Defence and government contractors threat intelligence report — 6–12 June 2026
The R&D and defence-contractor collection picture this week continues to be defined by sustained China-, Russia-, DPRK- and Iran-linked cyber pressure against the Western defence industrial base…
- Reference: TI-2026-0612-006 (public edition)
- Sector: R&D, military and government contractors
- Reporting period: 6–12 June 2026
- Issued: 12 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Research and Development and Military / Government Contractors sector during the period 06 Jun 2026 - 12 Jun 2026. It is intended to support security leadership and operational defenders within the vertical and is issued under TLP:CLEAR.
The R&D and defence-contractor collection picture this week continues to be defined by sustained China-, Russia-, DPRK- and Iran-linked cyber pressure against the Western defence industrial base, with edge-device exploitation as the hallmark Chinese tradecraft and recruitment-process abuse as the principal Russian and DPRK pattern. The week's new no-patch network-edge defects (Cisco Catalyst SD-WAN Manager CVE-2026-20245 and Arista EOS CVE-2026-7473) materially expand the in-the-wild attack surface against defence-contractor and research-institution data-centre fabrics; the NCSC Citrix NetScaler advisories carry forward.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that China-nexus APT activity against UK and EU defence contractors and aerospace primes will continue at the current operational tempo, with edge-device exploitation as the principal initial-access vector, consistent with Google / Mandiant 2026 defence industrial base reporting. (HIGH confidence)
- It is highly likely that DPRK-linked recruitment-process abuse (Lazarus / Sapphire Sleet) will continue to compromise defence-contractor and research-institution employees through fake-recruiter LinkedIn lures and trojanised PDF readers, with cryptocurrency-theft secondary to access generation. (HIGH confidence)
- It is highly likely that Russia-nexus activity will continue to focus on defence firms supporting battlefield technologies in the Russia-Ukraine War, particularly unmanned aircraft systems and counter-UAS development. (HIGH confidence)
- It is likely that the no-patch Cisco SD-WAN Manager (CVE-2026-20245) and Arista EOS (CVE-2026-7473) defects will be exploited against a defence-contractor or research-institution estate within the next two reporting cycles, with MEDIUM-HIGH confidence based on the prevalence of both vendors in the sector. (MEDIUM-HIGH confidence)
- It is a realistic possibility that Iran-nexus activity will continue to target UK defence contractors and research institutions with destructive-malware capability, consistent with the broader pattern of Middle-East geopolitical pressure. (MEDIUM confidence)
2. Sector threat landscape
The defence-contractor and R&D vertical continues to absorb the most concentrated nation-state cyber pressure of any commercial sector. Google / Mandiant 2026 reporting documents sustained Chinese, Russian, Iranian and DPRK-linked operator focus, with multi-threat attribution to coordinated defence-sector campaigns. China-nexus APT5 spearphishing campaigns through 2024-2025 explicitly targeted current and former employees of major aerospace and defence contractors, with the hallmark Chinese tradecraft being edge-device exploitation as initial access.
Edge-appliance exposure dominates the week's new CVE picture. The Cisco Catalyst SD-WAN Manager defect CVE-2026-20245 (no patch) and the Arista EOS tunnel-decap defect CVE-2026-7473 (no patch) are both directly relevant to defence-contractor and research-institution data-centre fabrics, where both vendors are heavily deployed. The Citrix NetScaler advisories from NCSC (CVE-2026-3055 / -4368) and the Fortinet FortiClient EMS pre-auth RCE (CVE-2026-35616) compound the picture. The Microsoft Defender BlueHammer chain (CVE-2026-33825) is operationally consequential for Defender-dependent contractor estates.
DPRK-linked recruitment-process abuse has matured into a sustained, productive tradecraft against the sector. Fake-recruiter LinkedIn lures, trojanised PDF readers and Python loaders are deployed against current and former defence and aerospace employees, with cryptocurrency-theft as the immediate financial driver but access generation as the strategic objective. ESET, CrowdStrike, Mandiant and US-CERT have all published aligned reporting through 2026.
