New cross domain guidance for government, industry and the wider security community

2026-04-21T20:52:13Z058bb389f978c7f4113c6caf19fdbaa6560500c2405d3c4aea4cdcfbf5883fd9
APT28CSPMCYBERUKCisco Catalyst SD-WANCitrix NetScaler ADCCitrix NetScaler GatewayDNS hijackingEASMF5 BIG-IP APMMiddle East advisoryNCSCNHS resiliencecross-domain guidanceedge devicesfrontier AImessaging app targetingpro-Russia hacktivistsremote code executionroutersvulnerability management

What happened

UK NCSC feed (Jan–Apr 2026) covering a mix of strategic guidance, incident advisories and vulnerability warnings. Key items: APT28 (Russian military intelligence) exploiting vulnerable consumer/edge routers for DNS hijacking and credential/theft; unauthenticated remote code execution in F5 BIG‑IP APM and two vulnerabilities in Citrix NetScaler ADC/Gateway with immediate mitigation guidance; confirmed exploitation of Cisco Catalyst SD‑WAN and encouragement to investigate possible compromise; warnings on messaging‑app targeting and pro‑Russia hacktivist DDoS activity; an advisory for UK orgs to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
uk_ncsc_all_rss
Record identifier
058bb389f978c7f4113c6caf19fdbaa6560500c2405d3c4aea4cdcfbf5883fd9
Enrichment time
2026-04-21T20:52:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.