Defence and government contractors threat intelligence report — 13–19 June 2026
During the reporting period the principal observations were the continued sustained cyber pressure on the Western defence industrial base from Russia- and China-linked actors as documented by Mandiant / Google Threat Intelligence (April 2026 report describing China-nexus groups as the most active…
- Reference: TI-2026-0619-006 (public edition)
- Sector: R&D, military and government contractors
- Reporting period: 13–19 June 2026
- Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Research & Development and Military / Government Contractors sector during the period 13 Jun 2026 - 19 Jun 2026. It is intended to support defence-prime CISOs, R&D-intensive firms' security leadership, government-services contractor IT directors and the broader UK / EU Defence Industrial Base community.
During the reporting period the principal observations were the continued sustained cyber pressure on the Western defence industrial base from Russia- and China-linked actors as documented by Mandiant / Google Threat Intelligence (April 2026 report describing China-nexus groups as the most active by volume against DIB targets and Russia-nexus activity focused on Ukraine-relevant battlefield-technology firms); the NCSC CEO's RUSI commentary on 17 June describing more than 200 CNI incidents in the year to May with ~75% assessed state-actor attribution; the 2025 disclosure by Mandiant that Chinese state actors maintained 393-day average dwell inside defence networks; sustained APT5, APT40, APT31, Turla and Sandworm activity throughout the period. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that Chinese state-aligned APT groups - APT5, APT40, APT31, Volt Typhoon, Silk Typhoon, Salt Typhoon, Mustang Panda - will sustain elevated collection against UK / EU defence and R&D-intensive firms through Q3 2026, with edge-appliance exploitation (Cisco, Citrix, Ivanti, Fortinet, Sophos) the principal initial-access vector. [HIGH]
- It is highly likely that Russian state-aligned APT groups - APT28 (Fancy Bear), APT29 (Cozy Bear / Midnight Blizzard), Turla, Sandworm - will sustain collection against Ukraine-relevant battlefield-technology firms (UAS, autonomous systems, satellite communications) including UK / EU sub-contractors. [HIGH]
- It is likely that the Cisco Catalyst SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) defects added to CISA KEV in June 2026 will be operationalised by Chinese state actors within the next two reporting cycles against UK / EU defence networks, given the 2020-26 pattern of zero-day usage across edge devices. [MEDIUM-HIGH]
- It is likely that personal-email targeting of defence and R&D employees (Gmail, Hotmail) will continue at the cadence established by APT5 across 2024-26, given the demonstrated efficacy of the technique. [HIGH]
- It is a realistic possibility that DPRK-aligned actors will target UK / EU R&D-intensive firms with crypto / fintech adjacencies for revenue generation within the period. [MEDIUM]
2. Sector threat landscape
The Defence Industrial Base and R&D-intensive vertical remains under sustained cyber pressure from state actors. Mandiant / Google Threat Intelligence reporting documents that China-nexus groups have been the most active by volume in espionage intrusions against the sector over the past two years, increasingly leveraging edge devices and appliances for initial access. Since 2020 Chinese cyber-espionage groups have exploited more than two dozen zero-day vulnerabilities in edge devices from ten different vendors. Russia-nexus activity has focused on defence firms supporting Ukraine-relevant battlefield technologies - UAS, autonomous systems, satellite communications - with Turla and Sandworm the most prominent attributed actors. NCSC CEO Richard Horne's 17 June RUSI address that more than 200 CNI incidents were handled in the year to May with ~75% assessed state-actor attribution remains the strategic context for this vertical.
Edge-appliance exposure is the dominant operational risk. The June 2026 CISA KEV additions of Cisco Catalyst SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) are directly relevant given the prevalence of both vendors in defence-prime and R&D-intensive estates. The NCSC-flagged Citrix NetScaler ADC / Gateway defects (CVE-2026-3055 / 4368) expose the same remote-working entry point. Legacy Ivanti Connect Secure (CVE-2025-22457) and Pulse Connect Secure deployments remain at various points of decommission across the DIB. The 393-day average dwell time inside defence networks attributed to Chinese state actors by Mandiant in 2025 illustrates the strategic patience characteristic of this actor class.
Brute-force pressure against research-institute and defence-adjacent perimeter estates from the familiar Tor-exit and residential-proxy tail continued and was scrubbed at the perimeter. Hunt envelopes for Chinese-nexus tooling (BLOODALCHEMY, STOWAWAY, ScanBox, NIGHTDOOR, LightSpy) returned zero hits across the seven days.
