Defence and government contractors threat intelligence report — 20–26 June 2026
The collection picture this period is dominated by sustained state-aligned espionage activity (Salt Typhoon, Mustang Panda, APT28 and Screening Serpens all remain active), continued infostealer activity affecting contractor supply chains…
- Reference: TI-2026-0626-006 (public edition)
- Sector: R&D, military and government contractors
- Reporting period: 20–26 June 2026
- Issued: 26 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Research & Development and Military / Government Contractors sector during the period 20 Jun 2026 - 26 Jun 2026. It is intended to support contractor IT and security functions, security-cleared personnel handling export-controlled and OFFICIAL-SENSITIVE information, and the senior information risk owner, and is graded TLP:CLEAR. The collection picture this period is dominated by sustained state-aligned espionage activity (Salt Typhoon, Mustang Panda, APT28 and Screening Serpens all remain active), continued infostealer activity affecting contractor supply chains, and the edge-appliance exposure introduced by the 23 June Ubiquiti UniFi OS KEV addition.
IP Insights enrichment surfaced ten 'critical' or 'block' addresses in the perimeter scan tail. The DoD's June 10 infostealer report - documenting 11.1 million infostealer-compromised devices and 3.3 billion stolen credentials in 2025 - remains the most relevant strategic context for the supply-chain risk model.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that PRC state-aligned actors (Salt Typhoon, Mustang Panda and related clusters) will continue sustained intrusion campaigns against UK and EU R&D and government contractor networks through Q3 2026, consistent with multi-year tracking and 2026 vendor reporting (HIGH confidence).
- It is highly likely that Russian state-aligned actors (APT28 and related GRU clusters) will continue router and edge-appliance exploitation tradecraft against contractor edge networks and remote-worker CPE, consistent with current NCSC advisories (HIGH confidence).
- It is highly likely that the three Ubiquiti UniFi OS defects added to KEV on 23 June will be exploited against unpatched contractor branch and back-office UniFi deployments within the next 14 days, with state-aligned actors a plausible exploiter alongside criminal volume (HIGH confidence).
- It is highly likely that infostealer-derived credentials harvested from contractor-supplier estates will continue to feed valid-account-based intrusions against principal contractors through Q3 2026, consistent with the DoD's June 10 report (HIGH confidence).
- It is a realistic possibility that Iranian state-aligned activity (Screening Serpens cluster) will expand from regional targeting to UK or EU contractor networks within the next two reporting cycles, given the post-February 2026 escalation pattern documented by Unit 42 (MEDIUM confidence).
2. Sector threat landscape
The R&D and military / government contractors vertical sits at the intersection of state-aligned espionage targeting, criminal ransomware activity and supply-chain compromise risk. The collection picture for this period is dominated by sustained PRC and GRU state-aligned activity (Salt Typhoon and Mustang Panda for PRC; APT28 for GRU), the edge-appliance exposure introduced by the 23 June Ubiquiti UniFi OS KEV addition, and the structural supply-chain compromise risk highlighted by the DoD's June 10 infostealer report.
Salt Typhoon (PRC) continues sustained operations against telecommunications, ISP and lawful-intercept infrastructure with downstream relevance to defence and intelligence contractor connectivity. Mustang Panda (PRC) continues targeting of NGOs, think-tanks, trade bodies and defence-adjacent professional services with PlugX, ToneShell and Korplug deployments. APT28 (GRU) continues router and edge-appliance exploitation per the current NCSC advisory; remote-worker CPE and SOHO routers remain a particular concern for contractor staff working from home.
Iranian state-aligned activity (Screening Serpens cluster) has increased operations since the February 2026 regional escalation, deploying two new RAT variants across entities in up to five countries per Unit 42's tracking. While currently regionally focused, the cluster's expansion pattern suggests UK and EU contractor networks could see targeting within Q3-Q4 2026, particularly where the contractor work involves Middle East programmes, sanctions enforcement or defence-export activity.
