Threat intelligence briefing — first half of July 2026
It consolidates the seven vertical-specific products (TI-2026-0717-001 through -007) into a single distribution-ready deliverable.
- Reference: TI-2026-07H1 (public edition)
- Coverage: all monitored sectors
- Reporting period: 1–17 July 2026
- Issued: 17 July 2026 · Lead analyst: Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This briefing is a unified cross-vertical threat intelligence product covering the seven client-facing industry verticals monitored by the UK Cyber Defence SOC. It is intended for security leadership and operational defenders across multiple sectors, and to inform prioritisation of detection and defensive investment during the reporting period 11 Jul 2026 - 17 Jul 2026. It consolidates the seven vertical-specific products (TI-2026-0717-001 through -007) into a single distribution-ready deliverable.
The reporting period was materially eventful across every monitored vertical, with four cross-cutting developments driving the picture:
SonicWall SMA1000 zero-day exploitation with a ransomware objective. CVE-2026-15409 (CVSS 10.0 SSRF) and CVE-2026-15410 (post-authentication OS command injection) were both added to CISA KEV on 14 Jul 2026. Rapid7 MDR has directly attributed the observed goal to ransomware. Exploitation began before public disclosure. Every vertical with SonicWall in the remote-access estate is exposed. Microsoft AD FS elevation-of-privilege CVE-2026-56155**.** Disclosed on 14 Jul 2026 as part of a record 622-CVE Patch Tuesday and added to the CISA KEV catalogue the same day, with active exploitation confirmed. A DKM container ACL weakness allows a low-privileged local user to gain administrator on the federation server; because AD FS bridges on-premises Active Directory to Microsoft 365 and Azure AD, compromise here yields tenant-wide identity impact. Federal remediation deadline 28 Jul 2026. 19-agency joint advisory on FSB Centre 16 and APT28 "FrostArmada". Published 13 Jul 2026. Systematic router-perimeter compromise across CNI and defence networks attributed to FSB Centre 16 (Static Tundra / Berserk Bear / Energetic Bear). Paired APT28 campaign hijacked DNS settings on approximately 18,000 MikroTik and TP-Link SOHO routers to intercept Microsoft 365 credentials and OAuth tokens. Every vertical with home-working populations connecting to M365 through consumer-grade routers is exposed. The Gentlemen ransomware brand dominance. Retained first place with 121 leak-site postings in June 2026 (Qilin 78) and ~300 postings across Q2 (Qilin 289). 90 per cent affiliate profit share is accelerating recruitment away from other brands. Qilin, DragonForce / Scattered Spider (four further UK arrests announced 10 Jul), Anubis, Interlock and Play continued to produce sector-relevant leak-site postings. The attacker rotates between first-party ROPC-capable Azure AD applications (Microsoft Azure CLI app id 04b07795-8ddb-461a-bbee-02f9e1bf7b46, Azure Active Directory PowerShell, Azure AD Connect, Microsoft Online Services, One Outlook Web, Microsoft Teams and OfficeHome), each of which represents a separate front door to the same deprecated flow. Every attempt observed to date has been refused by Entra smart lockout; zero successful sign-ins from attacker infrastructure across 30 days. The durable fix is a Conditional Access policy that blocks the ROPC / legacy-auth flow at the flow level rather than scoping to any single application id.
ISAC intelligence during the period continues to prioritise the cross-cutting developments above. Sector-specific focus:
FS-ISAC. Sustained probing of AD FS, NetScaler Gateway, SonicWall SMA workplace and Entra ID sign-in endpoints across peer FS estates.
MTS-ISAC. Anubis affiliate tradecraft after the Adriatic Port Authority precedent.
H-ISAC. Pathology, radiology and pharmacy-management system targeting.
RH-ISAC. Scattered Spider / DragonForce service-desk social engineering.
Space ISAC. Satellite-ground-segment and defence-supply-chain adversary interest.
For verticals without a dedicated ISAC (legal, trade bodies), analyst weight sits on the NCSC sector threat report and equivalent government advisories.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that Microsoft AD FS CVE-2026-56155 will drive credential-federation intrusion attempts against UK and EU client estates across every monitored vertical over the next two reporting cycles, given the same-day CISA KEV listing on 14 Jul 2026, the confirmed active exploitation, and the outsized value of federation-server compromise as a route into cloud-tenant control (HIGH confidence).
- It is highly likely that SonicWall SMA1000 CVE-2026-15409 and CVE-2026-15410, chained, will drive ransomware initial-access intrusions against UK and EU targets across financial services, retail, healthcare and defence contractor estates during the next two reporting cycles; Rapid7 MDR has confirmed the attacker objective is ransomware and the exploitation curve began before public disclosure (HIGH confidence).
- It is highly likely that The Gentlemen, Qilin and DragonForce / Scattered Spider will continue to drive the majority of materially-disruptive ransomware incidents across the monitored verticals during the next two reporting cycles; The Gentlemen's 90 per cent affiliate profit share is materially accelerating recruitment away from other brands (HIGH confidence).
