Unseen exposure, phishing-resistant identity and the infrastructure attackers reach first
The NCSC has warned of increased targeting of operational technology and internet-exposed systems, including activity affecting UK organisations.
In this edition, our SOC team focus on what the warning reveals about the gap between the systems organisations document and the infrastructure attackers can actually reach.
Also: Microsoft Entra makes passkeys the default authentication method, thousands of Exchange servers remain unpatched, Google fixes an exploited Chrome zero-day, the Manchester Airport data breach and follow-on phishing risks, attackers test a critical Citrix NetScaler flaw, and an Artifactory vulnerability puts software supply chains at risk.
What the NCSC warning tells us about unseen exposure
The NCSC has warned of increased targeting of operational technology, internet-exposed systems and edge devices across multiple sectors, including in the UK. Although aimed at operational technology, the warning has wider relevance because organisations often know what they deliberately publish online, but not everything attackers can reach.
That might include a remote-access appliance installed for a project, an unowned supplier connection or a management interface left behind after a migration.
The NCSC advises organisations to maintain a definitive view of assets, communications pathways and external connections, alongside stronger controls for internet-facing infrastructure. Without that visibility, security teams cannot patch, monitor or retire exposed systems.
Organisations should compare their asset inventory with what is actually reachable from the internet. Any difference between the two may reveal unmanaged or forgotten exposure.
Entra passkeys become the default
From 1 September 2026, Microsoft began making passkeys the default authentication experience in Entra ID. Users enabled for SMS or voice authentication will be prompted to register a passkey during multifactor authentication.
Microsoft-provided SMS and voice authentication will end on 1 February 2027. Organisations that still require either method will need to use a supported provider through the Microsoft Security Store.
Passkeys resist phishing by replacing passwords and interceptable one-time codes with public-key cryptography. Organisations now need to identify users who depend on weaker methods, resolve device, recovery and exception requirements, and prepare the service desk and users for the change.
Further reading
Why valid credentials are the fastest route past your defences
Kocho Security Operations Technical Lead Adam Febery explains why credential theft is only the start of an identity breach, and why attackers who gain valid access can move through an environment looking exactly like a legitimate user.
He sets out the identity controls that limit lateral movement, shorten dwell time, and turn valid-looking activity into an early warning rather than a missed signal.
Also in the news
Thousands of Exchange servers remain exposed after a fix was released
Nearly 22,000 internet-exposed Exchange servers remained unpatched for CVE-2026-62911 at the beginning of September, despite a fix released in August and reports of working exploit code.
Confirm the versions in use, apply available updates and remove unnecessary internet exposure. Unsupported Exchange deployments need a defined replacement plan because a released patch only reduces risk when systems can receive it.
Chrome’s latest zero-day makes browser coverage the priority
Google has patched CVE-2026-85046, a high-severity vulnerability in Chrome’s V8 engine that was exploited in the wild.
Verify that the update reached every device, including unmanaged browsers and endpoints that rarely connect or no longer report into endpoint management. Coverage matters more than successful deployment across known assets.
Manchester Airports breach increases follow-on phishing risk
Manchester Airports Group has confirmed that customer contact and vehicle data was accessed, although payment details, airport operations and passenger safety were unaffected.
The data could still support convincing phishing and impersonation attempts. Affected customers should treat unexpected airport or travel-related requests for payments, banking details or credentials with caution.
Attackers are testing Citrix NetScaler authentication defences
Requests matching public proof-of-concept code have been observed for CVE-2026-19490, a critical authentication bypass affecting some Citrix NetScaler Gateway and AAA configurations. The activity shows exploitation attempts, but not confirmed compromise.
Identify exposed NetScaler systems, verify affected configurations, apply Citrix’s recommended builds and review earlier activity. Public exploit code shortens the time available to respond.
Artifactory’s privileged position makes this more than a server flaw
CVE-2026-82329 is a critical authentication weakness that can give an unauthenticated attacker administrative access to self-hosted JFrog Artifactory under its default configuration. Attackers have reportedly used it to create administrator tokens.
Patch self-hosted deployments and review privileged tokens, credentials and federation relationships. Because Artifactory feeds trusted build and delivery processes, investigate connected development systems rather than treating it as an isolated server.
This month’s priority actions
References and Resources
- NCSC: Disruptive cyber activity highlights risk from internet-exposed systems and edge devices
- Microsoft: Passkeys become the default authentication method in Entra ID
- BleepingComputer: Attackers target critical Citrix NetScaler authentication bypass
- Help Net Security: Exchange servers remain exposed to CVE-2026-62911
- Help Net Security: Google patches actively exploited Chrome zero-day
- Manchester Airports Group: Data security incident update and FAQs
- SecurityWeek: Critical JFrog Artifactory vulnerability reportedly exploited
With thanks to the Kocho Security Operations Centre (SOC) team.
Stay safe. Stay informed.
Get cyber confident
Real partnership. Microsoft expertise. Complete transparency.
Request a call back today.
- AI-powered rapid protection, from day one
- Dedicated Microsoft experts, by your side
- Powerful, intuitive reporting tools
- Collaboration and transparency as standard
Got a question? Need more information?
Our expert team is here to help.