Supply-chain compromise risk remains structural. The DoD's June 10 infostealer report - 11.1 million compromised devices and 3.3 billion stolen credentials in 2025 - documents the scale of credential exposure across contractor supplier estates. MSP and BPO supplier compromise continues to be a major vector. Ransomware activity from Qilin, Akira and LockBit 5.0 has touched contractor-adjacent organisations during 2026 and supply-chain blast-radius remains a credible escalation path.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Salt Typhoon (PRC)
- Aliases: Salt Typhoon, GhostEmperor, Earth Estries, FamousSparrow overlap
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation-state (MSS)
- Primary Motivation: Espionage, lawful-intercept system access, telecommunications intelligence
- Sector Targeting: Telecommunications, government, defence contractors, research institutions, legal services with state-client work
- Geographic Focus: Five-Eyes primary; EU, JP, SEA secondary
- Signature TTPs: Edge-appliance and router exploitation; valid-account abuse; long-dwell-time intrusion; living-off-the-land binaries
- Tooling / Malware Families: GhostSpider, Demodex rootkit, custom POSIX implants
- Recent Activity: Sustained 2026 operations; reporting consistent with continued telco / ISP infrastructure access
- Assessed Threat to Vertical: HIGH for R&D and gov contractor verticals
- Analytic Confidence: HIGH
APT28 / Fancy Bear (GRU)
- Aliases: APT28, Fancy Bear, Sofacy, Strontium, Forest Blizzard, GRU Unit 26165
- Suspected Origin: Russian Federation
- Suspected Sponsor: Nation-state (GRU)
- Primary Motivation: Espionage, influence operations, strategic intelligence collection
- Sector Targeting: Government, defence contractors, R&D, NGOs, trade bodies, legal services with state-adjacent work
- Geographic Focus: NATO and partner states primary
- Signature TTPs: Router and edge-appliance exploitation for DNS hijack; spear-phishing of credentialed staff; AiTM token theft; ongoing exploitation of Outlook / Exchange
- Tooling / Malware Families: X-Agent, X-Tunnel, GooseEgg, Headlace, JaguarTooth
- Recent Activity: NCSC advisory on continued APT28 router exploitation and DNS hijack tradecraft remains current
- Assessed Threat to Vertical: HIGH for R&D, gov contractor, trade-body verticals
- Analytic Confidence: HIGH
Mustang Panda (PRC)
- Aliases: Mustang Panda, Bronze President, RedDelta, TA416, HoneyMyte
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation-state (MSS-aligned)
- Primary Motivation: Espionage, influence collection on diaspora and NGO targets
- Sector Targeting: Government, NGOs, think-tanks, trade bodies, defence contractors, R&D
- Geographic Focus: Global, with sustained EU and SEA operations
- Signature TTPs: Spear-phishing with weaponised LNK / ISO containers; PlugX deployment; long-dwell-time operations against policy-influence targets
- Tooling / Malware Families: PlugX, ToneShell, Korplug, ClaimLoader
- Recent Activity: Sustained 2026 operations against trade bodies and NGOs documented in vendor reporting
- Assessed Threat to Vertical: HIGH for trade bodies and R&D
- Analytic Confidence: HIGH
Screening Serpens (Iran)
- Aliases: Screening Serpens, MuddyWater overlap, CharmingKitten overlap
- Suspected Origin: Islamic Republic of Iran
- Suspected Sponsor: Nation-state (assessed IRGC-aligned)
- Primary Motivation: Espionage, regional collection, retaliatory positioning
- Sector Targeting: Government contractors, defence, R&D, maritime, energy
- Geographic Focus: Middle East primary; expanding EU / UK
- Signature TTPs: Spear-phishing with credential harvest; deployment of custom RAT families; ongoing positioning against regional adversaries
- Tooling / Malware Families: Two new RAT variants documented by Unit 42 in 2026, MuddyWater-style scripting toolkits
- Recent Activity: Increased operations since February 2026 regional conflict; activity across up to five countries (Unit 42)
- Assessed Threat to Vertical: MEDIUM-HIGH for R&D and government contractor verticals
- Analytic Confidence: MEDIUM
LockBit 5.0
- Aliases: LockBit, LockBit Black, LockBit Green, LockBit 5.0 (Aug 2025 relaunch)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Financial services, healthcare, manufacturing, government contractors, legal services