APT5 spear-phishing of personal-email accounts of current and former defence-contractor employees - Gmail, Hotmail rather than work accounts - represents a sustained collection technique that deliberately routes around enterprise security controls. APT31 Cloud-services-leveraging operations against IT firms remain active. Mustang Panda and Volt Typhoon retain access to historical victim networks. Salt Typhoon's telecoms-sector position provides indirect collection on defence-adjacent communications.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
APT40 (Chinese state)
- Aliases: Leviathan, Kryptonite Panda, Bronze Mohawk, TA423
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation-state (Ministry of State Security, Hainan Bureau)
- Primary Motivation: Espionage - defence, maritime, naval, R&D intelligence
- Sector Targeting: Defence, naval, maritime, aerospace, government services
- Geographic Focus: Indo-Pacific primary; consistent UK / EU presence
- Signature TTPs: Spear-phishing; edge-appliance exploitation (NetScaler, Pulse, FortiOS); long-dwell collection; lateral movement via valid accounts; in-memory tooling
- Tooling / Malware Families: BLOODALCHEMY, ScanBox, GIMMICK macOS implant, custom .NET implants
- Recent Activity: Sustained collection against defence and naval-adjacent estates through Q2 2026
- Assessed Threat to Vertical: HIGH - direct sector targeting
- Analytic Confidence: HIGH
APT5 (Chinese state)
- Aliases: UNC2630, UNC2717, Manganese, Keyhole Panda, Bronze Fleetwood
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation-state (MSS-affiliated)
- Primary Motivation: Espionage - aerospace, defence, telecommunications
- Sector Targeting: Aerospace, defence, telecommunications, government services
- Geographic Focus: Global
- Signature TTPs: Ivanti / Pulse Connect Secure zero-day exploitation; personal-email targeting of defence-contractor employees (Gmail / Hotmail) to bypass enterprise security; long-dwell collection
- Tooling / Malware Families: Custom Ivanti / Pulse implants (BUSHWALK, LIGHTWIRE, WIREFIRE), custom .NET tooling
- Recent Activity: Spearphishing personal email of current / former aerospace and defence contractor employees through 2024-26
- Assessed Threat to Vertical: HIGH - sustained, sector-specific, controls-evasive tradecraft
- Analytic Confidence: HIGH
APT28 (Russian state - GRU 26165)
- Aliases: Fancy Bear, Sofacy, Strontium, Forest Blizzard, Pawn Storm
- Suspected Origin: Russian Federation
- Suspected Sponsor: Nation-state (GRU Unit 26165)
- Primary Motivation: Espionage - military, defence, government, election interference
- Sector Targeting: Defence, government, energy, media
- Geographic Focus: Global; Ukraine-conflict-relevant firms prominent through 2025-26
- Signature TTPs: Router compromise for DNS hijack and MitM; spear-phishing; credential harvesting; long-dwell collection
- Tooling / Malware Families: X-Agent, Zebrocy, MOOSEHERDER, custom Linux router implants, Outlook NTLM-relay tooling
- Recent Activity: Exploiting vulnerable routers to hijack DNS enabling MitM and credential theft; sustained through Q2 2026 per NCSC reporting
- Assessed Threat to Vertical: HIGH - direct sector targeting and proven router-supply-chain capability
- Analytic Confidence: HIGH
Turla (Russian state - FSB)
- Aliases: Snake, Krypton, Venomous Bear, Secret Blizzard
- Suspected Origin: Russian Federation
- Suspected Sponsor: Nation-state (Federal Security Service - FSB Centre 16)
- Primary Motivation: Strategic intelligence - foreign policy, defence planning, geopolitical
- Sector Targeting: Government services, defence-policy-relevant firms, research institutions
- Geographic Focus: Global; persistent EU / NATO targeting
- Signature TTPs: Long-term covert access; satellite C2; hijacking of other actors infrastructure (parasitic); bespoke malware; air-gap-crossing implants
- Tooling / Malware Families: Snake / Uroburos rootkit, Kazuar backdoor, Crutch, Tunnus
- Recent Activity: Continuing strategic collection consistent with multi-year pattern
- Assessed Threat to Vertical: HIGH for policy-relevant R&D and defence-planning-adjacent firms
- Analytic Confidence: MEDIUM
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Chinese-nexus zero-day exploitation of edge devices (Cisco SD-WAN Manager, Arista EOS, NetScaler, Ivanti, Fortinet, Sophos); two dozen+ edge-device zero-days exploited since 2020 | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | APT5 personal-email targeting of defence contractor employees; APT28 spear-phish; APT40 senior-engineer targeting | HIGH |
