Retail threat intelligence report — 20–26 June 2026
The dominant theme this period is the continuing operational dominance of the DragonForce / Scattered Spider cluster against UK retail - its 2025 M&S…
SOC status:Duty analyst on shift
Insights
Research, detection engineering notes and plain-English explanations for the questions UK boards, IT managers and security leads actually ask. One substantial piece a week; a short threat brief in between.
Get the fortnightly briefing
The dominant theme this period is the continuing operational dominance of the DragonForce / Scattered Spider cluster against UK retail - its 2025 M&S…
The dominant theme this week is exposure of OT bridge devices following CISA's 23 June addition of CVE-2025-67038 (Lantronix EDS5000 serial-to-IP code injection) to the Known Exploited Vulnerabilities catalogue - this is operationally critical to the maritime vertical because Lantronix devices are…
The dominant collection theme this period is the convergence of edge-appliance exposure (Ubiquiti UniFi OS chain added to CISA KEV on 23 June) with sustained ransomware and pure data-extortion targeting of UK law firms which continues to attract NCSC, SRA and Law Society attention.
The dominant collection theme this period is continued aftermath reporting from the June 2026 London hospital ransomware incident, edge-appliance exposure introduced by the 23 June Ubiquiti UniFi OS KEV addition (operationally significant for hospital estates with widespread UniFi deployment)…
The collection picture this week is dominated by edge-appliance exposure - the three Ubiquiti UniFi OS defects added to the CISA Known Exploited Vulnerabilities catalogue on 23 June chain to unauthenticated root RCE under the Bishop Fox proof-of-concept and present a material risk to FS branch and…
The collection picture this period is dominated by sustained state-aligned espionage activity (Salt Typhoon, Mustang Panda, APT28 and Screening Serpens all remain active), continued infostealer activity affecting contractor supply chains…
The threat profile of this vertical is shaped by the holding of large member-data sets, the use of legacy CMS / association-management software and the convening / publishing role that makes these organisations targets for influence operations as well as conventional cyber-crime.
During the reporting period the principal observations were the continued Scattered Spider / DragonForce cluster's UK-retail targeting (anniversary of the 2025 M&S, Co-op, Harrods campaign now approaching its first cycle); the persistent Magento / Adobe Commerce skimmer wave that Sansec…
During the reporting period the principal observations were a ransomware compromise of the Adriatic Port Authority by the Anubis ransomware group, reported on 13 June and disrupting maritime logistics across the region…
During the reporting period the principal observations were the continued INC Ransom group campaign against law firms - 20 victims claimed across 2026 to date including ten claimed in a recent 48-hour burst - and the Halcyon 200+ ransomware incident dataset that places the legal sector as the…
During the reporting period the principal observations were the continuing strategic consequence of the June 2024 Synnovis / NHS London pathology compromise - South London and Maudsley NHS Foundation Trust pathology systems remained partially un-restored into early 2026…
All assessments use estimative language and confidence ratings per Section 11.
219 articles · page 4 of 19