- Geographic Focus: Global; consistent UK / EU / NA volume
- Signature TTPs: Initial access via exposed RDP, public-facing exploits, valid accounts; ESXi-specific encryptor build; double-extortion via leak site
- Tooling / Malware Families: LockBit 5.0 encryptor (Win/Linux/ESXi variants), StealBit exfiltrator, Cobalt Strike, Mimikatz
- Recent Activity: Continuing 2026 leak-site activity post-relaunch; selective targeting of FS, legal and contractor sub-verticals
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: MEDIUM-HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Anticipated mass-exploitation of Ubiquiti UniFi OS chain at contractor branch / back-office edge; sustained APT28 router exploitation against remote-worker CPE | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | Mustang Panda PlugX deployment via weaponised LNK / ISO containers; Screening Serpens credential-harvest lures to credentialed staff | HIGH |
| Initial Access | T1078 | Valid Accounts | Reuse of infostealer-harvested credentials from supplier-estate compromises; APT28 valid-account abuse post-router-compromise | HIGH |
| Initial Access | T1133 | External Remote Services | Salt Typhoon abuse of telecommunications / ISP infrastructure for downstream access; relevant to contractor connectivity | MEDIUM |
| Persistence | T1505.003 | Server Software Component: Web Shell | Edge-appliance web-shell deployment post-exploitation; sustained PRC state-aligned tradecraft | HIGH |
| Defense Evasion | T1070.004 | File Deletion | Anti-forensic clean-up consistent with sustained state-aligned tradecraft | MEDIUM |
| Credential Access | T1555.003 | Credentials from Web Browsers | Infostealer harvest of browser-stored credentials per DoD report; subsequent feeding into intrusion chains | HIGH |
| Discovery | T1018 | Remote System Discovery | Long-dwell-time network mapping by PRC and GRU clusters in contractor environments | HIGH |
| Collection | T1005 | Data from Local System | Bulk staging of R&D, design and export-controlled documents for slow exfiltration | HIGH |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | Low-and-slow exfiltration over established C2 to evade DLP and proxy-based controls | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 23 Jun 2026 | Ubiquiti UniFi OS Server (vendor) | Unattributed | Three CVEs added to CISA KEV; contractor branch / back-office / remote-worker CPE estates with UniFi hardware in scope | CISA KEV / Bishop Fox PoC |
| 23 Jun 2026 | Lantronix EDS5000 (vendor) | Unattributed | CVE-2025-67038 added to KEV; relevant to contractor OT / facility-management estates and to defence-test-range serial-to-IP bridges | CISA KEV / Lantronix |
| Continuing | Salt Typhoon telco / ISP campaigns | Salt Typhoon (PRC) | Multi-year sustained access to telco lawful-intercept infrastructure documented; downstream contractor relevance | Microsoft / Mandiant / CrowdStrike |
| Continuing | APT28 router exploitation campaign | APT28 / GRU Unit 26165 | Current NCSC advisory remains valid; remote-worker CPE and SOHO routers under sustained DNS-hijack and credential-theft targeting | NCSC |
| Continuing | Mustang Panda NGO and trade-body targeting | Mustang Panda (PRC) | PlugX, ToneShell, Korplug deployments against policy-influence targets; defence-adjacent professional services in scope | Microsoft / Mandiant |
| Continuing | Screening Serpens regional escalation | Iran-nexus IRGC-aligned | Increased operations since February 2026; two new RAT variants across up to five countries | Palo Alto Unit 42 |
| 10 Jun 2026 | DoD infostealer report (cross-cutting) | Multiple commodity actors | Report documents 11.1 million infostealer-compromised devices and 3.3 billion stolen credentials in 2025; structural contractor-supplier-chain risk | National Defense Magazine |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8 immediately per CISA BOD 26-04 (due 26 Jun 2026); audit management plane exposure |
| CVE-2026-34909 | Ubiquiti UniFi OS Server < 5.0.8 - path traversal | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; restrict management plane to dedicated VLAN; review for file-system access anomalies |