- It is highly likely that FSB Centre 16 (Static Tundra) router-perimeter compromise will be found to have affected at least one UK or EU CNI, defence-adjacent or professional-services target by the end of Q3 2026, given the 13 Jul 2026 advisory and the historical scope of Berserk Bear targeting (HIGH confidence).
- It is likely that the APT28 "FrostArmada" SOHO-router DNS-hijack campaign will surface additional Microsoft 365 credential-compromise cases across home-working populations in every monitored vertical during the next reporting cycle (MEDIUM-HIGH confidence).
- It is a realistic possibility that the Entra ID password-spray campaign will be publicly attributed to a named initial-access broker within the next two reporting cycles, given the strength of the AS200373 DREI-K-TECH-GMBH single-AS pivot (MEDIUM confidence).
2. Sector threat landscape
The cross-vertical threat picture for this reporting period is shaped by four cross-cutting developments, each of which affects multiple monitored verticals simultaneously.
(1) SonicWall SMA1000 zero-day exploitation. CVE-2026-15409 (CVSS 10.0 SSRF) and CVE-2026-15410 (post-auth code injection) were added to CISA KEV on 14 Jul 2026. Rapid7 MDR has attributed the observed goal to ransomware. Exploitation began before public disclosure.
(2) Microsoft AD FS CVE-2026-56155. Elevation-of-privilege on federation servers via a DKM container ACL weakness. Same-day CISA KEV listing on 14 Jul 2026, active exploitation confirmed. Federal remediation deadline 28 Jul 2026.
(3) FSB Centre 16 and APT28 "FrostArmada" advisory. 19-agency joint advisory of 13 Jul 2026. Systematic router-perimeter compromise attributed to FSB Centre 16 (Static Tundra); paired APT28 campaign hijacking DNS on approximately 18,000 SOHO routers to steal Microsoft 365 credentials and OAuth tokens.
(4) The Gentlemen ransomware brand dominance**.** First place among ransomware brands in June 2026 (121 leak-site postings; Qilin 78) at a 90 per cent affiliate profit share. Qilin, DragonForce, Anubis, Interlock and Play continued their leak-site cadence into this reporting period.
(5) Cross-client deprecated-Azure-legacy-auth spray campaign. Attribution is via shared attacker infrastructure across /16 blocks between tenants and rotation across all ROPC-capable first-party Azure AD applications. Smart lockout is holding on every attempt observed to date. The durable fix is a Conditional Access policy that blocks the ROPC / legacy-auth flow, not one that names any specific application id. This campaign is treated as a cross-vertical concern rather than a single-client incident because every client running Microsoft 365 with Entra ID sign-in is directly exposed to the same attack surface.
Per-vertical summary:
Financial Services / Banking / Fintech / Insurance. Dominated by AD FS CVE-2026-56155, SonicWall SMA1000 zero-days, the FSB Centre 16 / APT28 router advisory and continued Gentlemen / Qilin / DragonForce ransomware cadence. FS-ISAC AI Cybersecurity Hardening advisory rolled forward for deepfake KYC bypass. Maritime & Logistics. Anubis affiliate tradecraft continues to be the sector reference case (Adriatic Port Authority precedent). SonicWall SMA1000 exposure especially relevant for port and terminal remote-access estates. MTS-ISAC exchange prioritises OT-adjacent probing. Legal / Solicitors / Barristers / Legal Services. Play, INC Ransom, The Gentlemen and Qilin continue to treat mid-market and boutique firms as "low-hanging fruit". Pure data-extortion (Luna Moth-model) growing 11x year-on-year per Arctic Wolf. ICO enforcement risk elevated. Retail. DragonForce / Scattered Spider service-desk social-engineering methodology remains active despite the 10 Jul NCA arrests; The Gentlemen and Qilin producing UK / EU retail victims at cadence. M&S / Co-op / Harrods retrospective classed as Category 2 cyber hurricane (£270m–£440m combined). Healthcare. Synnovis retrospective continues to shape sector reference. SonicWall SMA1000 heavily represented in NHS remote-access estate. Qilin, The Gentlemen and Interlock cadence against pathology, radiology and pharmacy-management systems. Research & Development / Military / Government Contractors. China-nexus (UNC3886, UNC5221) remains the highest-volume threat per Google Cloud DIB update. FSB Centre 16 router campaign and APT28 FrostArmada campaign have direct DIB relevance. DPRK Kimsuky and BlueNoroff social-engineering against technical staff continues. Trade Bodies & Membership Organisations. Under-resourced membership organisations are opportunistic targets for The Gentlemen, Qilin, DragonForce and Interlock. Politically-salient membership registers attract state-nexus interest. Pure data-extortion pattern from the legal sector transfers directly.
the Entra ID password-spray campaign – seen across all verticals
The attacker rotated IPs on every attempt across nine documented families and diversified to five Microsoft app vectors (Azure CLI, AAD PowerShell, One Outlook Web, Microsoft Teams, OfficeHome). Smart lockout held on every burst; zero successes attributed.
