Threat intelligence briefing — second half of June 2026
Coverage this period is dominated by the CISA KEV addition of the SharePoint deserialisation defect (CVE-2026-45659) on 01 Jul with a three-day federal remediation deadline; the continued tail of CitrixBleed 3 session-token abuse against NetScaler estates…
- Reference: TI-2026-06H2 (public edition)
- Coverage: all monitored sectors
- Reporting period: 16–30 June 2026
- Issued: 6 July 2026 · Lead analyst: Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting clients during the second half of June of 2026. Coverage this period is dominated by the CISA KEV addition of the SharePoint deserialisation defect (CVE-2026-45659) on 01 Jul with a three-day federal remediation deadline; the continued tail of CitrixBleed 3 session-token abuse against NetScaler estates; and sustained double-extortion activity by Qilin, Akira and the DragonForce cluster observed via FS-ISAC daily indicator exchange and ransomware.live leak-site scraping.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that CVE-2026-45659 (SharePoint deserialisation RCE) will be exploited at scale against unpatched SharePoint estates within the next 14 days, given the CISA KEV three-day BOD 26-04 timeline, the low authenticated privilege bar (Site Member) and the prevalence of internally-facing SharePoint in FS document-management architectures (HIGH confidence).
- It is highly likely that ransomware and pure data-extortion crews - Qilin, Akira, DragonForce and the LockBit 5.0 cluster - will continue to drive the majority of materially-disruptive incidents against UK and EU firms during the next two reporting cycles, consistent with ransomware.live activity showing fresh Qilin and Akira postings on 01 Jul (HIGH confidence).
- It is likely that CitrixBleed 3 session-token abuse will continue against NetScaler-fronted remote-working and contractor access estates for a further two to four reporting cycles, given the known population of patched-but-not-session-invalidated deployments (MEDIUM-HIGH confidence).
- It is likely that AI-driven KYC bypass - deepfake voice and video authorisation of payments and synthetic-identity onboarding - will continue to expand as a fraud-adjacent threat vector through Q3 2026, consistent with ISAC's April 2026 AI Cybersecurity Hardening Advisory (MEDIUM-HIGH confidence).
- It is a realistic possibility that one of the BlueNoroff / Sapphire Sleet sub-clusters will conduct a credentialed intrusion against a UK or EU fintech or crypto-adjacent FS firm within the next two reporting cycles (MEDIUM confidence).
2. Threat Landscape
The largely financial services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. The collection picture for this period is dominated by the emergence of CVE-2026-45659 as a mass-exploitation candidate, sustained ransomware leak-site activity. FS-ISAC daily indicator exchange during the period surfaces a consistent set of Tor and bulletproof-hosting source ranges probing OWA, NetScaler Gateway and Entra ID sign-in endpoints across peer FS estates.
The CVE-2026-45659 SharePoint chain is operationally significant. SharePoint is the dominant document-management platform in mid-market and insurance firms and is frequently the store of record for underwriting files, KYC / CDD packs, board packs, and third-party counterparty due diligence. The vulnerability is exploitable by any authenticated user with Site Member permissions or higher, which is a low bar in typical deployments where all employees carry at least Site Member on the corporate intranet. Combined with Microsoft's May 2026 patch release date, unpatched estates have effectively been exposed for eight weeks.
Ransomware leak-site activity over the period was led, in volume terms, by Qilin (multiple postings including a fresh 01 Jul entry noted by ransomware.live), Akira (including the Refinery Hotel NYC posting on 01 Jul), and DragonForce (continuing sustained mid-week activity following the M&S / Co-op / Harrods retail cluster fallout). NCA arrested four UK nationals during the period in connection with the M&S / Co-op / Harrods cluster; the arrests reduce, but do not eliminate, the operational threat from the DragonForce / Scattered Spider cluster given the alliance-affiliate model.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the reporting period. The profile block below is repeated, in full, for each actor profiled.