| CVE-2026-34910 | Ubiquiti UniFi OS Server < 5.0.8 - improper input validation (chains to root RCE) | 10.0 | Yes | Yes | Patch immediately - Bishop Fox PoC chains the three UniFi defects to unauthenticated root RCE |
| CVE-2025-67038 | Lantronix EDS5000 Device Server - HTTP RPC command injection (root) | 9.8 | Yes | Yes | Apply Lantronix firmware update; remove internet exposure; segregate serial-to-IP devices to OT zone |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command injection | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; apply vendor mitigation; monitor for CLI abuse |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager - directory traversal | 8.6 | Yes | Yes | Apply vendor mitigation; restrict management plane to jumpbox-only; monitor file-system access patterns |
| CVE-2026-7473 | Arista EOS - tunnel decap incomplete comparison (mitigation only) | 7.5 | Yes | Yes | Enforce tunnel allow-list; deploy ACLs on decap interfaces; harden BGP / OSPF authentication |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply Citrix advisory; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately per NCSC; rotate gateway service accounts; force session reset for all interactive users |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read / write | 8.8 | Yes | Yes | Force Chrome / Edge update across workstation estate via Intune / SCCM; verify against KEV due-date |
| CVE-2025-48595 | Android Framework - integer overflow leading to local privilege escalation | 7.8 | Yes | Yes | Push June 2026 Android security patch via MDM; require minimum patch level on BYOD enrolments |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 21 Jun 2026 | HIGH | F3 Netze AS205100 Tor exit (DE); IP Insights threat score 100 / critical; observed in EmilyAI-tagged perimeter brute-force tail this period |
| IP | 92[.]118[.]39[.]95 | 23 Jun 2026 | HIGH | UNMANAGED LTD (AS47890, GB-registered); IP Insights critical / suggest=block; appears in SSH and OWA brute-force tail |
| IP | 80[.]94[.]95[.]115 | 24 Jun 2026 | HIGH | SS-Net (RO) AS204428; IP Insights critical / suggest=block; sustained mass-scan against management plane endpoints |
| IP | 134[.]122[.]114[.]42 | 23 Jun 2026 | MEDIUM | DigitalOcean droplet IP; IP Insights critical / suggest=block; pattern-matches NetScaler probe traffic |
| IP | 198[.]235[.]24[.]31 | 20 Jun 2026 | MEDIUM | Google Cloud Platform US (AS396982); IP Insights critical / suggest=block; aggressive web-scan against client portals |
| IP | 162[.]142[.]125[.]34 | 25 Jun 2026 | LOW | Censys research scanner; benign but high-volume - exclude from alerting via known-scanner allow-list to reduce noise |
| IP | 64[.]227[.]107[.]117 | 24 Jun 2026 | MEDIUM | DigitalOcean droplet; IP Insights suggest=block; new this period - submitted to ipinsights.io reciprocal feed via EmilyAI |
| IP | 152[.]32[.]143[.]49 | 22 Jun 2026 | MEDIUM | UCloud HK (AS135377) hosting / datacenter, NG geolocation; observed in SaaS-tenant credential-stuffing tail |
| IP | 146[.]70[.]180[.]13 | 21 Jun 2026 | MEDIUM | M247 (RO) hosting; persistent credential-stuffing pattern against public-facing portals across multiple verticals |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| PRC state-aligned long-dwell-time intrusion against principal contractor with R&D data exfiltration | M | H | HIGH |
| APT28 router exploitation against remote-worker CPE leading to credential theft and downstream tenant access | H | H | CRITICAL |
| Ubiquiti UniFi OS chain exploitation at contractor branch as criminal ransomware initial-access vector | H | H | CRITICAL |
| Infostealer-harvested credential reuse enabling valid-account intrusion via supplier estate | H | H | CRITICAL |
| Iranian state-aligned targeting of UK contractor with Middle East programme exposure | M | M | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat the Ubiquiti UniFi OS chain, APT28 router-exploitation tradecraft, Mustang Panda PlugX patterns and infostealer-credential-reuse indicators as the principal hunting hypotheses for this period. Hunt actively for low-and-slow exfiltration patterns and for web-shell artefacts on edge appliances.