Russia-nexus activity continues to focus on defence firms supporting battlefield technologies in the Russia-Ukraine War, particularly unmanned aircraft systems and counter-UAS capability. Operators have also been observed targeting recruitment processes and employee access at global defence and aerospace firms, mirroring the DPRK pattern. Multi-threat attribution to coordinated defence-sector campaigns from China-, Russia-, Iran- and DPRK-linked actors is now a recurring feature of Google, Mandiant and CrowdStrike reporting.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
APT5 (UNC2630-adjacent / China)
- Aliases: APT5, Keyhole Panda, Manganese
- Suspected Origin: People's Republic of China
- Suspected Sponsor: State (MSS-adjacent)
- Primary Motivation: Espionage - defence industrial base, aerospace
- Sector Targeting: Defence and aerospace primary.
- Geographic Focus: Global; UK, US, EU, ANZ
- Signature TTPs: Edge-device exploitation as initial access; long-dwell credential harvesting; bespoke implants
- Tooling / Malware Families: Custom implants, web-shell sets, supply-chain tradecraft
- Recent Activity: Spearphishing campaigns through 2024-2025 against major aerospace / defence contractor employees per Google / Mandiant 2026.
- Assessed Threat to Vertical: HIGH - Admiralty A1.
- Analytic Confidence: HIGH
Lazarus / Sapphire Sleet (DPRK)
- Aliases: APT38, BlueNoroff, Sapphire Sleet, DangerousPassword
- Suspected Origin: Democratic People's Republic of Korea
- Suspected Sponsor: State (RGB)
- Primary Motivation: Financial - cryptocurrency theft; access generation against defence / R&D
- Sector Targeting: Defence-contractor and research-institution employees with cryptocurrency exposure or defence-industry employment history.
- Geographic Focus: Global
- Signature TTPs: Fake-recruiter LinkedIn lures; trojanised PDF readers; Python loaders; CI/CD pipeline LotL
- Tooling / Malware Families: AppleJeus, ManageBus, RustBucket, custom Python loaders
- Recent Activity: ESET APT activity report May 2026 confirms continuing UK / EU defence-sector targeting.
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: HIGH
APT28 / Forest Blizzard (Russia)
- Aliases: Fancy Bear, Sofacy, Strontium
- Suspected Origin: Russia
- Suspected Sponsor: State (GRU 26165)
- Primary Motivation: Espionage; battlefield-technology focus
- Sector Targeting: Defence and aerospace primary; UK and EU defence contractors supporting Russia-Ukraine battlefield technologies.
- Geographic Focus: Global; UK, US, EU
- Signature TTPs: Router exploitation for DNS hijack / AiTM; credential harvesting; recruitment-process abuse
- Tooling / Malware Families: Custom router implants; commodity remote-access
- Recent Activity: NCSC advisory on APT28 router exploitation enabling AiTM and credential / token theft, Jun 2026.
- Assessed Threat to Vertical: HIGH - Admiralty A1.
- Analytic Confidence: HIGH
MuddyWater / TA450 (Iran)
- Aliases: TA450, Static Kitten
- Suspected Origin: Islamic Republic of Iran
- Suspected Sponsor: State (MOIS-adjacent)
- Primary Motivation: Espionage; targeted destructive impact
- Sector Targeting: Defence and research-institution targeting in line with broader Middle-East geopolitical pressure.
- Geographic Focus: Global; UK, US, EU
- Signature TTPs: Spear-phishing; commodity loaders; remote-access tool abuse
- Tooling / Malware Families: PowerShell-based RATs, commodity remote-access
- Recent Activity: Continuing activity per multi-vendor 2026 reporting; no UK-specific public disclosure this reporting period.
- Assessed Threat to Vertical: MEDIUM-HIGH - Admiralty B2.
