New cross domain guidance for government, industry and the wider security community
2026-04-21T20:52:13Z•058bb389f978c7f4113c6caf19fdbaa6560500c2405d3c4aea4cdcfbf5883fd9
APT28CSPMCYBERUKCisco Catalyst SD-WANCitrix NetScaler ADCCitrix NetScaler GatewayDNS hijackingEASMF5 BIG-IP APMMiddle East advisoryNCSCNHS resiliencecross-domain guidanceedge devicesfrontier AImessaging app targetingpro-Russia hacktivistsremote code executionroutersvulnerability management
What happened
UK NCSC feed (Jan–Apr 2026) covering a mix of strategic guidance, incident advisories and vulnerability warnings. Key items: APT28 (Russian military intelligence) exploiting vulnerable consumer/edge routers for DNS hijacking and credential/theft; unauthenticated remote code execution in F5 BIG‑IP APM and two vulnerabilities in Citrix NetScaler ADC/Gateway with immediate mitigation guidance; confirmed exploitation of Cisco Catalyst SD‑WAN and encouragement to investigate possible compromise; warnings on messaging‑app targeting and pro‑Russia hacktivist DDoS activity; an advisory for UK orgs to
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- uk_ncsc_all_rss
- Record identifier
- 058bb389f978c7f4113c6caf19fdbaa6560500c2405d3c4aea4cdcfbf5883fd9
- Enrichment time
- 2026-04-21T20:52:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.