SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Defence and government contractors threat intelligence report — 23–29 May 2026

The week's collection picture is shaped by GCHQ Director Sir Anne Keast-Butler's 27 May warning that 'time is running out for the West' to confront the threats from Russia and China; by ESET's 28 May APT Activity Report covering October 2025 to March 2026 with sustained China, Russia…

  • Reference: TI-2026-0529-006 (public edition)
  • Sector: R&D, military and government contractors
  • Reporting period: 23–29 May 2026
  • Issued: 29 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Research and Development and Military / Government Contractors vertical during the period 23 May 2026 to 29 May 2026. The week's collection picture is shaped by GCHQ Director Sir Anne Keast-Butler's 27 May warning that 'time is running out for the West' to confront the threats from Russia and China; by ESET's 28 May APT Activity Report covering October 2025 to March 2026 with sustained China, Russia, North Korea and Iran pressure on defence-industrial-base (DIB), aerospace, drone-maker and oil-shipment targets; by Symantec's Jewelbug coverage showing China-nexus collection widening into Russia; and by continued edge-appliance exploitation (Cisco SD-WAN, Ivanti EPMM, Exchange OWA, Apex One, Citrix NetScaler) against regulated DIB estates. Google's reporting on coordinated defence-sector cyber operations from China, Iran, Russia and North Korea remains the strongest single recent attribution anchor. Sources are graded against the Admiralty System.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that China-nexus APT activity — including Volt Typhoon, Salt Typhoon, APT5 and Jewelbug — will continue to target UK and Five-Eyes defence-industrial-base contractors and R&D-intensive organisations through the next reporting cycle, with edge-appliance and supply-chain compromise the consistent initial-access pattern. (HIGH confidence)
  2. It is highly likely that Russian APT activity — particularly APT28, APT29 and the GRU 26165 cluster — will continue targeting UK defence contractors and government-aligned R&D organisations, with router compromise, AiTM credential-theft and Outlook NTLM-relay the dominant TTPs. (HIGH confidence)
  3. It is highly likely that Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973, Microsoft Exchange OWA CVE-2026-42897 and Trend Micro Apex One CVE-2026-34926 will be weaponised against DIB-sector edge tiers within the next two reporting cycles; UK Cyber Defence assesses these CVEs as the priority patching set for the cycle. (HIGH confidence)
  4. It is likely that North Korean and Iranian APT activity — particularly DPRK IT-worker infiltration patterns — will continue to target UK DIB and R&D-intensive employer recruitment pipelines. (MEDIUM-HIGH confidence)
  5. There is a realistic possibility that one or more UK DIB-tier-2 suppliers will publicly disclose an APT-attributed compromise within the next two reporting cycles, given the documented activity volume and edge-appliance exposure. (MEDIUM confidence)

2. Sector threat landscape

The threat landscape facing UK R&D and military / government-contractor organisations is now uncontroversially characterised as the highest-pressure cyber-espionage environment the sector has faced. GCHQ Director Sir Anne Keast-Butler's 27 May warning that 'time is running out for the West to confront threats from Russia and China' is the headline framing for the week. Google's reporting earlier in 2026 linking China, Iran, Russia and North Korea to coordinated defence-sector cyber operations remains the strongest single recent attribution anchor, and ESET's APT Activity Report covering October 2025 to March 2026 — released 28 May — reflects sustained pressure across the entire APT axis, with particular focus on oil-shipment, drone-maker and aerospace-DIB targets.

China-nexus collection against the vertical continues to dominate by volume. Mandiant, Microsoft Threat Intelligence and CrowdStrike all place China-nexus actors as the largest single source of intrusions against the DIB in 2025–2026. APT5's two campaigns spear-phishing current and former employees of major aerospace and defence contractors in mid-to-late 2024 and again in May 2025 are still being referenced in 2026 vendor and government reporting. Volt Typhoon and Salt Typhoon pre-positioning against US and Five-Eyes critical infrastructure has direct implications for UK defence supply-chain operators, and Symantec's Jewelbug coverage — China-nexus collection widening into Russia — has knock-on relevance for any UK organisation collaborating across the Russia-aligned supply chain.

Russian APT activity remains highly active. APT28's router-compromise / DNS-hijack pattern and the Outlook NTLM-relay primitive continue to drive intrusions against NATO defence and government targets. The May 2026 CISA / FBI / NSA joint advisory on Russian state-sponsored campaign against technology companies and logistics entities continues to be the dominant Russian-cluster anchor. ESET's APT activity report flags continued Russian targeting of drone-maker and oil-shipment infrastructure, both of which sit adjacent to UK DIB-sector collaboration. Russian-aligned hacktivist DDoS and brand-damage activity against UK DIB-aligned organisations is a steady-state operational pressure.

Edge-appliance exploitation pressure is shaping the initial-access landscape across the vertical. The same CVE set that drives risk in financial services and healthcare — Cisco Catalyst SD-WAN (CVE-2026-20182, CVSS 10.0, UAT-8616 in-the-wild), Ivanti EPMM (CVE-2026-6973), Microsoft Exchange OWA (CVE-2026-42897), Trend Micro Apex One (CVE-2026-34926), Citrix NetScaler (CVE-2026-3055/4368) — applies acutely to DIB-tier WAN, mobile-device-management, mail and remote-access tiers. The UAT-8616 in-the-wild observation has direct DIB implications because the activity cluster has been linked to broader China-nexus tooling and is not known to be exclusively a financial-services threat.

North Korean and Iranian APT activity continues. ESET's 28 May report flags sustained DPRK operations including the IT-worker infiltration pattern, in which DPRK-aligned individuals secure remote-developer or technical employment with Western R&D-intensive employers and use the access to fund regime activity, exfiltrate IP, or pre-position for follow-on compromise. UK DIB and R&D-intensive employers should treat their recruitment-and-onboarding process as in scope for cyber-security review, with particular focus on identity-verification of remote-only candidates and on payment-route validation. Iranian APT activity against drone-related and aerospace-DIB targets continues at a steady cadence.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Volt Typhoon

  • Aliases: VANGUARD PANDA, BRONZE SILHOUETTE, Insidious Taurus
  • Suspected Origin: China (PRC)
  • Suspected Sponsor: Nation-state — PLA / MSS aligned
  • Primary Motivation: Pre-positioning for disruption of critical infrastructure
  • Sector Targeting: Cross-sector with sustained Research & Development and Military / Government Contractors relevance.
  • Geographic Focus: US, UK Five Eyes; CNI sectors (energy, water, comms, transport)
  • Signature TTPs: Living-off-the-land via legitimate Windows utilities; valid-account abuse; long-dwell persistence on edge devices
  • Tooling / Malware Families: Native LOLBins; minimal custom implants; rare beacon traffic
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty A1.
  • Analytic Confidence: HIGH

Salt Typhoon

  • Aliases: GhostEmperor, Earth Estries
  • Suspected Origin: China (PRC)
  • Suspected Sponsor: Nation-state — MSS aligned
  • Primary Motivation: Espionage of telecoms backbone; SIGINT support
  • Sector Targeting: Cross-sector with sustained Research & Development and Military / Government Contractors relevance.
  • Geographic Focus: Telecoms providers, US/UK CNI; lawful-intercept infrastructure
  • Signature TTPs: Edge-appliance zero-days; long-dwell persistence; passive collection on backbone routers
  • Tooling / Malware Families: GhostEmperor rootkit, custom telecom implants
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty A1.
  • Analytic Confidence: HIGH

APT5 (UNC2630 / Manganese)

  • Aliases: Keyhole Panda, Bronze Fleetwood, Manganese
  • Suspected Origin: China (PRC)
  • Suspected Sponsor: Nation-state — MSS aligned
  • Primary Motivation: Espionage; aerospace / defence / military technology theft
  • Sector Targeting: Cross-sector with sustained Research & Development and Military / Government Contractors relevance.
  • Geographic Focus: Aerospace and defence contractors in US, UK, Australia, Japan
  • Signature TTPs: Spear-phishing of current and former DIB employees; edge-appliance zero-days; ManageEngine and Citrix targeting
  • Tooling / Malware Families: BLOODMINE, BLOODBANK, PALEWAVE, custom Pulse Secure implants
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty A1.
  • Analytic Confidence: HIGH

APT28 (Fancy Bear / Sednit / Forest Blizzard)

  • Aliases: Sofacy, STRONTIUM, Pawn Storm, Forest Blizzard
  • Suspected Origin: Russia
  • Suspected Sponsor: Nation-state — Russian GRU 26165
  • Primary Motivation: Espionage; geopolitical intelligence
  • Sector Targeting: Cross-sector with sustained Research & Development and Military / Government Contractors relevance.
  • Geographic Focus: NATO member states, Ukraine, MENA defence chain
  • Signature TTPs: Router compromise to hijack DNS; AiTM credential theft; Outlook NTLM relay; HeadLace / OceanMap implants
  • Tooling / Malware Families: X-Agent, X-Tunnel, HeadLace, OceanMap, Zebrocy, GooseEgg
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — NCSC and Five Eyes joint advisories
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty A1.
  • Analytic Confidence: HIGH — NCSC and Five Eyes joint advisories

Jewelbug

  • Aliases:
  • Suspected Origin: China (PRC)
  • Suspected Sponsor: Nation-state — espionage cluster
  • Primary Motivation: Espionage; recently widened to Russian targets per Symantec
  • Sector Targeting: Cross-sector with sustained Research & Development and Military / Government Contractors relevance.
  • Geographic Focus: Russia, Asia, NATO members
  • Signature TTPs: Custom backdoors; long-dwell intelligence collection; supply-chain via trusted vendors
  • Tooling / Malware Families: Custom China-nexus implants; named in May 2026 Symantec reporting
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. MEDIUM-HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: MEDIUM-HIGH

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
ReconnaissanceT1595Active ScanningInternet-wide scanning of UK DIB ASN ranges for Cisco SD-WAN, Ivanti EPMM, NetScaler and Exchange OWA exposure.HIGH
Resource DevelopmentT1585.001Establish Accounts: Social MediaDPRK IT-worker infiltration pattern — synthetic LinkedIn / GitHub profiles seeded for UK DIB / R&D recruitment.MEDIUM
Initial AccessT1190Exploit Public-Facing ApplicationCisco SD-WAN CVE-2026-20182 (UAT-8616), Ivanti EPMM CVE-2026-6973, Exchange OWA CVE-2026-42897, Apex One CVE-2026-34926, Citrix NetScaler CVE-2026-3055/4368.HIGH
Initial AccessT1566.001Spear-phishing AttachmentAerospace-and-defence-themed spear-phish (APT5 pattern) against current and former employees of major contractors.HIGH
Initial AccessT1078Valid AccountsVolt Typhoon valid-account abuse via living-off-the-land; long-dwell persistence.HIGH
ExecutionT1059Command and Scripting InterpreterNative Windows utilities used by Volt Typhoon LOTL; PowerShell and WMI in APT28 / APT29 operations.MEDIUM
PersistenceT1505.003Server Software Component: Web ShellWeb-shell drops on exploited NetScaler and SD-WAN appliances for long-dwell re-entry.HIGH
Credential AccessT1187Forced AuthenticationOutlook NTLM-relay primitive used by APT28 cluster for credential theft.HIGH
Credential AccessT1003.001OS Credential Dumping: LSASSMimikatz / comsvcs.dll MiniDump against domain controllers in DIB networks.MEDIUM
Command and ControlT1071.001Application Layer Protocol: Web ProtocolsGhostEmperor / X-Agent / X-Tunnel C2 over HTTPS; long-dwell low-volume beacon traffic.HIGH
ExfiltrationT1041Exfiltration Over C2 ChannelEspionage exfiltration over the established C2 channel; rclone / MEGA / AzCopy in criminal blends.HIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
27 May 2026GCHQ Director public warning — Russia / China cyber threatStrategic contextSir Anne Keast-Butler: 'time is running out for the West' to confront cyber threats; UK DIB-relevant strategic anchor for the cycle.CNBC
28 May 2026ESET APT Activity Report — Oct 2025 to Mar 2026Multiple — Russian, Chinese, North Korean and Iranian APTsSustained DIB / drone-maker / oil-shipment targeting; methodologically transparent vendor reporting.ESET / Help Net Security
Earlier 2026Jewelbug — China-nexus collection widening into RussiaJewelbugSymantec coverage of China-nexus APT widening reach to Russian targets; supply-chain implications for UK collaborators.Symantec / Broadcom
May 2026CISA / FBI / NSA joint advisory — Russian state-sponsored campaign against technology and logistics entitiesAPT28-adjacentSustained Russian collection against technology and logistics entities supporting Ukraine; UK DIB supply-chain relevance.CISA / FBI / NSA
February 2026Google reporting — coordinated defence-sector cyber operations from China, Iran, Russia and North KoreaMulti-APTMethodological anchor for nation-state pressure on the vertical.Google / The Hacker News

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN Controller / Manager (auth bypass; UAT-8616 in-the-wild)10.0YesYesPatch immediately; rotate SSH keys; review NETCONF logs
CVE-2026-6973Ivanti EPMM (post-CVE-2026-1340 credential reuse chain)7.2YesYesPatch and rotate any admin credential issued before 1 Feb 2026
CVE-2026-34926Trend Micro Apex One (On-Premise) — directory traversal9.4YesYesPatch to build ≥17079; treat as EDR-control-plane exposure until verified
CVE-2026-42897Microsoft Exchange Server (Subscription Edition / 2019 / 2016) — XSS via crafted email8.1YesYesApply 14 May 2026 OOB update; disable OWA externally pending patch
CVE-2025-34291Langflow — origin validation error (added KEV 21 May 2026)9.1YesSuspectedPatch and restrict admin endpoints to trusted networks
CVE-2026-8398 / CVE-2026-45321 / CVE-2026-48027DAEMON Tools Lite / TanStack packages / Nx Console developer extension (supply-chain trio added KEV 27 May)8.0–8.8YesYesAudit developer endpoints; remove compromised package versions
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler ADC and Gateway (NCSC alert week of 24 May)9.0 / 7.5NoSuspectedApply Citrix advisory updates; review session tokens

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]101[.]5ongoingMTOR exit node — Network Attack + tor_exit categories, IP Insights suggestion: block
IP193[.]32[.]162[.]157ongoingMBrute-force / malware family — listed on 6 blacklists per IP Insights
Domainglobal-retool-leaks[.]onion24 May 2026MQilin leak-site post — Global Retool Group disclosure

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
China-nexus espionage compromise via edge-appliance (Cisco SD-WAN / Ivanti EPMM / NetScaler)HIGHHIGHCRITICAL
Russian APT28 / APT29 spear-phish or Outlook NTLM-relay against DIB employee mailboxHIGHHIGHCRITICAL
DPRK IT-worker infiltration of remote-developer / engineering pipelineMEDIUMHIGHHIGH
Iranian APT spear-phish against aerospace / drone-related R&DMEDIUMMEDIUMMEDIUM
Supply-chain compromise via shared CAD / ALM / clinical-trial SaaSMEDIUMHIGHHIGH
Russian-aligned hacktivist DDoS or defacement against DIB public-facing servicesMEDIUMMEDIUMMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection engineering should treat the Cisco Catalyst SD-WAN compromise pattern as the highest-priority hunting hypothesis for the next reporting cycle. Cross-walk EPMM admin logins against the documented CVE-2026-1340 / CVE-2026-6973 credential set, rotating any admin token issued before 1 February 2026 as untrusted. For Microsoft Exchange tenants still on-prem, instrument OWA crafted-email telemetry against CVE-2026-42897 — IIS access logs paired with mailbox event 41 should surface the exploitation primitive. Trend Micro Apex One administrators should monitor for directory-traversal probes against the ApexOne web-admin endpoint and treat any EDR-control-plane configuration change without a corresponding change-management record as a P1 trigger. For R&D / DIB tenants specifically, instrument Volt Typhoon-pattern LOTL detection — any use of LOLBaS utilities (wmic, schtasks, certutil) from non-administrative-baseline parent lineages should generate a P2 hunting hypothesis. Hunt for new external SSH keys on Cisco SD-WAN, web-shell artefacts on Citrix NetScaler, and any GhostEmperor / X-Agent C2 fingerprint in JA3 / SNI clusters. Instrument Outlook NTLM-relay primitives on Exchange Server logs. Watch for synthetic-LinkedIn / GitHub identity signals in recruitment-pipeline interviews; index remote-developer payment routes against known DPRK-facilitator clusters.

Defend

Preventive priorities follow Section 6 directly: patch Cisco Catalyst SD-WAN Controller and Manager out of band as the single highest-value action of the reporting cycle, treat any pre-patch SD-WAN admin credential as untrusted, and rotate. EPMM tenants should rotate all admin credentials issued before 1 February 2026 and apply the CVE-2026-6973 patch. Trend Micro Apex One should be patched to build 17079 or later; until then, isolate the Apex web-admin interface behind a management VPN. Microsoft Exchange tenants should apply the OOB update for CVE-2026-42897, and restrict OWA external exposure to MFA-protected paths only. Hardening should follow ISO/IEC 27001 Annex A controls A.5.7 (threat intelligence), A.5.23 (information security for cloud services), A.8.8 (management of technical vulnerabilities), A.8.16 (monitoring activities) and A.8.23 (web filtering); under the NIST CSF mapping, the bulk of these controls land under Identify-AM, Protect-AC and Detect-CM. Helpdesk identity-verification scripts should be exercised against an explicit Scattered Spider / DragonForce voice-phishing scenario before the next quarter close. R&D / DIB clients should map controls onto DEF STAN 05-138 (Defence Cyber Protection Partnership), Cyber Essentials Plus, ISO/IEC 27001 Annex A, NIST SP 800-171 for any US-DOD-facing contracts, and the NCSC Cyber Assessment Framework. Phishing-resistant MFA (FIDO2 / passkeys) should be mandatory across the DIB workforce, with conditional-access policies blocking legacy authentication. Recruitment processes for remote-developer roles should require identity verification beyond document-only checks, with payment-route validation.

Disrupt

Disruption activity within client lawful authority should focus on: (i) participation in the relevant ISAC indicator-exchange channel — FS-ISAC, H-ISAC, RH-ISAC, Aviation-ISAC, MTS-ISAC and the National Council of ISACs aggregator each provide indicator-sharing forums whose value compounds with active participation; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through the registrar-abuse channel and Cloudflare / Microsoft / Google trust-and-safety forms where attribution is sufficient; (iii) deception deployment in the helpdesk-identity-verification path — honey-identities seeded with watch-listed credential signatures will surface IAB front-end activity early; and (iv) tabletop exercise of the Scattered Spider / DragonForce playbook against the inbound helpdesk channel, scoped to a realistic voice-phishing-to-encryption window of 4 to 12 hours. The DIB-ISAC and the Space ISAC provide indicator-sharing forums for the vertical, alongside NCSC's CiSP defence trust group. The MITRE ATT&CK D3FEND knowledge base provides analytic scaffolding for mapping observed activity. The DPRK-IT-worker pattern warrants disruption activity targeted at the recruitment-platform and payment-route infrastructure, in coordination with the NCSC and FBI joint guidance set.

10. Forward outlook

Looking forward to the next reporting period (30 May – 5 June 2026), it is highly likely that China-, Russia-, North Korea- and Iran-aligned APT activity against UK DIB and R&D-intensive employers will continue at sustained cadence, with edge-appliance and supply-chain compromise the consistent initial-access patterns. It is likely that one or more UK DIB-tier-2 suppliers will publicly disclose an APT-attributed compromise within the next two cycles. There is a realistic possibility of a UAT-8616 SD-WAN exploitation event naming a UK DIB-sector entity over the next reporting cycle.

*Trigger conditions that would prompt revision of this outlook include: (a) any UK DIB-tier-1 prime contractor publicly disclosing an APT-attributed compromise; (b) a fresh NCSC / Five-Eyes advisory naming a specific APT cluster with UK targeting; (c) a Volt Typhoon-style long-dwell discovery on a UK CNI operator; or (d) a fresh DPRK IT-worker infiltration disclosure in UK DIB employment.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1CISA KEV Catalog updates — 15, 20, 21, 27 May 2026 — https://www.cisa.gov/known-exploited-vulnerabilities-catalogCISAA1
2Cisco Catalyst SD-WAN Auth Bypass (CVE-2026-20182) — joint advisory CISA / NSA / FBI / NCSC-UK / ACSC / CCCS / NCSC-NZCISA et al.A1
3Talos Intelligence — Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616)Cisco TalosB2
4Trend Micro Apex One CVE-2026-34926 — CISA KEV addition 21 May 2026CISA / Trend MicroA1
5Microsoft Exchange Server CVE-2026-42897 — active exploitation confirmed by MicrosoftMicrosoft / Help Net SecurityB1
6NCSC weekly threat reports and advisory feed (NCSC-UK)NCSCA1
7ESET APT Activity Report — Oct 2025 to Mar 2026ESETB2
8Check Point Research — The State of Ransomware Q1 2026Check Point ResearchB2
9Ransomware.live — leak-site tracker (Qilin / Akira / DragonForce / TheGentlemen postings, week ending 28 May 2026)Ransomware.liveC2
10IP Insights — IP reputation enrichment (https://www.ipinsights.io)UK Cyber Defence LtdB2
11FS-ISAC — sector resilience and AI-fraud advisories (subscription)FS-ISACA2
12NCSC alert — Citrix NetScaler ADC / Gateway CVE-2026-3055 and CVE-2026-4368NCSCA1
13GCHQ Director Sir Anne Keast-Butler — 27 May 2026 warning on Russia / China cyber threatCNBCB1
14ESET APT Activity Report Oct 2025–Mar 2026 (released 28 May 2026)ESET / Help Net SecurityB2
15Symantec — Jewelbug: Chinese APT widens reach to RussiaSymantec / BroadcomB2
16Google — China, Iran, Russia, North Korea linked to coordinated defence-sector cyber operationsGoogle / The Hacker NewsB2
17CISA / FBI / NSA joint advisory — Russian state-sponsored campaign against technology and logistics entities (May 2026)CISA / FBI / NSAA1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.