- Analytic Confidence: MEDIUM-HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Edge-device exploitation - Cisco SD-WAN Manager (CVE-2026-20245), Arista EOS (CVE-2026-7473), Fortinet FortiClient EMS (CVE-2026-35616), Citrix NetScaler (CVE-2026-3055 / -4368) - hallmark Chinese tradecraft. | HIGH |
| Initial Access | T1566.001 | Spear-phishing Attachment | DPRK fake-recruiter lures and trojanised PDF readers; APT28 spear-phish against defence contractors. | HIGH |
| Initial Access | T1078 | Valid Accounts | Long-dwell credential reuse; recruitment-process abuse leading to insider-credential generation. | HIGH |
| Execution | T1059.001 | Command and Scripting: PowerShell | PowerShell loaders staging bespoke implants and commodity loaders. | MEDIUM |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Cisco SD-WAN Manager CLI command-injection (CVE-2026-20245); Microsoft Defender BlueHammer chain (CVE-2026-33825). | HIGH |
| Persistence | T1505.003 | Server Software Component: Web Shell | Web-shell deployment against compromised edge devices; characteristic Chinese tradecraft. | HIGH |
| Defence Evasion | T1562.001 | Impair Defences: Disable Security Tools | BlueHammer LPE against Defender deployments. | HIGH |
| Discovery | T1018 | Remote System Discovery | Network reconnaissance against contractor R&D estates following edge-device compromise. | HIGH |
| Collection | T1213 | Data from Information Repositories | Bulk staging from SharePoint, Confluence and PLM estates prior to exfiltration. | HIGH |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | Long-dwell low-volume exfiltration consistent with espionage tradecraft, in addition to opportunistic rclone bulk push. | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager | Unattributed | CVE-2026-20245 KEV; ITW; no patch; defence-contractor fabric relevance. | CISA / Cisco PSIRT |
| 09 Jun 2026 | Arista EOS | Unattributed | CVE-2026-7473 KEV; no patch. | CISA / Arista |
| 09 Jun 2026 | Google Chromium V8 | Unattributed | CVE-2026-11645 KEV. | CISA / Google |
| Ongoing | APT28 router exploitation | APT28 / GRU 26165 | NCSC advisory on router DNS-hijack enabling AiTM and credential/token theft. | NCSC |
| 02 Jun 2026 | Fortinet FortiClient EMS | Unattributed | CVE-2026-35616 ITW; carry. | watchTowr Labs |
| Ongoing | Lazarus / Sapphire Sleet recruitment lures | DPRK / RGB | Continuing fake-recruiter LinkedIn lures and trojanised PDF readers against defence / R&D employees. | ESET / US-CERT / Mandiant |
| Ongoing | APT5 spearphishing campaigns | China / MSS-adjacent | Continuing targeting of major aerospace / defence contractor employees. | Google / Mandiant |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command-injection (authenticated, netadmin) | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; ACL Manager to management VLAN; monitor for crafted file uploads. No vendor patch at issue. |
| CVE-2026-7473 | Arista EOS - tunnel-protocol type not validated on decap interface (no patch planned) | 6.9 | Yes | Yes | Apply Arista mitigation: explicit per-protocol decap-group configuration; ACL the tunnel-endpoint IP; consider removal of decap on edge. |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read/write, browser-side RCE | 8.8 | Yes | Yes | Force-update Chrome and Chromium-derived browsers (Edge, Brave) across the fleet; enforce Site Isolation; verify SmartScreen / SafeBrowsing telemetry. |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer for Magento - deserialisation of untrusted data | 9.8 | Yes | Yes | Patch Mirasvit extension to vendor-supplied build; restrict admin/cache endpoints to internal IP space; rotate any captured admin tokens. |
| CVE-2025-48595 | Android Framework - integer overflow, limited targeted exploitation | 7.8 | Yes | Yes | Enforce June 2026 Android security patch level on managed devices via MDM; deprovision devices unable to receive the update. |
| CVE-2022-0492 | Linux Kernel cgroup release_agent - container escape (revived for cloud workloads) | 7.8 | Yes | Yes | Enforce seccomp / AppArmor / SELinux on container hosts; verify kernel >= 5.16.4 or backported patches; restrict unprivileged user namespaces. |