IP Insights enrichment established a single-AS pivot on the campaign: every documented IPv4 family (45.3.x, 209.50.x, 65.111.x, 104.207.x, 216.26.x, 151.123.x, 104.167.x) resolves to AS200373 DREI-K-TECH-GMBH (3xK Tech GmbH), a German ASN operating IPs geolocated across Brazil, Great Britain, the United States and Spain. The ASN is the pivot, not the per-IP geolocation.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
The Gentlemen
- Aliases: The Gentlemen (single-name RaaS brand); Qilin-affiliate lineage per Halcyon
- Suspected Origin: Unattributed (Russian-speaking assessed)
- Suspected Sponsor: Organised criminal RaaS
- Primary Motivation: Financial (double extortion)
- Sector Targeting: Broad mid-market; disproportionately professional services, legal, healthcare, manufacturing, retail, trade bodies
- Geographic Focus: Global; western Europe and North America dominant in June-July 2026 tally; Germany over-represented
- Signature TTPs: Initial access via brokered credentials and public-facing exploitation (SharePoint CVE-2026-45659 chains this period), LOTL tooling, aggressive leak-site publication cadence, PowerShell + custom Rust payload
- Tooling / Malware Families: The Gentlemen ransomware (Rust), Rclone, PsExec, Cobalt Strike
- Recent Activity: 121 leak-site postings in Jun 2026 (revised up from initial 115) - first month above Qilin in over a year; 300 postings across Q2 2026 (Qilin 289); 90% affiliate profit share; sustained cadence into 11-17 Jul 2026
- Assessed Threat to Vertical: HIGH - fastest-growing RaaS brand
- Analytic Confidence: HIGH
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B, Water Galura
- Suspected Origin: Russian-speaking (unattributed)
- Suspected Sponsor: Organised criminal RaaS
- Primary Motivation: Financial (double extortion)
- Sector Targeting: Financial services, healthcare, manufacturing, retail, professional services, legal, logistics
- Geographic Focus: Global; UK and EU disproportionately represented in H1 2026 leak-site postings; Germany over-represented
- Signature TTPs: Initial access via brokered credentials, Check Point VPN CVE-2026-50751 exploitation, RMM abuse (AnyDesk, SplashTop), PowerShell + Rust ransomware payload; ESXi Linux variant
- Tooling / Malware Families: Qilin.B ransomware (Rust), Cobalt Strike, Rclone-to-Mega, Mimikatz, SharpHound
- Recent Activity: 1,496 leak-site victims across trailing 12 months (dominant RaaS by lifetime volume); 78 postings in June 2026 (overtaken by The Gentlemen); 289 postings across Q2 2026; Max Fordham (UK, 06 Jul 2026) leak-site claim
- Assessed Threat to Vertical: HIGH - dominant RaaS operator across UK/EU by lifetime volume
- Analytic Confidence: HIGH
DragonForce / Scattered Spider cluster
- Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
- Suspected Origin: Anglophone (UK/US); further four arrests 10 Jul 2026 per NCA
- Suspected Sponsor: Organised criminal alliance / RaaS
- Primary Motivation: Financial (ransomware + data extortion)
- Sector Targeting: Retail, hospitality, telecoms, technology, real estate, manufacturing, construction, financial services (payments)
- Geographic Focus: Anglophone western targets
- Signature TTPs: Voice-phishing IT service desk to reset MFA, help-desk social engineering, EDR bypass via legitimate RMM tooling, DragonForce Linux/ESXi ransomware, aggressive cloud-tenant pivot
- Tooling / Malware Families: DragonForce ransomware, Ngrok, AnyDesk, SplashTop, Impacket, Chisel
- Recent Activity: Continued leak-site postings (Real Estate, Manufacturing, Construction focus); further NCA arrests 10 Jul 2026 connected to M&S/Co-op/Harrods case; alliance-affiliate operations continue
- Assessed Threat to Vertical: HIGH - social-engineering methodology transfers directly across verticals
- Analytic Confidence: HIGH
FSB Centre 16 (Static Tundra / Berserk Bear)
- Aliases: Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra
- Suspected Origin: Russian Federation (FSB Centre 16)
- Suspected Sponsor: Nation state (Russian FSB)
- Primary Motivation: Espionage; strategic access; disruption-adjacent given target choice
- Sector Targeting: Energy, communications, defence industrial base, healthcare, financial services, government, critical national infrastructure globally
- Geographic Focus: Global; UK, US, EU and allied CNI
- Signature TTPs: Systematic router-perimeter compromise (Cisco IOS legacy CSRF resurfaced 13 Jul 2026), SNMP abuse, credential harvesting via man-in-the-middle, edge-appliance persistence
- Tooling / Malware Families: Custom implants on Cisco IOS, MikroTik, TP-Link; SNMP misuse; DNS hijacking
- Recent Activity: 19-agency joint advisory of 13 Jul 2026 attributing systematic router-perimeter compromise across CNI and defence-sector networks; paired APT28 "FrostArmada" DNS-hijack campaign against ~18,000 SOHO routers stealing M365 credentials and OAuth tokens
