory →
CISA KEV CRITICAL 2026-08-04
CVE-2026-9198 — IBM | Langflow

IBM Langflow Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

View CISA Advisory →
CISA KEV CRITICAL 2026-08-03
CVE-2026-18577 — N-able | N-central

N-able N-central Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

View CISA Advisory →
CISA KEV CRITICAL 2026-07-29
CVE-2026-20316 — Cisco | Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center (FMC) Vulnerability

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

View CISA Advisory →
CISA KEV CRITICAL 2026-07-27
CVE-2025-68686 — Fortinet | FortiOS

Fortinet FortiOS Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

View CISA Advisory →

Financial Fraud Warnings & Action Fraud Alerts

Why this matters to your business: The FCA ScamSmart programme and Action Fraud publish warnings about unauthorised firms, clone investment scams, and financial services impersonation attacks targeting UK consumers and businesses. If your employees handle payments, invoices, or client funds, these alerts are directly relevant.
FCA ScamSmart FINANCIAL FRAUD THURSDAY, JULY 3

Trial date set for individual charged with illegal promotions

On 30 July 2026, Lucy Beck attended Southwark Crown Court for a hearing in relation to unauthorised promotions on social media. Ms Beck entered a not guilty plea and the date of her trial has been set as 12 June 2028.It...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, JULY 3

Blue Motor Finance Limited enters administration

On 30 July 2026, Blue Motor Finance Limited (BMFL) was placed into administration. Simon Edel, Richard Barker and Alan Michael Hudson of Ernst & Young LLP were appointed as joint administrators. BMFL (firm reference...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD TUESDAY, JULY 28

Strengthening resilience across an increasingly interconnected financial system

Think of the last time you made a payment, transferred money, used a banking app or logged on to online financial services. Did you give much thought to the infrastructure that makes those essential everyday transactions...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD MONDAY, JULY 27,

FCA secures majority of victims’ money back from convicted fraudster

Victims of convicted fraudster John Burford are set to recover the majority of the money they invested after the FCA obtained a confiscation order against him. In September 2025 Mr Burford, 86, was sentenced to 2 years...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, JULY 2

FCA decides to ban father and son following fraud and misuse of client money

The FCA has decided to ban a father and son from UK financial services after the High Court found that they had engaged in fraud and misused client money.

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD WEDNESDAY, JULY

Anthropic to support FCA’s Supercharged Sandbox

Anthropic will support the second group of firms in the FCA's Supercharged Sandbox. The Sandbox is a controlled environment where firms can safely experiment with advanced AI.Anthropic will provide access to Claude for...

Read FCA Warning →

ICO Enforcement Notices & Data Protection Penalties

What the ICO publishes: The Information Commissioner's Office issues enforcement notices, monetary penalty notices, and reprimands against organisations that have failed to protect personal data under UK GDPR. These cases set precedent for what the ICO expects — and what it will act on — for businesses of all sizes.
ICOENFORCEMENT

ICO Enforcement Notices & Monetary Penalties

The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.

View ICO Enforcement Register →

Is Your Business Exposed?

Many of these vulnerabilities affect software used by UK SMEs every day. A GET-IT threat intelligence scan will tell you exactly where your perimeter stands.

Book a Resilience Scan →

Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.