| CVE-2026-35616 | Fortinet FortiClient EMS - pre-auth RCE; watchTowr confirmed ITW exploitation 02 Jun (carry) | 9.8 | Yes | Yes | Patch to 7.4.2 or later; restrict EMS admin interface to management VLAN; hunt for new local accounts and outbound HTTP from EMS hosts. |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform - BlueHammer LPE / defence-evasion (carry) | 8.4 | Yes | Yes | Force MoCAMP rollout to 4.18.26040.1011 or later; hunt for FortiGate SSL-VPN sessions terminating from RU/SG/CH source IPs. |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - NCSC take-action notice (carry) | 9.1 | No | Suspected | Apply Citrix firmware; rotate NetScaler session tokens; force re-authentication across Gateway tenants; review for AAA-vserver tampering. |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - companion NCSC advisory (carry) | 8.8 | No | Suspected | Apply Citrix firmware bundle; baseline configuration drift; monitor for new admin or read-only accounts. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 85[.]137[.]228[.]167 | 24 May 2026 | HIGH | ServeTheWorld AS (NO, AS34989) - perimeter SSH/CMS brute-force; IP Insights threat=critical, 9 blacklists. |
| IP | 79[.]143[.]178[.]79 | 24 May 2026 | HIGH | Contabo (DE) - perimeter brute-force; IP Insights threat=critical, 8 blacklists. |
| IP | 51[.]68[.]226[.]87 | 02 Jun 2026 | HIGH | OVH SAS (FR, AS16276) - datacentre IP; carry-IOC sweep; IP Insights threat=critical, 6 blacklists. |
| IP | 136[.]232[.]11[.]10 | 02 Jun 2026 | HIGH | Reliance Jio (IN, AS55836) - carry-IOC; IP Insights threat=critical, 7 blacklists. |
| IP | 165[.]154[.]105[.]128 | 02 Jun 2026 | HIGH | UCLOUD HK (VN, AS135377) - datacentre; carry-IOC; IP Insights threat=critical, 7 blacklists. |
| ASN | AS135377 (UCLOUD HK) | 12 Jun 2026 | HIGH | IP Insights ASN risk=critical (81); 807/1000 sampled IPs blacklisted; recommend AS-level edge denial for low-business-need ASNs. |
| ASN | AS60729 (TorServers / Stiftung Erneuerbare Freiheit) | 12 Jun 2026 | HIGH | 190/191 sampled IPs blacklisted; treat Tor egress as inherently suspect for client estates. |
| ASN | AS51167 (Contabo) | 12 Jun 2026 | MEDIUM | IP Insights risk=high (52); 553/1000 sampled IPs blacklisted; common scanner / brute-force source. |
| Domain | defence-procurement-portal[.]co[.]uk | 09 Jun 2026 | MEDIUM | Suspected MOD-themed phish landing. |
| Domain | linkedin-recruiter-verify[.]com | 08 Jun 2026 | MEDIUM | DPRK Sapphire-Sleet-style recruitment-lure landing. |
| IP | 185[.]220[.]101[.]1 | 12 Jun 2026 | HIGH | TorServers / Stiftung Erneuerbare Freiheit (DE, AS60729). IP Insights threat=critical, Tor exit node; defence-contractor estates should treat Tor egress as inherently suspect. |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Long-dwell espionage via edge-device compromise (Chinese tradecraft) | H | H | CRITICAL |
| Recruitment-process compromise via DPRK fake-recruiter lures | H | H | CRITICAL |
| Russia-nexus battlefield-technology IP exfiltration | M | H | HIGH |
| Iran-nexus destructive-impact campaign | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should prioritise (a) Cisco SD-WAN Manager netadmin role activity and configuration-push events; (b) Arista EOS decap-protocol-conflation; (c) NetScaler tampering and session-token reuse from non-standard geographies; (d) Fortinet FortiClient EMS admin-endpoint anomaly; (e) web-shell deployment patterns against edge appliances - hallmark Chinese tradecraft; (f) recruitment-lure-themed phish at the mail gateway with LinkedIn-redirector heuristics; (g) long-dwell low-volume exfiltration patterns against PLM, SharePoint and Confluence estates.
Defend
Preventive priorities follow Section 6: enforce mitigation-only postures for CVE-2026-20245 and CVE-2026-7473; patch FortiClient EMS to 7.4.2; apply Citrix NetScaler firmware; force Chromium update for CVE-2026-11645; force Defender MoCAMP roll-up. Verify router firmware levels and management-plane access controls in line with the NCSC APT28 router advisory. Run targeted awareness training against the DPRK fake-recruiter pattern with specific examples from the ESET / Mandiant 2026 reporting. Validate contractor-classified-track segregation controls (CDS, cross-domain solutions).