- Assessed Threat to Vertical: HIGH for CNI, defence, government; MEDIUM-HIGH elsewhere
- Analytic Confidence: HIGH
Anubis
- Aliases: Anubis ransomware / affiliate programme
- Suspected Origin: Unattributed
- Suspected Sponsor: Organised criminal RaaS
- Primary Motivation: Financial (double extortion; disruption-adjacent given target choice)
- Sector Targeting: Maritime, ports, logistics, 3PL, transportation, healthcare
- Geographic Focus: Global
- Signature TTPs: Spear-phishing initial access; lateral movement via unpatched systems (particularly OT-adjacent); privilege escalation; encryption of cargo-tracking / customs-processing / clinical-support systems; VPN credential abuse; RMM tooling for persistence
- Tooling / Malware Families: Anubis ransomware toolkit (RaaS), stolen VPN credentials, exploitation of CitrixBleed 2 (CVE-2025-5777) and adjacent VPN CVEs
- Recent Activity: Adriatic Port Authority (Port of Ancona, Italy) intrusion (Dec 2025, attributed Jan 2026, $10m demand, $380m supply-chain delay). Continued tradecraft into 2026 flagged in MTS-ISAC exchange; NCSC continues to investigate UK-terminated intrusions
- Assessed Threat to Vertical: HIGH - specific maritime and healthcare sector fit
- Analytic Confidence: HIGH
UNC3886 (China-nexus)
- Aliases: UNC3886 (Mandiant/Google Cloud)
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation state (China-nexus)
- Primary Motivation: Espionage; strategic access to defence and technology sectors
- Sector Targeting: Defence industrial base, technology, telecommunications, virtualisation platforms, government
- Geographic Focus: Global; US, UK, EU and allied defence sectors
- Signature TTPs: Zero-day exploitation of virtualisation platforms (VMware ESXi / vCenter), Fortinet FortiOS and adjacent edge devices; persistence via appliance-native mechanisms; discreet lateral movement
- Tooling / Malware Families: Custom implants targeting VMware and network appliance firmware; LOTL tooling
- Recent Activity: Continued edge-device-focused activity per Google Cloud 2026 Defense Industrial Base update; representative of the dominant China-nexus tradecraft against the DIB
- Assessed Threat to Vertical: HIGH for defence industrial base, technology and telecoms
- Analytic Confidence: HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | This week the principal exploited public-facing systems observed by ISAC and government feeds are Microsoft SharePoint on-premises (CVE-2026-45659, rolling forward with Storm-2603 / Warlock ransomware use), SonicWall SMA1000 (CVE-2026-15409/-15410 zero-days, active from late June), AD FS (CVE-2026-56155 disclosed and added to KEV on 14 Jul), and three Joomla-family upload flaws added to CISA KEV in the trailing two weeks. All exploited within days of disclosure. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud Accounts | FSB Centre 16 / APT28 "FrostArmada" activity (13 Jul 2026 joint advisory) hijacked DNS on approximately 18,000 SOHO routers to intercept Microsoft 365 credential and OAuth token flows. Concurrently, sustained password-spray and smart-lockout activity against Entra ID sign-in endpoints across the tenants we monitor rotating through five Microsoft app vectors (Azure CLI, AAD PowerShell, One Outlook Web, Teams, OfficeHome). | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud Accounts (ROPC / deprecated legacy-auth flow) | Directly observed, assessed on shared infrastructure and shared methodology as the same actor. The attacker uses the Resource Owner Password Credentials OAuth2 flow — a Microsoft-deprecated mechanism that bypasses interactive MFA — through first-party Azure AD applications (Microsoft Azure CLI 04b07795-8ddb-461a-bbee-02f9e1bf7b46, Azure Active Directory PowerShell, Azure AD Connect, Microsoft Online Services, One Outlook Web, Microsoft Teams, OfficeHome). Every documented spray IPv4 family (45.3.x, 209.50.x, 65.111.x, 104.207.x, 216.26.x, 151.123.x, 104.167.x) resolves to AS200373 DREI-K-TECH-GMBH; two IPv6 families (OVH 2607:5300:203::/48 and 2a06:b440::/32) added in the last week. Entra smart lockout holding on every observed attempt; zero attacker-IP successful sign-ins over 30 days. | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | IcedID, Latrodectus and DarkGate loader chains via ISO/IMG/OneNote continued to dominate the phishing tail; volume steady week-on-week per Proofpoint and Sophos public telemetry. Anubis affiliate spear-phish tradecraft (documented in the Adriatic Port Authority intrusion earlier this year) remains active and directly relevant to any organisation with limited external-mail sandboxing. | HIGH |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | CVE-2026-56155 (AD FS DKM container ACL weakness) provides a low-privileged local user with a route to full administrator on the federation server. Because AD FS bridges on-premises AD to Microsoft 365 / Azure AD, exploitation here confers identity-federation-level control on the joined tenant. | HIGH |