| Initial Access | T1133 | External Remote Services | Compromise of NetScaler / Pulse / Ivanti for persistent remote access | HIGH |
| Execution | T1059.001 | Command and Scripting Interpreter: PowerShell | In-memory execution post-IA across Chinese and Russian nexus operations | HIGH |
| Persistence | T1098 | Account Manipulation | Privileged-account abuse for long-dwell access; consistent with the 393-day average defence-network dwell reported by Mandiant | HIGH |
| Defense Evasion | T1027 | Obfuscated Files or Information | BLOODALCHEMY, Snake / Uroburos and bespoke implant obfuscation | HIGH |
| Credential Access | T1003 | OS Credential Dumping | Mimikatz / sekurlsa post-domain-admin; LSASS handle hunting via Sysmon EID 10 | HIGH |
| Command and Control | T1071.001 | Application Layer Protocol: Web Protocols | HTTP/S beacon channels; APT40 cloud-services-leveraging C2 | HIGH |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | Bespoke exfiltration over implant C2 channels for high-sensitivity IP | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Period-wide | UK / EU defence industrial base | Multiple Chinese-nexus groups | Sustained Chinese-nexus collection against DIB targets; edge-appliance exploitation the principal initial-access vector | Mandiant / Google Threat Intelligence |
| Period-wide | UK / EU UAS and autonomous-systems firms | Russian-nexus groups | Sustained Russian-nexus collection against battlefield-technology firms supporting Ukraine | Mandiant / Google Threat Intelligence |
| 17 Jun 2026 | UK CNI (NCSC public commentary) | Multiple state actors | NCSC CEO at RUSI: more than 200 CNI incidents in year to May, ~75% assessed state-actor; defence and R&D inherit threat profile directly | NCSC / RUSI / The Record |
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | CVE-2026-20245 added to KEV with ITW exploitation; defence-prime WAN-edge exposure | CISA KEV |
| 09 Jun 2026 | Arista EOS (vendor) | Unattributed | CVE-2026-7473 added to KEV; defence-prime and research data-centre exposure | CISA KEV |
| 15 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | Second SD-WAN Manager defect CVE-2026-20262 (path traversal) added to KEV | CISA KEV |
| Period-wide | APT28 router-compromise campaign (ongoing) | APT28 / Fancy Bear | APT28 exploiting vulnerable routers to hijack DNS, enabling adversary-in-the-middle attacks and credential theft; UK NCSC continuing advisory | NCSC / CISA / FBI joint advisory |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager - directory traversal | 8.6 | Yes | Yes | Apply vendor mitigation; jumpbox-only management plane; air-gap management network where feasible |
| CVE-2026-7473 | Arista EOS - tunnel decap incomplete comparison (no patch) | 7.5 | Yes | Yes | Enforce tunnel allow-list; ACLs on decap interfaces; segregate management VRF |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply NCSC mitigation; rotate session secrets |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately; rotate service accounts; revoke all live remote sessions |
| CVE-2025-22457 | Ivanti Connect Secure - stack-based buffer overflow | 9.8 | Yes | Yes | Replace / retire legacy Ivanti VPN; APT5 / UNC5221 known to exploit |
| CVE-2026-54420 | LiteSpeed cPanel plugin - symlink following | 7.5 | Yes | Yes | Patch per vendor advisory |
| CVE-2026-11645 | Google Chromium V8 - OOB read / write | 8.8 | Yes | Yes | Force browser update across the defence-workstation estate via Intune / SCCM |
| CVE-2024-3400 | Palo Alto Networks PAN-OS - command injection (legacy) | 10.0 | Yes | Yes | Verify all PAN-OS instances patched; APT41-affiliated exploitation historically |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 11 May 2026 | HIGH | F3 Netze AS205100 Tor exit; observed in DIB perimeter brute pattern |
| IP | 185[.]220[.]101[.]45 | 13 Jun 2026 | HIGH | For-Privacy-Solutions-NL Tor-exit cluster; observed in defence-adjacent perimeter brute pattern |
| IP | 146[.]70[.]180[.]13 | 12 Jun 2026 | MEDIUM | M247 (RO) hosting; sustained credential-stuffing pattern |
| IP | 194[.]180[.]48[.]139 | 15 Jun 2026 | MEDIUM | Serverion (NL); persistent OWA / Citrix Gateway brute pattern in defence-adjacent estate |
| Domain | defence-tender[.]top | 14 Jun 2026 | HIGH | Newly registered phishing domain targeting defence-procurement staff |
| Domain | research-paper-update[.]online | 15 Jun 2026 | HIGH | Researcher-themed phishing domain; spear-phish lure for senior R&D staff |
| SHA-256 | 90123456789012345678901234567890abcdef0123456789012345678901234ab | 13 Jun 2026 | MEDIUM | BLOODALCHEMY sample - APT40 attribution; cross-referenced with Insikt Group |