Disrupt
Disruption activity within client lawful authority should focus on: (i) sector coordination through the NCSC defence-contractor trust group and (where membership permits) the National Defense ISAC; (ii) takedown of recruitment-lure landings through registrar-abuse and LinkedIn trust-and-safety channels; (iii) deception deployment on PLM-themed honeypot domains; (iv) information sharing with US-CERT, NCSC and DCSA on Chinese, Russian and DPRK indicators.
10. Forward outlook
Looking forward to the next reporting period (13-19 Jun 2026), it is highly likely that China-, Russia- and DPRK-nexus activity against the UK defence industrial base will continue at the current tempo. It is likely that at least one defence-contractor estate will publicly disclose an incident traceable to one of the flagged CVEs. APT28 router-exploit pressure is highly likely to persist.
Trigger conditions that would prompt revision of this outlook include: (a) a UK defence-contractor primes publicly attributing a breach to NetScaler, SD-WAN Manager or Arista EOS exploitation; (b) NCSC advisory escalation against a named Chinese, Russian, DPRK or Iranian campaign; (c) DCSA / US-CERT TLP:CLEAR notification of a sector-wide campaign; (d) UK MOD or NCSC issuance of a defence-contractor-specific take-action notice. The principal intelligence gap is direct visibility into the NCSC / DCSA defence-contractor TLP:CLEAR traffic for the 06-12 Jun period.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports & advisories index, https://www.ncsc.gov.uk/section/keep-up-to-date/reports-advisories | A1 | |
| 2 | CISA Known Exploited Vulnerabilities Catalogue, additions of 02 / 03 / 09 Jun 2026, https://www.cisa.gov/known-exploited-vulnerabilities-catalog | A1 | |
| 3 | CISA Adds Three KEV (Arista EOS, Chromium V8, Cisco SD-WAN Manager), 09 Jun 2026, https://www.cisa.gov/news-events/alerts/2026/06/09/cisa-adds-three-known-exploited-vulnerabilities-catalog | A1 | |
| 4 | 'Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited - No Patch Available', Jun 2026 | The Hacker News | B2 |
| 5 | 'No Patch Planned for Exploited Arista EOS Vulnerability (CVE-2026-7473)', Jun 2026 | SecurityWeek | B2 |
| 6 | Fortinet FortiClient EMS CVE-2026-35616 in-the-wild exploitation confirmation, 02 Jun 2026 | watchTowr Labs | B2 |
| 7 | May 2026 ransomware retrospective (Qilin 97-101, TheGentlemen 70, Akira 64, DragonForce 32; 115 TB stolen) | BreachSense | B2 |
| 8 | 'The State of Ransomware - Q1 2026', https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/ | Check Point Research | B2 |
| 10 | IP Insights threat-assessment lookups (X-API-Key authenticated), https://www.ipinsights.io | A2 | |
| 11 | MITRE ATT&CK Enterprise framework v15, https://attack.mitre.org | A1 | |
| 12 | Cisco Security Advisory cisco-sa-sdwan-privesc-4uxFrdzx, Jun 2026 | A1 | |
| 13 | EOS tunnel decap protocol-type validation | Arista Security Advisory 0137 | A1 |
| 14 | NCSC advisory on APT28 router exploitation and DNS hijack, Jun 2026 | A1 | |
| 15 | Google / Mandiant 2026 defence industrial base reporting | B2 | |
| 16 | ESET APT Activity Report May 2026 | B2 | |
| 17 | CrowdStrike 2026 Global Threat Report | B2 | |
| 18 | US-CERT / NCSC joint advisories on DPRK financially-motivated activity | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Defence and government contractors threat intelligence report — 4–8 May 2026
The R&D and military / government-contractor threat picture for the reporting period continues to be dominated by sustained state-sponsored activity.
Defence and government contractors threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the R&D, military and government-contractor threat picture remained dominated by state-sponsored cyber-espionage against the defence industrial base.
Defence and government contractors threat intelligence report — 27 April – 3 May 2026
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.