| THREAT ACTOR PROFILE - Qilin (a.k.a. Agenda) | |
|---|---|
| Aliases | Agenda, Qilin.B, Water Galura |
| Suspected Origin | Russian-speaking (unattributed) |
| Suspected Sponsor | Organised criminal RaaS |
| Primary Motivation | Financial (double extortion) |
| Sector Targeting | Financial services, healthcare, manufacturing, retail, professional services |
| Geographic Focus | Global; UK and EU disproportionately represented in H1 2026 leak-site postings |
| Signature TTPs | Initial access via brokered credentials, RMM abuse (AnyDesk, SplashTop), RDP; PowerShell + Rust ransomware payload; ESXi Linux variant; sustained LOTL |
| Tooling / Malware Families | Qilin.B ransomware (Rust), Cobalt Strike, Rclone-to-Mega, Mimikatz, SharpHound |
| Recent Activity | 338 leak-site postings in Q1 2026; 97 attacks in May 2026; continuing at similar cadence into July - fresh victim posted 01 Jul 2026 |
| Assessed Threat to Vertical | HIGH - dominant RaaS operator against FS globally |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE - DragonForce / Scattered Spider cluster | |
|---|---|
| Aliases | Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate |
| Suspected Origin | Anglophone (UK/US); four arrests 30 Jun 2026 |
| Suspected Sponsor | Organised criminal alliance / RaaS |
| Primary Motivation | Financial (ransomware + data extortion) |
| Sector Targeting | Retail, hospitality, telecoms, technology, FS (particularly insurance and payments) |
| Geographic Focus | Anglophone western targets |
| Signature TTPs | Voice-phishing IT service desk to reset MFA, help-desk social engineering, EDR bypass via legitimate RMM tooling, DragonForce Linux/ESXi ransomware, aggressive cloud-tenant pivot |
| Tooling / Malware Families | DragonForce ransomware, Ngrok, AnyDesk, SplashTop, Impacket, Chisel |
| Recent Activity | 4 individuals arrested in the UK on 30 Jun 2026 in the West Midlands / London per NCA; alliance-affiliate model continues under other operators |
| Assessed Threat to Vertical | HIGH - social-engineering methodology transfers directly to FS help-desk and payments-fraud vectors |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE - Akira | |
|---|---|
| Aliases | Akira, Storm-1567 |
| Suspected Origin | Russian-speaking (unattributed) |
| Suspected Sponsor | Organised criminal RaaS |
| Primary Motivation | Financial (double extortion) |
| Sector Targeting | Manufacturing, professional services, FS mid-market, education, hospitality |
| Geographic Focus | North America and Europe; UK and Ireland heavily represented in FY26 tally |
| Signature TTPs | Cisco VPN unpatched initial access, valid credentials from IABs, weak-MFA bypass, RDP lateral movement, ESXi hypervisor targeting |
| Tooling / Malware Families | Akira ransomware (Rust / C++), Megazord ESXi variant, Cobalt Strike, Mimikatz, Rclone, AnyDesk |
| Recent Activity | Cumulative $244m proceeds; Refinery Hotel NYC posted 01 Jul 2026 per ransomware.live; sustained mid-cycle activity |
| Assessed Threat to Vertical | HIGH - direct threat to FS mid-market and back-office ESXi estates |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE - BlueNoroff / Sapphire Sleet (DPRK) | |
|---|---|
| Aliases | APT38, BlueNoroff, Sapphire Sleet, Dangerous Password, CryptoCore |
| Suspected Origin | Democratic People's Republic of Korea (Lazarus umbrella) |
| Suspected Sponsor | Nation state (DPRK Reconnaissance General Bureau) |
| Primary Motivation | Financial (regime revenue generation, especially cryptocurrency theft) |
| Sector Targeting | Cryptocurrency exchanges, Web3, DeFi, fintech, cross-border payments, VC / investment firms |
| Geographic Focus | Global with heavy Anglophone and Japanese targeting |
| Signature TTPs | Social engineering via LinkedIn / Telegram / X, fake job offers, fake investment approaches, macOS-focused implants (RustBucket, KANDYKORN), signed installer chains |
| Tooling / Malware Families | RustBucket, KANDYKORN, ObjCShellz, TodoSwift, DPRK signed installer chains |
| Recent Activity | Ongoing campaigns against cross-border payments and crypto-adjacent FS firms; NCSC / CISA joint reporting continues to flag active LinkedIn recruitment |
| Assessed Threat to Vertical | MEDIUM-HIGH - moderate volume but very high per-incident impact where successful |
| Analytic Confidence | MEDIUM |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours have been cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments. These have driven a significant number of autonomous defence responses.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1566.001 | Spearphishing Attachment | Malicious ISO / IMG / OneNote attachments delivering IcedID, Latrodectus and DarkGate loaders continued to dominate the phishing tail this period; volume steady week-on-week per Proofpoint and Sophos | HIGH |