| Discovery | T1046 | Network Service Discovery | Automated port sweeps from datacentre-hosted infrastructure; IP Insights flagged multiple AS209605 (HOSTBALTIC), dmzhost and Tor-exit sources in the perimeter tail this period. | MEDIUM |
| Command and Control | T1071.001 | Application Layer Protocol: Web | Cobalt Strike, Sliver and Havoc HTTPS C2 beaconing observed in incident retrospectives via ISAC channels this period; JARM / JA3 fingerprint hunts remain the primary detection. | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone-to-Mega and rclone-to-Backblaze exfiltration patterns dominant in Qilin, Akira, DragonForce and The Gentlemen double-extortion intrusions this period. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Qilin, Akira, DragonForce, The Gentlemen and Interlock ransomware deployment observed against sector-adjacent peers per ransomware.live and ISAC reporting. Warlock (Storm-2603) reported this period on SharePoint CVE-2026-45659 chains. | HIGH |
| Initial Access | T1584.005 | Compromise Infrastructure: Botnet | APT28 "FrostArmada" campaign (per 13 Jul 2026 advisory) hijacked DNS settings on approximately 18,000 SOHO routers to intercept Microsoft 365 credential and OAuth token flows — an intermediate step between infrastructure compromise and cloud-account theft that is directly relevant to home-working populations across every monitored vertical. | HIGH |
| Initial Access | T1195.002 | Supply Chain Compromise: Software Supply Chain | UNC3886-style targeting of virtualisation platforms and network appliance software remains the dominant China-nexus initial-access pattern against the defence industrial base per Google Cloud 2026 update; continued relevance to any client running VMware, Fortinet, Ivanti, Cisco or Palo Alto edge devices. | HIGH |
| Initial Access | T1566.004 | Spearphishing Voice | Voice-phishing IT service desks to reset MFA on privileged accounts is the operational hallmark of the DragonForce / Scattered Spider cluster and continues to spread through the affiliate ecosystem. Recommended service-desk countermeasure remains: caller-callback verification against HR-of-record contact detail, and prohibition of MFA reset on the same call as the request. | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 14 Jul 2026 | Multiple SonicWall SMA1000 customers (global) | Unattributed / assessed ransomware precursor | SonicWall SMA1000 CVE-2026-15409/-15410 zero-days confirmed exploited from late June; Rapid7 MDR reports the observed goal is ransomware. Federal BOD 26-04 remediation deadline set to 17 Jul 2026. Sector relevance: every vertical with SonicWall in remote access. | Rapid7 / SonicWall / CISA KEV |
| 14 Jul 2026 | AD FS-federated Microsoft 365 tenants (global) | Unattributed | CVE-2026-56155 AD FS elevation-of-privilege added to CISA KEV on the day of disclosure with active exploitation confirmed. DKM container ACL weakness allows a low-privileged local user to gain administrator and therefore identity-federation control over the joined M365 / Azure AD tenant. Federal remediation deadline 28 Jul 2026. | Microsoft / CISA KEV / KB5121391 |
| 13 Jul 2026 | Critical national infrastructure and defence networks (multiple jurisdictions) | FSB Centre 16 / Static Tundra (also APT28 "FrostArmada") | 19-agency joint advisory. Systematic compromise of Cisco, MikroTik and TP-Link routers at the perimeter of CNI and defence networks; separate APT28 "FrostArmada" campaign against ~18,000 SOHO routers hijacking DNS to steal Microsoft 365 credentials and OAuth tokens. | NCSC / CISA / 19-agency joint advisory |
| 11 Jul 2026 | The Gentlemen ransomware brand | The Gentlemen | The Gentlemen retained first place with 121 leak-site postings in June 2026 (vs Qilin 78) and roughly 300 postings across Q2 (Qilin 289). Sustained UK / EU mid-market victim cadence into the reporting period at a 90% affiliate profit share. | Halcyon / SOCRadar / ransomware.live |
| 10 Jul 2026 | M&S / Co-op / Harrods long-tail (retrospective) | DragonForce / Scattered Spider cluster | NCA announced four further arrests of UK nationals connected to the cluster. Retrospective total impact: M&S ~£300m, Co-op ~£206m; combined £270m-£440m; classed as a Category 2 cyber hurricane. Retail sector-relevant. | NCA / Cybersecurity Dive / Computer Weekly |
| 06 Jul 2026 | Max Fordham - UK architecture, engineering and design firm | Qilin | Qilin leak-site claim (professional services / R&D-adjacent). Illustrative of continued mid-market UK targeting cadence into July. | DeXpose / ransomware.live |
