Threat intelligence briefing — first half of July 2026
It consolidates the seven vertical-specific products (TI-2026-0717-001 through -007) into a single distribution-ready deliverable.
SOC status:Duty analyst on shift
Founder and Head of Threat Disruption
Peter founded Hedgehog Security in 2009 — the penetration testing consultancy that became UK Cyber Defence — and leads the company from The Officers' Mess at Duxford.
Before that he was Global CISO for a FTSE 100 gaming company and for Microsoft Europe. He brings decades of SOC operations, incident response, penetration testing and security leadership experience to the work, and still spends time in the SOC and on engagements.
He writes here about running security operations that boards can understand, the practical side of regulation (FCA, DORA, NIS2, Cyber Essentials) and what actually happens during incidents.
169 articles by Peter Bassill
It consolidates the seven vertical-specific products (TI-2026-0717-001 through -007) into a single distribution-ready deliverable.
The trade body and membership organisation vertical continues to be shaped by three structural characteristics that shape the threat picture: (i) the sector holds sensitive membership registers, financial information (dues, event bookings…
The retail vertical continues to be shaped by the M&S / Co-op / Harrods retrospective — reclassified by UK observers as a "Category 2 cyber hurricane" with total combined costs assessed at £270m–£440m — and by the continued arrests connected to the DragonForce / Scattered Spider cluster.
The maritime and logistics vertical continues to be shaped by the operational lessons of the Anubis intrusion of the Adriatic Port Authority (attributed January 2026, \$10m demand, \$380m of downstream supply-chain delay)…
The legal-services vertical continues to be shaped by the NCSC Cyber Threat Report on the UK legal sector and by the accelerated cadence of intrusions against mid-market and boutique firms.
The healthcare vertical continues to be shaped by the Synnovis retrospective (7 London hospitals, June 2024, Qilin, still generating disruption two years on) and by the sustained 10x surge in IPS events across UK hospitals reported by SonicWall for Jan-May 2026 (264k events).
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets.
The R&D and defence-contractor vertical continues to be shaped by the sustained China-nexus dominance of intrusions against the defence industrial base identified by Google Cloud / Mandiant in the 2026 update, and by continued Russian and North Korean activity in the same space.
It consolidates the seven vertical-specific products (TI-2026-0717-001 through -007) into a single distribution-ready deliverable.
The trade bodies and membership organisations vertical is characterised by the combination of high personal-data density (member records, event registrations, directory data) and typically low cyber-maturity relative to commercial peers of similar size.
The retail vertical remains defined operationally by the DragonForce / Scattered Spider methodology - voice-phishing IT service desks to reset MFA, help-desk social engineering, aggressive cloud-tenant pivot, and DragonForce ransomware detonation.
The maritime and logistics vertical is in an actively-adverse threat environment this period. The Adriatic Port Authority intrusion, attributed to Anubis with a \$10m ransom demand and confirmed exfiltration of safety plans, employee records and internal communications, is the anchor event.
The legal vertical remains a high-value target for both organised criminal extortion crews and, in the top firms, state-linked espionage actors seeking privileged client material.
The healthcare vertical is in a sustained reconnaissance phase from the perspective of the attackers. SonicWall's mid-year data - 264,000 IPS events across UK hospital networks Jan-May 2026 versus 27,000 across the whole of 2025, a 10x surge - is the anchor statistic for the reporting period.
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets.
The R&D and DIB vertical continues to sit at the highest strategic threat level of any of the covered verticals, with the dominant threat being long-dwell espionage from China-nexus and DPRK-nexus actors.
Coverage this period is dominated by the CISA KEV addition of the SharePoint deserialisation defect (CVE-2026-45659) on 01 Jul with a three-day federal remediation deadline; the continued tail of CitrixBleed 3 session-token abuse against NetScaler estates…
Coverage this period is dominated by the CISA KEV addition of CVE-2026-45659, sustained credential-stuffing volumes against member portals, and the continuing baseline of BEC / invoice-redirect fraud against trade-body finance functions.
Coverage this period is dominated by the NCA arrests on 30 Jun 2026 of four UK nationals connected to the M&S / Co-op / Harrods DragonForce / Scattered Spider cluster, the CISA KEV addition of CVE-2026-45659 (SharePoint deserialisation RCE)…
Coverage this period is dominated by the SharePoint deserialisation KEV entry (CVE-2026-45659) - operationally significant given the prevalence of SharePoint document management across shipping agents, brokers…
Coverage this period is dominated by the SharePoint deserialisation KEV entry (CVE-2026-45659) - operationally significant for the legal sector given the near-ubiquity of SharePoint and iManage for matter files, trust-account documentation…
Coverage this period is dominated by the CISA KEV addition of CVE-2026-45659 (SharePoint deserialisation RCE), continued long-tail impact of the Synnovis / Qilin June 2024 attack on NHS South East London, and sustained ransomware activity by Qilin against healthcare-adjacent targets.
Coverage this period is dominated by the CISA KEV addition of the SharePoint deserialisation defect (CVE-2026-45659) on 01 Jul with a three-day federal remediation deadline; the continued tail of CitrixBleed 3 session-token abuse against NetScaler estates…
Coverage this period is dominated by the CISA KEV addition of CVE-2026-45659 - a significant risk given the prevalence of SharePoint in classified-adjacent document management - and by continuing PRC state-sponsored activity attributable to Salt Typhoon and Volt Typhoon.