National Cyber Security Centre Finland

Notifications
News
Citrix NetScaler vulnerabilities exploited in Finland
The National Cyber Security Centre Finland (NCSC-FI) has issued an alert about several critical vulnerabilities in Citrix NetScaler ADC and Gateway products that are also being actively exploited in Finland. The vulnerabilities may allow attackers to execute remote code without authentication, launch denial-of-service attacks and carry out other malicious activity on affected systems. The NCSC-FI recommends that organisations update vulnerable systems immediately and check their environments for signs of exploitation.
TIETO26 exercise strengthens companies’ and public authorities’ preparedness through cooperation
The Finnish Transport and Communications Agency Traficom supports companies and public authorities in preparing for cyber incidents. The TIETO26 exercise strengthens cooperation in the event of large-scale incidents.
Cyber Weather August 2026
, updated at 17:24August’s cyber weather remained rainy, and incident numbers increased after the summer holiday season.
Vulnerabilities
Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products, several intrusions in Finland
, updated at 8:42The National Cyber Security Centre Finland (NCSC-FI) has received reports of active exploitation of critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products in Finland. Systems affected by the vulnerabilities must be updated to patched software versions without delay. Organisations must also check their environments for possible exploitation attempts and intrusions.
Microsoft 365 accounts compromised – beware of phishing
, updated at 13:50In August, the NCSC-FI received 70 reports related to Microsoft 365 account breaches. After the summer holiday season ended, the number of cases has risen significantly, and at present, organisational email accounts are being compromised at an accelerating pace. Numerous organisations have been exposed to breaches and subsequent phishing emails, and within a single organisation there may be several – even dozens – of compromised accounts. Criminals use stolen credentials to log in to Microsoft 365 services, and the hijacked accounts are then exploited to send new phishing messages and to carry out invoicing fraud.
Data breaches to Palo Alto GlobalProtect products – requires immediate action
, updated at 14:29A vulnerability (CVE-2024-3400) in a Palo Alto GlobalProtect product that is widely used in organisations is being actively exploited. The vulnerability has significant effects and requires updating and investigating the devices. Devices susceptible to the vulnerability should be suspected of being breached.

Everyday information security
Not everything online is what it seems. Learn to recognize common scams and protect your personal information.
Ulkoinen verkkopalvelu.