| Retrospective | Adriatic Port Authority (Port of Ancona) | Anubis | Retro reference. Continues as the reference case for port-authority tradecraft in MTS-ISAC exchange; $10m demand, $380m supply-chain delay. | Resecurity / Industrial Cyber / MTS-ISAC |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Product | CVSS | KEV | Exploited | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-15410 | SonicWall SMA1000 Appliance Management Console | 7.2 | Yes | Yes | Applied by the same 12.4.3-02962 patch; observed chained with CVE-2026-15409 to gain unauthenticated code execution. Restrict management console to management VLAN and enable MFA on admin logins. Added to CISA KEV 14 Jul 2026. |
| CVE-2026-45659 | Microsoft SharePoint Server SubEd / 2019 / 2016 - deserialisation RCE (Site Member+ authenticated) | 8.8 | Yes | Yes | Rolling forward from prior weeks. Microsoft May 2026 patch. Storm-2603 / Warlock ransomware operators observed exploiting during this period. Audit Site Member permissions; hunt w3wp.exe child processes (cmd.exe, powershell.exe, rundll32.exe) under the SharePoint application pool; restrict /_layouts/15 uploader paths at the WAF. |
| CVE-2026-48939 | Joomla iCagenda extension - unrestricted upload of file with dangerous type | 9.8 | Yes | Yes | Update iCagenda immediately; audit uploads directories for webshells; added to CISA KEV 10 Jul 2026. |
| CVE-2026-56291 | Joomla Balbooa Forms extension - unrestricted upload of file with dangerous type | 9.8 | Yes | Yes | Update Balbooa Forms immediately; audit uploads directories; added to CISA KEV 10 Jul 2026. Third Joomla-family upload flaw added to KEV in the trailing two weeks. |
| CVE-2026-48908 | JoomShaper SP Page Builder (Joomla) - unrestricted file upload of dangerous type | 9.8 | Yes | Yes | Rolling forward from prior week. Update SP Page Builder; audit uploads directories for webshells. Added to CISA KEV 07 Jul 2026. |
| CVE-2026-56290 | Joomlack Page Builder (Joomla) - improper access control on administration endpoints | 9.1 | Yes | Yes | Rolling forward from prior week. Update the extension; restrict administrator paths at the WAF. Added to CISA KEV 07 Jul 2026. |
| CVE-2026-55255 | Langflow - authorisation bypass through user-controlled key | 9.1 | Yes | Yes | Rolling forward from prior week. Restrict LLM-tooling admin interfaces to internal networks. Added to CISA KEV 07 Jul 2026. |
| CVE-2026-8451 | Citrix NetScaler ADC / Gateway - memory overread (CitrixBleed 3 follow-on) | 9.3 | Yes | Yes | Rolling forward. Apply fixed builds 14.1-66.59 / 13.1-62.23 / 13.1-37.262 FIPS/NDcPP; MUST run "kill icaconnection -all", "kill pcoipConnection -all", "kill aaa session -all" post-patch to invalidate stolen sessions. Exploited within 24h of 30 Jun 2026 disclosure. |
| CVE-2026-50751 | Check Point Security Gateway - improper authentication (Qilin-affiliate exploitation) | 9.8 | Yes | Yes | Rolling forward. Apply Check Point R81.20 / R81.10 / R80.40 hotfixes; hunt admin sessions from non-management source addresses; Qilin affiliates observed leveraging as initial-access vector. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 45[.]3[.]40[.]47 | 11 Jul 2026 | HIGH | AS200373 DREI-K-TECH-GMBH (3xK Tech GmbH), IP Insights geoloc Brazil / São Paulo. Documented spray family 45.3.x - 164 events/7d against estate. Lockout held on every burst. |
| IP | 209[.]50[.]181[.]167 | 11 Jul 2026 | HIGH | AS200373 DREI-K-TECH-GMBH, IP Insights geoloc City of London (GB). Documented spray family 209.50.x - 182 events/7d against estate. |
| IP | 104[.]207[.]40[.]240 | 11 Jul 2026 | HIGH | AS200373 DREI-K-TECH-GMBH, IP Insights geoloc Ashburn (US). Documented spray family 104.207.x - 152 events/7d. |
| IP | 216[.]26[.]247[.]80 | 11 Jul 2026 | HIGH | AS200373 DREI-K-TECH-GMBH, IP Insights geoloc Madrid (ES). Documented spray family 216.26.x - 174 events/7d. |
| IP | 104[.]167[.]25[.]95 | 12 Jul 2026 | HIGH | AS200373 DREI-K-TECH-GMBH, IP Insights geoloc Ashburn (US). Documented spray family 104.167.x - 10 events/7d, all lockouts. |
| IPv6 prefix | 2a06:b440::/32 | 16 Jul 2026 | HIGH | Ninth documented family in the Entra ID password-spray campaign, first IPv6-only family; 40 events/7d against 9 named targets; observed across Microsoft Azure CLI, Azure Active Directory PowerShell, One Outlook Web and Microsoft Teams applications. |
| IP | 185[.]220[.]100[.]240 | 11 Jul 2026 | HIGH | F3 Netze e.V. AS205100 Tor exit (DE, tor-exit-13.zbau.f3netze.de). IP Insights threat score 100/critical, 7 active blacklists (IPInsights Honeypot, AbuseIPDB, ipsum, Dan.me.uk, Checkpoint TOR, malicious-ip); sustained perimeter tail against multiple estates during the reporting period. |
| IP | 45[.]148[.]10[.]240 | 12 Jul 2026 | HIGH | dmzhost bulletproof (NL). IP Insights threat score 100/critical, 5 blacklists including IPInsights Honeypot capture categorised "SSH/Telnet Brute Force"; SSH / RDWeb brute-force tail against monitored estates. |
| App list | Azure Active Directory PowerShell; Azure AD Connect; Microsoft Online Services; One Outlook Web; Microsoft Teams; OfficeHome | 11-17 Jul 2026 | HIGH | Seven ROPC-capable first-party Azure AD applications observed as attack surface for the cross-client campaign. Attacker adds new apps over time (OfficeHome added 17 Jul 2026). Assume any first-party ROPC-capable application is in scope for this actor. Block the flow, not the app. |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via SonicWall SMA1000 CVE-2026-15409/-15410 chain (all verticals with SonicWall in remote access) | H | H | CRITICAL |
| AD FS CVE-2026-56155 exploitation leading to federation-server compromise and M365 tenant control (any AD FS-federated tenant) | M | H | HIGH |
| FSB Centre 16 router-perimeter compromise (CNI, defence, and healthcare; membership registers of political salience) | M | H | HIGH |
| APT28 "FrostArmada" SOHO-router DNS hijack against remote-working populations | H | H | CRITICAL |
| The Gentlemen / Qilin ransomware via brokered credentials or SharePoint CVE-2026-45659 chain | H | H | CRITICAL |
| DragonForce / Scattered Spider service-desk social-engineering leading to MFA reset and privileged compromise | H | H | CRITICAL |
| Business email compromise / vendor payment redirect against finance function (all verticals) | H | H | CRITICAL |
| Anubis affiliate targeting of maritime / port / 3PL / healthcare cargo-tracking, customs and clinical-support systems | M | H | HIGH |
| Pure data-extortion (Luna Moth-model) against legal case files or trade-body member registers | H | H | CRITICAL |
| DPRK BlueNoroff / Kimsuky social-engineering of technical staff at fintech, crypto-adjacent and defence-contractor targets | M | H | HIGH |
9. Forward Outlook
Looking forward to the next reporting period (18 Jul - 24 Jul 2026), it is highly likely that at least one UK or EU public disclosure will attribute a breach to SonicWall SMA1000 CVE-2026-15409/-15410. It is likely that AD FS CVE-2026-56155 exploitation will feature in at least one public attribution to a nation-state or ransomware actor before the 28 Jul federal remediation deadline. It is likely that The Gentlemen, Qilin, DragonForce and Interlock will maintain their leak-site cadence with mid-market UK and EU victims across financial services, legal, healthcare, retail and professional services. It is a realistic possibility that a UK CNI or defence-adjacent target will be publicly linked to FSB Centre 16 activity or the FrostArmada campaign within the next two reporting cycles. It is a realistic possibility that public attribution will emerge linking the Entra ID password-spray campaign to a named initial-access broker given the strength of the AS200373 pivot.
Trigger conditions that would prompt revision of this outlook include:
- a UK or EU organisation across any monitored vertical publicly attributing a breach to CVE-2026-15409/-15410, CVE-2026-56155, CVE-2026-45659 or CVE-2026-50751, which would warrant immediate out-of-cycle reporting;
- emergence of an unauthenticated variant of the AD FS chain;
- further CISA KEV additions materially affecting core infrastructure (particularly SonicWall, Check Point, Ivanti, Fortinet, Citrix or Microsoft);
- a successful smart-lockout defeat on the campaign — the campaign's zero-success record to date is a load-bearing analytic assumption;
- any public sector victim named in an FSB Centre 16 / APT28 attribution;
- service-desk social-engineering methodology change post-arrest in the M&S / Co-op / Harrods case;
- ICO announcement of a materially-sized monetary penalty in any monitored vertical.
- observation of an eighth ROPC-capable first-party application in the attacker's rotation, particularly if it is one not previously identified as ROPC-capable in Microsoft documentation;
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities catalogue (daily updates) | CISA | A1 |
| 3 | CISA KEV additions 14 Jul 2026 (SonicWall SMA1000 CVE-2026-15409, CVE-2026-15410; Microsoft AD FS CVE-2026-56155; Cisco IOS CVE-2008-4128 re-listing) | CISA | A1 |
| 4 | CISA KEV additions 10 Jul 2026 (Joomla iCagenda CVE-2026-48939; Balbooa Forms CVE-2026-56291) | CISA | A1 |
| 5 | CISA KEV additions 07 Jul 2026 (JoomShaper SP Page Builder CVE-2026-48908; Langflow CVE-2026-55255; Joomlack Page Builder CVE-2026-56290) | CISA | A1 |
| 6 | Microsoft July 2026 Patch Tuesday - 622 CVEs including two actively-exploited zero-days (AD FS CVE-2026-56155, SharePoint CVE-2026-45659 rolling forward) | Microsoft MSRC / Zero Day Initiative | A1 |
| 7 | SonicWall product notice - SMA1000 series multiple vulnerabilities and 12.4.3-02962 patch guidance | SonicWall | A2 |
| 8 | Rapid7 MDR blog - SonicWall SMA1000 zero-day exploitation with ransomware objective (CVE-2026-15409, CVE-2026-15410) | Rapid7 | A2 |
| 9 | Sophos X-Ops blog - SonicWall SMA1000 vulnerabilities in active exploitation | Sophos | A2 |
| 10 | 19-agency joint advisory - FSB Centre 16 (Static Tundra / Berserk Bear) systematic router compromise; APT28 "FrostArmada" 18,000-router DNS hijack | NCSC / CISA / 17 partner agencies | A1 |
| 11 | Google Cloud Mandiant - Threats to the Defense Industrial Base (2026 update, China-nexus dominance) | Google Cloud / Mandiant | A2 |
| 12 | The Hacker News / bytevanguard - CVE-2026-56155 AD FS DKM ACL hardening, active exploitation confirmed | Third-party technical media | B2 |
| 13 | ransomware.live daily leak-site tracker (Qilin, The Gentlemen, DragonForce, Akira, Interlock, Warlock) | ransomware.live | B2 |
| 14 | Halcyon / SOCRadar - The Gentlemen 483 lifetime victims; 121 in June 2026, first month above Qilin | Halcyon / SOCRadar | B2 |
| 15 | MOXFIVE / Infosecurity Magazine - Qilin ransomware 2026 profile (1,496 leak-site victims trailing 12 months) | MOXFIVE / Infosecurity Magazine | B2 |
| 16 | NCSC Anubis ransomware advisory (VPN credential abuse and RMM tradecraft) | National Cyber Security Centre | A1 |
| 17 | Bitdefender July 2026 Threat Debrief | Bitdefender | B2 |
| 18 | Check Point Q1 2026 State of Ransomware / ReliaQuest Q2 2026 Ransomware & Cyber Extortion | Check Point Research / ReliaQuest | B2 |
| 19 | CISA KEV entry rolling forward for CVE-2026-45659 (SharePoint deserialisation) - Storm-2603 / Warlock ransomware use | CISA / Microsoft / hard2bit | A1 |
| 20 | IP Insights REST API enrichment (multiple lookups during the reporting period - AS200373 DREI-K-TECH-GMBH pivot on the Entra ID password-spray campaign) | IP Insights / UK Cyber Defence Ltd | A1 |
| 22 | Cybersecurity Breaches Survey 2025/2026 - UK statutory dataset (rolling reference) | DSIT / GOV.UK | A1 |
| 23 | Verizon Data Breach Investigations Report 2026 - sector chapters (rolling reference) | Verizon | B2 |
| 24 | FS-ISAC daily indicator exchange (member portal - TLP:CLEAR) | FS-ISAC | A1 |
| 25 | FS-ISAC April 2026 AI Cybersecurity Hardening Advisory (rolling reference for deepfake KYC bypass) | FS-ISAC | A1 |
| 26 | MTS-ISAC daily bulletin and Cyware indicator exchange (TLP:CLEAR) | MTS-ISAC | A1 |
| 27 | Resecurity - Anubis ransomware attack on Adriatic Port Authority (retro reference) | Resecurity / Industrial Cyber | B2 |
| 28 | CYTUR / SAFETY4SEA - Maritime cyber incidents 103% year-on-year (2025 dataset, retro reference) | CYTUR | B2 |
| 29 | NCSC Cyber Threat Report - UK Legal Sector | National Cyber Security Centre | A1 |
| 30 | Law Society of Scotland journal - "Law in the crosshairs: ransomware gangs targeting low-hanging fruit firms" (July 2026) | Law Society of Scotland | B2 |
| 31 | Chaucer Group press release - 226 UK law firms suffered data breaches in the past year | Chaucer Group | B2 |
| 32 | RH-ISAC member exchange (TLP:CLEAR) | Retail and Hospitality ISAC | A1 |
| 33 | National Crime Agency - four arrests connected to M&S / Co-op / Harrods cluster (10 Jul 2026) | National Crime Agency / Cybersecurity Dive | A1 |
| 34 | Computer Weekly / Infosecurity Magazine - M&S / Co-op "Category 2 cyber hurricane" retrospective (total costs £270m-£440m) | Computer Weekly / Infosecurity Magazine | B2 |
| 35 | H-ISAC daily bulletin (member portal - TLP:CLEAR) | H-ISAC | A1 |
| 36 | Digital Health / Industrial Cyber - NHS ransomware retrospective (Synnovis, ongoing disruption) | Digital Health / Industrial Cyber | B2 |
| 37 | SonicWall - 10x surge in IPS events across UK hospitals Jan-May 2026 (264k events, retro reference) | SonicWall / Enterprise Times | B2 |
| 38 | Google Cloud Threat Intelligence - Threats to the Defense Industrial Base (2026 update) | Google Cloud / Mandiant | A2 |
| 39 | Space ISAC / National Council of ISACs bulletins (TLP:CLEAR) | NCI / Space ISAC | A1 |
| 40 | Ankura CTIX Flash Update 15 Jul 2026 (defence sector overview) | Ankura | B2 |
| 41 | National Council of ISACs aggregator - cross-sector indicator exchange | National Council of ISACs | A1 |
| 42 | NCSC Cyber Threat Report - UK Charity Sector (rolling reference for membership organisations) | National Cyber Security Centre | A1 |
| 43 | Information Commissioner's Office - breach disclosure register (rolling reference) | ICO | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Threat intelligence briefing — second half of June 2026
Coverage this period is dominated by the CISA KEV addition of the SharePoint deserialisation defect (CVE-2026-45659) on 01 Jul with a three-day federal remediation deadline; the continued tail of CitrixBleed 3 session-token abuse against NetScaler estates…
Cross-sector threat intelligence briefing — 11–17 July 2026
It consolidates the seven vertical-specific products (TI-2026-0717-001 through -007) into a single distribution-ready deliverable.
May 2025 Education Threat Intelligence Briefing
Threat Analysis of the Education Sector (1 May 2025 – 31 May 2025)