| Initial Access | T1078.004 | Cloud Accounts | OAuth token replay and refresh-token abuse against Microsoft 365 tenants; credential-stuffing tail from Tor exits and bulletproof ranges | MEDIUM |
| Persistence | T1053.005 | Scheduled Task/Job | Post-exploitation scheduled-task creation observed in Akira intrusions, particularly on domain controllers immediately following DCSync activity | MEDIUM |
| Discovery | T1046 | Network Service Discovery | Automated port sweeps from datacentre-hosted infrastructure - IP Insights flagged multiple AS135771 and AS14061 sources in the perimeter tail | MEDIUM |
| Command and Control | T1071.001 | Web Protocols | Cobalt Strike, Sliver and Havoc HTTPS C2 beaconing observed in incident retrospectives from FS-ISAC and H-ISAC partners this period; JARM / JA3 fingerprint hunts remain the primary detection | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone-to-Mega and rclone-to-MEGAsync exfiltration patterns dominant in Qilin double-extortion intrusions; Akira favours MEGA and Backblaze B2 | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Qilin, Akira and DragonForce ransomware deployment observed against sector-adjacent peers this period per ransomware.live and FS-ISAC / H-ISAC reporting | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 01 Jul 2026 | Microsoft SharePoint Server (vendor) | Unattributed | CVE-2026-45659 added to CISA KEV with 04 Jul remediation deadline; deserialisation RCE with Site Member auth pre-req; FS document-management estates directly in scope | CISA KEV / Microsoft advisory / Rapid7 vulnerability database |
| 01 Jul 2026 | Refinery Hotel New York City (hospitality) | Akira | Leak-site posting; illustrative of Akira's continuing operational tempo against sector-adjacent mid-market targets | ransomware.live |
| 30 Jun 2026 | Four UK nationals (West Midlands / London) | DragonForce / Scattered Spider (allegedly) | NCA arrests on suspicion of Computer Misuse Act offences, blackmail, money laundering, participating in an OCG; connected to M&S, Co-op, Harrods intrusions | National Crime Agency press release |
| Ongoing | Multiple UK Businesses (anonymised, ISAC-derived) | Qilin | Sustained double-extortion targeting; two peer FS firms confirmed to us via FS-ISAC channel this period; details TLP:CLEAR-restricted | FS-ISAC daily indicator exchange (member portal) |
| Ongoing | Multiple EU FS firms (sector-adjacent) | BlueNoroff sub-cluster | Continuing LinkedIn-lure recruitment campaigns targeting FS technology and blockchain engineering staff | Mandiant, CrowdStrike, ESET APT reporting |
| Ongoing | Multiple UK insurance firms | N/A | Continued voice-based deepfake authorisation attempts against claims-adjuster and treasury workflows | FS-ISAC AI Cybersecurity Hardening Advisory / member exchange |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product(s) | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-45659 | Microsoft SharePoint Server SubEd / 2019 / 2016 - deserialisation RCE | 8.8 | Yes | Yes | Patch immediately per CISA KEV entry 01 Jul 2026, remediation deadline 04 Jul 2026; audit Site Member permissions; restrict inbound SharePoint /_layouts and /_vti_bin paths at the WAF; hunt w3wp.exe child processes |
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; BOD 26-04 deadline 26 Jun 2026 has passed; restrict management plane to dedicated VLAN |
| CVE-2026-34909 | Ubiquiti UniFi OS Server - path traversal | 9.8 | Yes | Yes | As per -34908; component of the Bishop Fox unauthenticated root RCE chain |
| CVE-2026-34910 | Ubiquiti UniFi OS Server - improper input validation | 9.8 | Yes | Yes | As per -34908; component of the Bishop Fox unauthenticated root RCE chain |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory overread (CitrixBleed 3) | 9.3 | Yes | Yes | Fixed builds 14.1-66.59, 13.1-62.23, 13.1-37.262 FIPS/NDcPP; must run 'kill icaconnection -all', 'kill pcoipConnection -all', 'kill aaa session -all' post-patch |
| CVE-2026-4368 | Citrix NetScaler Gateway / AAA vserver - race condition | 7.7 | Yes | Yes | Applied by the same patches as -3055; session mix-up risk against Gateway and AAA virtual servers |
| CVE-2025-67038 | Lantronix EDS5000 serial-to-IP bridge - command injection | 9.6 | Yes | Suspected | Vendor patch pending; segment device management to dedicated OT VLAN |
| CVE-2026-50751 | Check Point Security Gateway - improper authentication | 9.8 | Yes | Yes | Apply Check Point R81.20 / R81.10 / R80.40 hotfixes; hunt admin sessions from non-management source addresses |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - authenticated RCE | 8.4 | Yes | Suspected | Cisco fixed release train; disable public-facing vManage where feasible |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within non-client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 21 Jun 2026 | HIGH | F3 Netze AS205100 Tor exit (DE); IP Insights score 100 / critical; 7 blacklists (AbuseIPDB, ipsum, Dan.me.uk, Checkpoint, IPInsights honeypot); sustained perimeter tail in EmilyAI |
| IP | 185[.]220[.]101[.]34 | 28 Jun 2026 | HIGH | for-privacy.net Tor exit; IP Insights score 100 / critical; 8 blacklists; observed in credential-spray tail against Entra ID sign-in endpoints |
| IP | 194[.]180[.]48[.]18 | 30 Jun 2026 | HIGH | serverion (NL); IP Insights score 85 / critical; 2 active + 3 degraded blacklists; observed in SSH brute-force tail against perimeter jump hosts |
| IP | 92[.]118[.]39[.]203 | 01 Jul 2026 | HIGH | dmzhost / PPTECHNOLOGY (NL/UK); IP Insights score 85 / critical; 5 blacklists; observed in Exchange OWA spray tail |
| IP | 141[.]98[.]11[.]90 | 02 Jul 2026 | MEDIUM | UAB Host Baltic AS209605 (LT); IP Insights score 10 / low but datacentre-flagged; source of scripted OAuth token replay against Microsoft 365 |
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| SharePoint (CVE-2026-45659) mass-exploitation at document-management estate | H | H | CRITICAL |
| Ransomware deployment via CitrixBleed 3 session-token theft | M | H | HIGH |
| Ransomware deployment via Ubiquiti UniFi OS chain at branch / back-office edge | M | H | HIGH |
| Business email compromise / vendor payment redirect targeting finance function | H | H | CRITICAL |
| Supply-chain compromise via shared SaaS (SharePoint, M365, Salesforce) | M | H | HIGH |
| Deepfake voice / video authorisation of payments (fraud-adjacent) | M | H | HIGH |
| DPRK BlueNoroff social-engineering of technical staff at crypto-adjacent FS firms | M | H | HIGH |
9. Defensive Actions
The actions below are organised against the three operational pillars of Detect, Defend, and Disrupt.
Detect
Detection engineering should treat CVE-2026-45659 as the principal hunting hypothesis for the next reporting cycle. We built Pulse rules around w3wp.exe spawning cmd.exe, powershell.exe or rundll32.exe under the SharePoint app pool identity; anomalous deserialisation exception patterns in SharePoint ULS logs; and Site Member-permission accounts accessing /_vti_bin, /_layouts/15/upload.aspx or /_layouts/15/uploadex.aspx outside expected sessions. Continued hunts against CitrixBleed 3 residual token replay (multiple client sessions sharing a single ICA connection token, particularly from geographically distant addresses). We retained the standard Qilin / Akira / DragonForce initial-access playbook hunts (RMM install, PsExec / SMBExec, DCSync, Rclone-to-Mega) as the ransomware-tail baseline. We have deployed IP Insights critical-tail block / alert lists to WAF and Entra ID Conditional Access.
Defend
Preventive priorities follow Section 6 directly. Complete Citrix NetScaler patching where residual pre-3055 builds remain and run the session-invalidation commands ('kill icaconnection -all', 'kill pcoipConnection -all', 'kill aaa session -all') on every patched appliance. We are monitoring the patching updates for these. Complete Ubiquiti UniFi OS Server upgrade to 5.0.8 as a residual BOD 26-04 hangover. We recommend restricting SharePoint uploader and layouts endpoints to authenticated internal networks via WAF path filtering. We also recommend enforcing phishing-resistant MFA on all privileged accounts including finance-function payment approvers to raise the bar on help-desk social-engineering as demonstrated by the DragonForce cluster.
Disrupt
Disruption activity within the lawful authority has focused on:
- sustained participation in the ISAC daily indicator exchange, with this period's IP Insights critical / block tail submitted as the highest-value contributable;
- honeypot deployment fronting NetScaler Gateway and SharePoint uploader paths, with any capture routed to the disruption workflow and shared with ISAC and NCSC CiSP;
- coordinated take-down requests to bulletproof-hosting providers (dmzhost, serverion, PPTECHNOLOGY) from the IP Insights critical tail this week, submitted via the NCSC Takedown Service where the tail intersects with UK-hosted infrastructure;
- continued participation in the ISAC AI Cybersecurity Hardening working group covering deepfake payments-fraud detection.
10. Forward outlook
Looking forward to the next reporting period (July H1), it is likely that at least one UK FS firm will publicly disclose a SharePoint-borne incident traceable to CVE-2026-45659, given the volume of unpatched estate exposed to internal users with Site Member permissions and the short remediation deadline. It is likely that CitrixBleed 3 session-token replay against NetScaler estates will continue at low-to-moderate volume for at least two further cycles. Ransomware leak-site cadence from Qilin, Akira and the DragonForce cluster is expected to remain steady week-on-week; the NCA arrests are unlikely to materially reduce the operational threat to FS given the alliance-affiliate model.
Trigger conditions that would prompt revision of this outlook include:
- a UK FS firm publicly attributing a breach to SharePoint CVE-2026-45659 exploitation, which would warrant immediate out-of-cycle reporting;
- emergence of an unauthenticated variant of the SharePoint chain that removes the Site Member auth pre-requisite - this would elevate the risk to CRITICAL and warrant emergency advisory;
- further CISA KEV additions materially affecting FS infrastructure (particularly Fortinet, Ivanti or SonicWall gateways);
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities catalogue (daily updates) | CISA | A1 |
| 3 | CISA KEV addition of CVE-2026-45659 SharePoint deserialisation RCE, 01 Jul 2026 | CISA | A1 |
| 4 | CISA KEV addition of CVE-2026-34908, -34909, -34910 Ubiquiti UniFi OS chain, 23 Jun 2026 | CISA | A1 |
| 5 | Citrix Security Bulletin CTX696300 for CVE-2026-3055 and CVE-2026-4368 | Citrix / Cloud Software Group | A2 |
| 6 | Microsoft Security Update Guide entry for CVE-2026-45659 | Microsoft | A2 |
| 7 | SharePoint RCE CVE-2026-45659 added to CISA KEV after active exploitation | The Hacker News | B2 |
| 8 | CISA warns of actively exploited Microsoft SharePoint vulnerability | SecurityWeek | B2 |
| 9 | Rapid7 vulnerability database: Microsoft SharePoint CVE-2026-45659 | Rapid7 | B1 |
| 10 | NHS England Digital cyber alert CC-4759 - Citrix critical security updates | NHS Digital | A1 |
| 11 | ransomware.live daily leak-site tracker | ransomware.live | B2 |
| 12 | The State of Ransomware - Q1 2026 | Check Point Research | A2 |
| 13 | Global ransomware activity for May 2026 | Industrial Cyber | B2 |
| 14 | FS-ISAC daily indicator exchange (member portal - TLP:CLEAR) | FS-ISAC | A1 |
| 15 | H-ISAC daily bulletin (member portal - TLP:CLEAR) | H-ISAC | A1 |
| 16 | MTS-ISAC daily bulletin and Cyware indicator exchange (TLP:CLEAR) | MTS-ISAC | A1 |
| 17 | Retail and Hospitality ISAC member exchange (TLP:CLEAR) | RH-ISAC | A1 |
| 18 | NCA arrests four for attacks on M&S, Co-op and Harrods (30 Jun 2026) | National Crime Agency | A1 |
| 19 | AA25-239A: Countering Chinese State-Sponsored Actors | CISA / NSA / NCSC / partners | A1 |
| 20 | July rundown - Salt Typhoon and SharePoint scares | IT Pro | B2 |
| 21 | NHS South East London / Synnovis long-tail update | Recorded Future News | B2 |
| 22 | NHS pathology reports backlog update (Q1 2026) | Digital Health | B2 |
| 23 | NCSC Cyber Threat Report: UK Legal Sector | National Cyber Security Centre | A1 |
| 24 | Cyber attacks on law firms jump by 77% (Jun 2026) | Law Society Gazette | B2 |
| 25 | 226 UK law firms suffered data breaches in the past year | Chaucer Group | C3 |
| 26 | SRA 2024 Risk Outlook (ongoing reference) | Solicitors Regulation Authority | A2 |
| 27 | M&S, Co-op & Harrods cyber-attacks - lessons for retailers | Brabners | B2 |
| 28 | Cyber-attacks on M&S, Co-op, Harrods post-incident summary | Air IT Group | C2 |
| 29 | NCSC Cyber Threat Report: UK Charity Sector | National Cyber Security Centre | A1 |
| 30 | GOV.UK: protect your charity from cyber crime | Cabinet Office / DCMS | A1 |
| 31 | IP Insights REST API enrichment (multiple lookups during the reporting period) | IP Insights / UK Cyber Defence Ltd | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Cross-sector threat intelligence briefing — 11–17 July 2026
It consolidates the seven vertical-specific products (TI-2026-0717-001 through -007) into a single distribution-ready deliverable.
Threat intelligence briefing — first half of July 2026
It consolidates the seven vertical-specific products (TI-2026-0717-001 through -007) into a single distribution-ready deliverable.
May 2025 Education Threat Intelligence Briefing
Threat Analysis of the Education Sector (1 May 2025 – 31 May 2025)