Defend
Preventive priorities follow Section 6 directly. Ubiquiti UniFi OS 5.0.8 patch must be applied across the contractor estate by 26 June to meet CISA BOD 26-04. The Cisco SD-WAN Manager and Arista EOS prior-period defects remain mitigation-only and require sustained ACL and netadmin-role discipline. For APT28 router-exploitation exposure, audit remote-worker CPE estates against NCSC current router-hardening guidance and replace unsupported SOHO router hardware where remote-worker traffic carries credentialed access. For infostealer-credential-reuse risk, enforce mandatory password rotation on any account flagged by HaveIBeenPwned, BreachAlert or supplier-estate infostealer reporting and enforce phishing-resistant authentication (FIDO2 / WebAuthn) for privileged R&D and export-controlled access. Apply DSPT / NIS2 / CMMC / DEFCON 658 / 705 compliance-aligned hardening per applicable regulatory regime. Maintain immutable, off-premises backups of all R&D and export-controlled material.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the Defence Cyber Protection Partnership (DCPP), the NCSC CiSP contractor and CNI communities, and the relevant national-authority indicator exchange, with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) coordination with NCSC on the APT28 router-exploitation campaign and the Ubiquiti UniFi OS chain across contractor supply chains; (iii) takedown coordination via NCSC ACD for contractor-brand-themed phishing infrastructure; (iv) coordination with the MoD JSyCC, Defence Equipment & Support and the relevant export-control authority on incident notification thresholds; (v) submission of observed state-aligned indicators to NCSC Early Warning, MISP communities and ipinsights.io.
10. Forward outlook
Looking forward to the next reporting period (27 Jun - 03 Jul 2026), it is likely that at least one UK or EU R&D or contractor organisation will publicly disclose an incident traceable to one of the Ubiquiti UniFi OS chain, Cisco SD-WAN Manager, Arista EOS or APT28 router-exploitation patterns in Section 6. Sustained state-aligned activity from Salt Typhoon, Mustang Panda and APT28 is highly likely to continue. The Screening Serpens cluster's geographical scope is likely to expand further during Q3 2026.
Trigger conditions that would prompt revision of this outlook include: (a) NCSC, FBI or partner attribution of a fresh PRC or GRU campaign specifically targeting UK contractor networks, which would warrant immediate out-of-cycle reporting; (b) emergence of evidence linking Screening Serpens to a successful UK or EU contractor intrusion, which would elevate the Iranian threat from MEDIUM to HIGH; (c) a publicly attributed APT28 router-exploitation incident affecting remote-worker CPE that touches a UK contractor's privileged access, which would trigger an emergency SOHO router-replacement advisory; (d) a sector-impacting infostealer disclosure naming UK contractor staff, which would trigger immediate password-rotation and FIDO2 step-up enforcement. The principal intelligence gap remains visibility into peer-contractor incident telemetry across non-CDS supply chains.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | CISA Alert: Three Ubiquiti UniFi OS Flaws Added to KEV (23 Jun 2026) | CISA | A1 |
| 4 | CISA Alert: CVE-2025-67038 Lantronix EDS5000 added to KEV (23 Jun 2026) | CISA | A1 |
| 5 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 6 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 7 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 8 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 9 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 10 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 11 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 12 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 13 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 14 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 15 | IP Insights (ipinsights.io) IP enrichment, blocklists and STIX 2.1 feed | UK Cyber Defence Ltd | A1 |
| 17 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 18 | NCSC advisory: APT28 router exploitation and DNS hijack (current) | National Cyber Security Centre | A1 |
| 19 | DCPP (Defence Cyber Protection Partnership) advisories and indicator exchange (Week 26, 2026) | MoD / DCPP | A1 |
| 20 | Microsoft Threat Intelligence Salt Typhoon tracking (2026) | Microsoft Corporation | B2 |
| 21 | Mandiant / Google Threat Intelligence on PRC defence-supplier intrusions (Jun 2026) | Google / Mandiant | B2 |
| 22 | National Defense Magazine: DoD infostealer report (10 Jun 2026) | National Defense Magazine | B2 |
| 23 | Palo Alto Unit 42 Screening Serpens tracking (Jun 2026) | Palo Alto Networks Unit 42 | B2 |
| 24 | CrowdStrike Adversary Universe China and Russia updates (2026) | CrowdStrike Holdings | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Defence and government contractors threat intelligence report — 4–8 May 2026
The R&D and military / government-contractor threat picture for the reporting period continues to be dominated by sustained state-sponsored activity.
Defence and government contractors threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the R&D, military and government-contractor threat picture remained dominated by state-sponsored cyber-espionage against the defence industrial base.
Defence and government contractors threat intelligence report — 27 April – 3 May 2026
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.