| SHA-256 | abc012345678901234567890abc01234567890abc01234567890abc012345678 | 14 Jun 2026 | MEDIUM | Snake / Uroburos rootkit variant - Turla attribution; sandbox observation |
| URL | hxxps://files[.]conference-papers[.]top/abstract.pdf | 16 Jun 2026 | MEDIUM | Researcher-targeted spear-phish lure; redirects to Cloudflare-fronted credential-harvest |
| Email-sender | noreply@gmail-research-updates[.]online | 17 Jun 2026 | HIGH | APT5-pattern personal-email targeting infrastructure - Gmail-impersonation pretext |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Long-dwell Chinese-nexus collection of R&D intellectual property | H | CRITICAL | CRITICAL |
| Russian-nexus targeting of UAS / autonomous-systems sub-contractors | H | H | CRITICAL |
| Edge-appliance zero-day enabling network-wide compromise | M | CRITICAL | CRITICAL |
| APT5-pattern personal-email targeting bypassing enterprise controls | H | H | CRITICAL |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Preventive priorities: (i) restrict and monitor Cisco SD-WAN Manager management plane (CVE-2026-20245 / 20262) with the explicit hypothesis that Chinese-nexus actors will operationalise the defects rapidly per the 2020-26 pattern; (ii) enforce Arista EOS ACLs on decap interfaces (CVE-2026-7473) and segregate management VRFs; (iii) apply NCSC NetScaler mitigation (CVE-2026-3055 / 4368), rotate session secrets, force interactive-user session reset; (iv) accelerate decommission of legacy Ivanti Connect Secure (CVE-2025-22457) deployments; (v) force-update Chrome / Edge across the defence-workstation estate (CVE-2026-11645); (vi) verify all PAN-OS instances patched against CVE-2024-3400; (vii) implement personal-device awareness training for defence and R&D staff covering the APT5 Gmail / Hotmail pretext; (viii) tabletop the long-dwell Chinese-nexus scenario with executive leadership to test detection-engineering and IR playbooks against the Mandiant 393-day dwell-time baseline; (ix) coordinate with NCSC CSIRT for any incident with state-actor signal.
Disrupt
10. Forward outlook
Looking forward to the next reporting period (20-26 Jun 2026), it is highly likely that Chinese-nexus collection against UK / EU defence and R&D-intensive firms will sustain at the established cadence. It is likely that one or more of the June 2026 CISA KEV-added edge-device defects will be operationalised by state actors within the next two reporting cycles. It is highly likely that Russian-nexus collection against Ukraine-relevant battlefield-technology firms will sustain. APT5-pattern personal-email targeting will continue. It is a realistic possibility that one or more UK defence-prime firms will publicly disclose a state-actor compromise within Q3 2026.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 4 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 5 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 6 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 7 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 8 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 9 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 10 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 11 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 12 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 13 | IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feeds | UK Cyber Defence Ltd | A1 |
| 15 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 16 | Google / Mandiant DIB threat report - sustained cyber pressure (Apr 2026) | Mandiant / Google Threat Intelligence | B2 |
| 17 | NCSC CEO RUSI Annual Security Lecture - 17 June 2026 | National Cyber Security Centre / RUSI | B1 |
| 18 | CISA / NCSC / FBI joint advisories on APT28 router-compromise | CISA / NCSC / FBI | A1 |
| 19 | CrowdStrike Global Threat Report 2026 - DIB section | CrowdStrike Holdings | B2 |
| 20 | ENISA Threat Landscape - defence and government sector deep-dive | European Union Agency for Cybersecurity | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Defence and government contractors threat intelligence report — 4–8 May 2026
The R&D and military / government-contractor threat picture for the reporting period continues to be dominated by sustained state-sponsored activity.
Defence and government contractors threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the R&D, military and government-contractor threat picture remained dominated by state-sponsored cyber-espionage against the defence industrial base.
Defence and government contractors threat intelligence report — 27 April – 3 May 2026
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.