The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and deployable private 5G

The National Cyber Security Centre (NCSC) is seeking collaborations with technology partners and industry leaders to enhance the resilience and security of private 5G networks. This initiative is part of the NCSC's broader research efforts aimed at developing advice, guidance, and future products to safeguard critical UK information and capabilities.
Private 5G is increasingly vital for organizations requiring secure, reliable, and high-performance communications. As its adoption expands, the focus is shifting beyond basic connectivity to developing networks that are resilient, secure, rapidly deployable, and capable of operating in environments where traditional infrastructure might be unavailable, degraded, or under attack.
Current private 5G deployments often rely on fixed infrastructure, conventional authentication models, and traditional security approaches, which may not offer the necessary operational and cyber resilience for future use cases. The NCSC aims to address these limitations by fostering solutions that can be deployed quickly with minimal specialized resources, maintain connectivity without conventional backhaul, provide enterprise-grade identity and access management, rapidly detect and recover from cyber incidents, support flexible and scalable deployments, and ensure operational continuity in challenging environments.
The NCSC has outlined several priority areas for collaboration. These include the development of compact, portable private 5G platforms for rapid installation in temporary, remote, or emergency settings, as well as for event connectivity and research. Such platforms should maintain enterprise-level performance, security, and manageability.
Another key area is building resilient connectivity without fixed infrastructure. The NCSC is interested in solutions leveraging wireless mesh networking and Integrated Access and Backhaul (IAB) to create flexible, self-forming, and self-healing networks. These capabilities could support rapid network expansion, coverage in challenging environments, enhanced operational resilience, diverse infrastructure options, and reduced deployment costs.
Secure, identity-based access is also a priority, particularly as private 5G integrates more closely with enterprise identity systems. The NCSC is exploring approaches such as EAP-TLS authentication, Public Key Infrastructure (PKI) integration, zero trust architectures, certificate lifecycle management, and enhanced identity assurance for private mobile networks. These could simplify security management and improve trust and control within enterprise environments.
Improving recovery and operational resilience is crucial, with the NCSC seeking solutions that support the secure backup, protection, and rapid recovery of critical private 5G services and subscriber data. The goal is to minimize downtime and quickly restore operations after system failures or cyber incidents.
Finally, the NCSC is focused on enhancing security monitoring and threat detection for private 5G, which introduces new visibility challenges across radio networks, transport layers, and core infrastructure. Areas of interest include 5G-specific intrusion detection, threat monitoring across network interfaces, detection of rogue network elements, signaling and protocol anomaly detection, security analytics and automation, integration with modern Security Information and Event Management (SIEM) and Security Operations Center (SOC) environments, and the application of machine learning for enhanced threat detection.
Organizations responding to this Expression of Interest (EOI) should note that the NCSC expects to retain ownership of any foreground intellectual property developed as part of these collaborative projects, while suppliers would typically retain ownership of their existing intellectual property.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed