Defence and government contractors threat intelligence report — 30 May – 5 June 2026
The R&D / defence-industrial-base collection picture this week has been shaped by continuing state-sponsored espionage activity against UK and EU contractors, with ESET's October-2025-to-March-2026 APT activity report (released 28 May) flagging sustained Chinese (Mustang Panda…
- Reference: TI-2026-0605-006 (public edition)
- Sector: R&D, military and government contractors
- Reporting period: 30 May – 5 June 2026
- Issued: 5 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The R&D / defence-industrial-base collection picture this week has been shaped by continuing state-sponsored espionage activity against UK and EU contractors, with ESET's October-2025-to-March-2026 APT activity report (released 28 May) flagging sustained Chinese (Mustang Panda, Volt Typhoon-aligned cluster), Russian (APT28, Sandworm-aligned) and North Korean (Lazarus / DangerousPassword) targeting. The continuing APT28 router-exploit campaign against UK SOHO and small-office router infrastructure (NCSC-UK live advisory) is operationally relevant to small R&D shops and home-working researchers. The Microsoft Defender BlueHammer LPE chain (CVE-2026-33825) has acute relevance to the vertical given the breadth of Defender deployment across the UK DIB endpoint estate.
Perimeter scrubbing was dominated by sustained brute-force pressure from the standing IP Insights 'critical' tail - none successful. Routine SSH / RDP brute-force pressure from VN, KZ and LU-resident sources continues to be the noise floor against which DIB-specific signals are filtered.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that Chinese, Russian and North Korean state-sponsored actors will continue to prioritise UK and EU R&D firms, defence contractors and government-supplier entities for espionage and intellectual-property theft over the next reporting cycle. (HIGH confidence)
- It is likely that APT28 router-exploit activity against UK SOHO and small-office routers will continue at the cadence flagged by the live NCSC-UK advisory, with consequences for home-working researchers and small R&D shops. (MEDIUM-HIGH confidence)
- It is likely that the Microsoft Defender BlueHammer LPE chain (CVE-2026-33825) will be incorporated into state-sponsored intrusion tradecraft against UK DIB endpoint estates, given the LPE / defence-evasion primitive's value against EDR-dependent environments. (MEDIUM-HIGH confidence)
- It is highly likely that Lazarus / DangerousPassword fake-recruiter activity will continue against UK and EU R&D researchers in cryptography, AI, semiconductor and defence-adjacent domains. (HIGH confidence)
- It is a realistic possibility that the FortiClient EMS zero-day (CVE-2026-35616) will be operationalised by state-sponsored actors against UK DIB entities within the next two reporting cycles. (MEDIUM confidence)
2. Sector threat landscape
The R&D / DIB vertical continues to be the principal espionage target set in the UK threat picture, on account of the combination of high-value intellectual property, classified or controlled material, and a target population that ranges from large-prime defence integrators with mature SOCs to small specialist shops with limited security capacity. ESET's October-2025-to-March-2026 APT activity report, released 28 May, places Mustang Panda, Volt Typhoon-aligned clusters, APT28 and Sandworm-aligned operators, and Lazarus / DangerousPassword as the dominant state-sponsored threats against the vertical.
The continuing APT28 router-exploit campaign against UK SOHO and small-office routers (NCSC-UK live advisory) is operationally relevant to home-working researchers and to small R&D shops whose perimeter is a domestic-grade router. Successful router compromise gives APT28 a long-dwell foothold for traffic interception and credential harvest; refresh of perimeter equipment to managed-router fleets remains the principal mitigation.
Edge-appliance exposure on the IT side remains the principal commercial-threat initial-access route. The Microsoft Defender BlueHammer chain (CVE-2026-33825) is acutely relevant given the breadth of Defender deployment across the UK DIB endpoint estate, and observed real-world intrusions chaining BlueHammer to compromised FortiGate SSL-VPN credentials from RU / SG / CH source IPs are directly applicable to the vertical's threat model.
Lazarus / DangerousPassword fake-recruiter activity continues against UK and EU researchers in cryptography, AI, semiconductor and defence-adjacent domains. The pattern - LinkedIn approach, trojanised PDF reader on second contact, AppleJeus / RustBucket / ManageBus on third - has remained stable through 2026 and is uniquely well-targeted at the vertical.
Perimeter scrubbing handled sustained brute-force pressure from the standing IP Insights 'critical' tail - none successful.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
APT28 (Fancy Bear, FROZENLAKE)
- Aliases: APT28, GRU Unit 26165, Fancy Bear, FROZENLAKE, Forest Blizzard
- Suspected Origin: Russia
- Suspected Sponsor: State (GRU)
- Primary Motivation: Espionage; influence; sabotage
- Sector Targeting: Cross-sector with sustained Research & Development and Military / Government Contractors relevance.
- Geographic Focus: UK, EU, NATO partners
- Signature TTPs: SOHO-router exploitation for long-dwell foothold; credential harvest via OAuth phishing; targeted spear-phishing of researchers
- Tooling / Malware Families: MooBot derivatives; XAgent; custom Python loaders
- Recent Activity: NCSC-UK live advisory on router-exploit campaign against UK SOHO and small-office routers.
- Assessed Threat to Vertical: HIGH for DIB; Admiralty A1.
- Analytic Confidence: HIGH
Mustang Panda
- Aliases: RedDelta, Bronze President, Earth Preta
- Suspected Origin: China
- Suspected Sponsor: State (MSS-aligned)
- Primary Motivation: Espionage; IP theft
- Sector Targeting: Cross-sector with sustained Research & Development and Military / Government Contractors relevance.
- Geographic Focus: Global; UK / EU defence-supplier interest
- Signature TTPs: DLL-sideloading via legitimate signed binaries; PlugX / Hodur loaders; long-dwell collection
- Tooling / Malware Families: PlugX, Hodur, Korplug, custom DLL sideloaders
- Recent Activity: ESET APT activity report (28 May) flags continuing UK / EU defence-supplier interest.
- Assessed Threat to Vertical: HIGH for DIB; Admiralty A2.
- Analytic Confidence: HIGH
Lazarus / DangerousPassword
- Aliases: APT38, BlueNoroff, Sapphire Sleet
- Suspected Origin: Democratic People's Republic of Korea
- Suspected Sponsor: State (RGB)
- Primary Motivation: Financial; espionage; revenue generation
- Sector Targeting: Cross-sector with sustained Research & Development and Military / Government Contractors relevance.
- Geographic Focus: Global; UK / EU cryptography, AI, semiconductor researchers
- Signature TTPs: Fake-recruiter LinkedIn lures; trojanised PDF readers; supply-chain via developer toolchain
- Tooling / Malware Families: AppleJeus, ManageBus, RustBucket, custom Python loaders
- Recent Activity: ESET (28 May) flags continuing UK / EU R&D targeting.
- Assessed Threat to Vertical: HIGH for crypto / AI / semiconductor R&D; Admiralty B2.
- Analytic Confidence: HIGH
Sandworm-aligned cluster
- Aliases: Voodoo Bear, Iron Viking, Seashell Blizzard
- Suspected Origin: Russia
- Suspected Sponsor: State (GRU)
- Primary Motivation: Espionage; disruption
- Sector Targeting: Cross-sector with sustained Research & Development and Military / Government Contractors relevance.
- Geographic Focus: UK, EU, NATO partners; particular interest in DIB ICS / OT supply
- Signature TTPs: Edge-appliance exploitation; living-off-the-land; long-dwell collection
- Tooling / Malware Families: NotPetya-derivative wipers; KAPEKA; custom backdoors
- Recent Activity: ESET (28 May) flags continuing DIB-supplier interest with ICS / OT angle.
- Assessed Threat to Vertical: HIGH for DIB ICS supply; Admiralty A2.
- Analytic Confidence: MEDIUM-HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Fortinet EMS (CVE-2026-35616); Cisco SD-WAN (CVE-2026-20182); FortiGate SSL-VPN; Exchange OWA. | HIGH |
| Initial Access | T1133 | External Remote Services | APT28 router-exploit campaign against UK SOHO and small-office routers (NCSC live advisory). | HIGH |
| Initial Access | T1566.002 | Spear-phishing Link | Lazarus / DangerousPassword fake-recruiter LinkedIn lures targeting researchers. | HIGH |
| Initial Access | T1566.001 | Spear-phishing Attachment | Trojanised PDF readers and conference-paper lures from Lazarus and Mustang Panda. | HIGH |
| Execution | T1574.002 | DLL Side-Loading | Mustang Panda PlugX / Hodur via legitimate signed binaries. | HIGH |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Microsoft Defender BlueHammer (CVE-2026-33825) - direct DIB endpoint relevance. | MEDIUM-HIGH |
| Collection | T1213 | Data from Information Repositories | Targeted collection of design-document and source-code repositories. | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGAcmd / Azure to attacker-controlled tenants; long-dwell trickle pattern. | MEDIUM |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 02 Jun 2026 | Microsoft Defender platform (vendor) | Multiple - RU / SG / CH transit | BlueHammer LPE chain disclosed; observed in real-world intrusions chaining FortiGate SSL-VPN credential reuse - direct DIB relevance. | Microsoft / The Hacker News |
| 02 Jun 2026 | Fortinet FortiClient EMS (vendor) | Unattributed | CVE-2026-35616 confirmed in-the-wild; DIB perimeter exposure substantial. | watchTowr Labs |
| Continuing | UK SOHO and small-office routers | APT28 | NCSC-UK live advisory on router-exploit campaign; relevant to home-working researchers and small R&D shops. | NCSC-UK |
| Continuing | UK / EU R&D researchers | Lazarus / DangerousPassword | Continuing fake-recruiter LinkedIn lures; ESET-confirmed pattern. | ESET |
| 28 May 2026 | ESET APT Activity Report Oct 2025 - Mar 2026 | Multiple state | Comprehensive review of UK / EU DIB threat picture for the cycle. | ESET |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-35616 | Fortinet FortiClient EMS - pre-auth RCE; active in-the-wild exploitation reported by watchTowr 02 Jun 2026 | 9.8 | Yes | Yes | Patch to 7.4.2 or later; restrict EMS admin interface to management VLAN |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform - BlueHammer LPE / defence-evasion (<4.18.26040.1011) | 8.4 | Yes | Yes | Force MoCAMP rollout; hunt for FortiGate SSL-VPN sessions terminating from RU/SG/CH |
| CVE-2026-45585 | Microsoft Windows BitLocker - YellowKey bypass; in-the-wild PoC live | 7.1 | Yes | Suspected | Apply June mitigation guidance; enforce TPM+PIN on regulated workstations |
| CVE-2026-42897 | Microsoft Exchange Server (SE / 2019 / 2016) - OWA crafted-email XSS (continuing exploitation) | 8.1 | Yes | Yes | Apply 14 May 2026 OOB update if not already; disable external OWA pending patch |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller / Manager - auth bypass; UAT-8616 continuing campaign | 10.0 | Yes | Yes | Verify Emergency Directive 26-03 closure; rotate SSH keys; review NETCONF logs |
| CVE-2026-6973 | Ivanti EPMM - admin credential reuse chain (post CVE-2026-1340) | 7.2 | Yes | Yes | Rotate any EPMM admin credential issued before 01 Feb 2026; confirm patch level |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer (Magento) - deserialisation; KEV 03 Jun 2026 | 9.8 | Yes | Yes | Patch immediately; isolate Magento admin behind WAF; hunt for unsigned PHP cache entries |
| CVE-2025-48595 | Android Framework - integer-overflow LPE; KEV 02 Jun 2026; limited/targeted exploitation observed by Google | 7.8 | Yes | Yes | Push June 2026 Android security patch to MDM-managed handsets |
| CVE-2022-0492 | Linux Kernel cgroup release_agent - KEV 02 Jun 2026 for revived container-escape campaigns | 7.8 | Yes | Yes | Validate kernels >=5.17; audit container hosts for unconfined cgroup mounts |
| CVE-2026-41091 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-45498 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-N8N-CRIT | n8n self-hosted - max-severity authentication-bypass per CyberScoop research (defenders rushing PoC) | 9.8 | Yes | Suspected | Upgrade to patched build; restrict n8n console to private network only |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 85[.]137[.]228[.]167 | 30 May 2026 | H | ServeTheWorld AS (NO); IP Insights threat_score 100, 8 blacklists incl. Emerging Threats Compromised, Brute Force Blocker, Malicious IP - SSH/brute-force cluster |
| IP | 79[.]143[.]178[.]79 | 31 May 2026 | H | contabo.DE; threat_score 100, 7 blacklists incl. ThreatFox malware family - staged loader infrastructure |
| IP | 176[.]65[.]139[.]151 | 01 Jun 2026 | H | Offshore LC (LU); threat_score 100, 7 blacklists - recurring bullet-proof hosting for brute-force |
| IP | 212[.]19[.]134[.]75 | 02 Jun 2026 | H | JSC Kazakhtelecom (KZ); threat_score 100, 8 blacklists; SSH/Telnet brute force at scale |
| IP | 27[.]79[.]41[.]68 | 03 Jun 2026 | H | Viettel Group (VN); threat_score 100, 7 blacklists; SSH brute force |
| IP | 103[.]77[.]246[.]158 | 04 Jun 2026 | H | Megacore Technology (VN); threat_score 100, 7 blacklists; sustained brute-force |
| IP | 34[.]86[.]81[.]254 | 31 May 2026 | M | Google LLC datacentre (US); IP Insights flagged 'critical'; abuse of cloud egress for compromised-stack traffic |
| IP | 136[.]117[.]199[.]185 | 02 Jun 2026 | M | Google LLC datacentre (US); IP Insights 'critical'; cloud-egress abuse |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| State-sponsored intrusion via FortiClient EMS or Cisco SD-WAN edge-appliance | HIGH | HIGH | CRITICAL |
| APT28 router-exploit foothold against home-working researchers | HIGH | MEDIUM | HIGH |
| Lazarus / DangerousPassword recruiter-lure intrusion against named researcher | HIGH | HIGH | CRITICAL |
| EDR-control-plane compromise via Microsoft Defender BlueHammer chain | MEDIUM-HIGH | HIGH | HIGH |
| Mustang Panda DLL-sideload intrusion via signed-binary chain | MEDIUM | HIGH | HIGH |
| Supply-chain compromise via shared SaaS developer-toolchain | MEDIUM | HIGH | HIGH |
| Sandworm-aligned ICS / OT supply-chain compromise | MEDIUM | HIGH | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should prioritise (a) FortiClient EMS exploitation per the Section 4 TTPs; (b) Defender MoCAMP build below 4.18.26040.1011 across DIB endpoint estates; (c) any DLL-sideload pattern matching Mustang Panda's PlugX / Hodur tradecraft (signed-binary parent process loading sideload DLL from user-writable path); (d) any LinkedIn-originated download chain on researcher workstations consistent with Lazarus / DangerousPassword recruiter-lure tradecraft; (e) anomalous outbound traffic from home-office UK SOHO router subnets consistent with the NCSC APT28 advisory. Cross-walk all telemetry against ESET, Mandiant, Talos and CrowdStrike DIB-specific indicator streams.
Defend
Preventive priorities: patch Fortinet FortiClient EMS to 7.4.2 or later; force MoCAMP 4.18.26040.1011 across DIB endpoint estates; replace UK SOHO and small-office consumer-grade routers used by home-working researchers with managed-router fleets per NCSC guidance; harden LinkedIn-originated attachment policy on researcher workstations; verify SD-WAN ED 26-03 closure; apply the 14 May Exchange OOB update. Reference Defence Cyber Protection Partnership requirements, NIST 800-171 / CMMC equivalents for supplier estates, and ISO/IEC 27001 Annex A.5.7, A.8.8 and A.5.23.
Disrupt
Disruption priorities: (i) sustained participation in the Defence Cyber Protection Partnership and the wider National Council of ISACs aggregator; (ii) coordinated takedown of Lazarus / DangerousPassword recruiter-lure infrastructure through LinkedIn trust-and-safety and registrar-abuse channels; (iii) tabletop exercises around the APT28 router-exploit and BlueHammer EDR-blind scenarios; (iv) deception deployment around fake design-document repositories and fake LinkedIn recruiter profiles to gain attacker-side telemetry.
10. Forward outlook
Looking forward to the next reporting period (06 - 12 June 2026), it is likely that at least one UK DIB entity will be targeted by Lazarus / DangerousPassword recruiter-lure tradecraft, with HIGH confidence based on the standing pattern. It is a realistic possibility that state-sponsored actors will weaponise the FortiClient EMS zero-day (CVE-2026-35616) against a UK DIB perimeter within the cycle. It is highly likely that APT28 router-exploit activity against UK SOHO and small-office routers will continue at the cadence flagged by NCSC-UK.
Trigger conditions that would prompt revision include: (a) NCSC-UK or Five Eyes joint advisory attributing a UK DIB incident to APT28, Mustang Panda or Lazarus; (b) a UK DIB entity publicly disclosing a BlueHammer-chained intrusion; (c) novel ESET, Mandiant or CrowdStrike reporting on DIB-specific tradecraft.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | CISA KEV Catalog updates 27 May, 02 Jun and 03 Jun 2026 - https://www.cisa.gov/known-exploited-vulnerabilities-catalog | CISA | A1 |
| 2 | CISA Alert - CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2022-0492, CVE-2025-48595), 02 Jun 2026 | CISA | A1 |
| 3 | CISA Alert - CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-45247), 03 Jun 2026 | CISA | A1 |
| 4 | NCSC-UK weekly threat report and advisory feed (week ending 05 Jun 2026) - https://www.ncsc.gov.uk/section/keep-up-to-date/threat-reports | NCSC | A1 |
| 5 | ESET APT Activity Report - October 2025 to March 2026 | ESET | B2 |
| 6 | Health-ISAC Heartbeat & 2026 Global Health Sector Threat Landscape Report | Health-ISAC | A2 |
| 7 | Check Point Research - Ransomware Quarterly Insights and May 2026 retrospective | Check Point Research | B2 |
| 8 | BreachSense - May 2026 Ransomware Report (646 victims, 61 groups) | BreachSense | C2 |
| 9 | Ransomware.live - leak-site tracker (Qilin / TheGentlemen / Akira / DragonForce postings, w/e 05 Jun 2026) | Ransomware.live | C2 |
| 10 | watchTowr Labs - Fortinet FortiClient EMS Zero-Day CVE-2026-35616, 02 Jun 2026 | watchTowr | B2 |
| 11 | The Hacker News - Microsoft mitigation for YellowKey BitLocker bypass CVE-2026-45585 | The Hacker News | B2 |
| 12 | The Hacker News - Microsoft warns of two actively exploited Defender vulnerabilities (BlueHammer) | Microsoft / The Hacker News | B1 |
| 13 | CyberScoop - researchers warn of max-severity defect in n8n self-hosted | CyberScoop | B2 |
| 14 | IP Insights - IP reputation enrichment (https://www.ipinsights.io) | UK Cyber Defence Ltd | B2 |
| 16 | NCSC-UK - live advisory on APT28 router-exploit campaign | NCSC | A1 |
| 17 | ESET - APT Activity Report October 2025 to March 2026 (released 28 May 2026) | ESET | A2 |
| 18 | Defence Cyber Protection Partnership - standing requirements for UK DIB | MOD / DCPP | A1 |
| 19 | watchTowr - Fortinet FortiClient EMS Zero-Day CVE-2026-35616 | watchTowr | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Defence and government contractors threat intelligence report — 4–8 May 2026
The R&D and military / government-contractor threat picture for the reporting period continues to be dominated by sustained state-sponsored activity.
Defence and government contractors threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the R&D, military and government-contractor threat picture remained dominated by state-sponsored cyber-espionage against the defence industrial base.
Defence and government contractors threat intelligence report — 27 April – 3 May 2026
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.