Defence and government contractors threat intelligence report — 27 June – 3 July 2026
Coverage this period is dominated by the CISA KEV addition of CVE-2026-45659 - a significant risk given the prevalence of SharePoint in classified-adjacent document management - and by continuing PRC state-sponsored activity attributable to Salt Typhoon and Volt Typhoon.
- Reference: TI-2026-0703-006 (public edition)
- Sector: R&D, military and government contractors
- Reporting period: 27 June – 3 July 2026
- Issued: 3 July 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Research and Development, Military and Government Contractor sector during the period 27 Jun 2026 - 03 Jul 2026. It is intended to support operational defenders and risk owners in defence primes, tier-1 and tier-2 defence suppliers, MoD-adjacent research organisations, dual-use technology firms and Government contractors and is graded TLP:CLEAR. Coverage this period is dominated by the CISA KEV addition of CVE-2026-45659 - a significant risk given the prevalence of SharePoint in classified-adjacent document management - and by continuing PRC state-sponsored activity attributable to Salt Typhoon and Volt Typhoon.
The perimeter tail is dominated by IP Insights critical-scored Tor and bulletproof hosting, with sustained password-spray volumes against Entra ID and VPN sign-in endpoints.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that CVE-2026-45659 will be a priority exploitation target for state-sponsored actors against defence and R&D estates within the next 14 days, given the CISA KEV timeline and the intelligence value of SharePoint repositories in this vertical (HIGH confidence).
- It is highly likely that Salt Typhoon (China) will continue targeting telecommunications, defence contractors and government agencies through Q3 2026, consistent with the sustained CISA / NCSC / NSA joint advisory campaign under AA25-239A (HIGH confidence).
- It is likely that Volt Typhoon pre-positioning activity against UK / EU / US critical national infrastructure will continue at low volume but strategic significance through the reporting horizon (MEDIUM-HIGH confidence).
- It is likely that Iranian and DPRK cyber activity against UK defence and dual-use targets will remain at current volumes, consistent with recent NCSC public advisories on Middle-East-adjacent activity (MEDIUM-HIGH confidence).
- It is a realistic possibility that a supply-chain compromise of a defence-adjacent software vendor will be publicly disclosed during Q3 2026, consistent with historical PRC operating patterns (MEDIUM confidence).
2. Sector threat landscape
The R&D, military and government contractor vertical sits at the intersection of commercial IT and national-security-sensitive workflows, with attack surface that includes corporate SharePoint / M365, VPN and remote-access gateways, engineering CAD / PLM environments, and (in some estates) genuinely classified enclaves. The collection picture for the period is dominated by PRC state-sponsored activity, sustained ransomware pressure against defence-adjacent SMEs, and the CISA KEV addition of CVE-2026-45659.
CVE-2026-45659 is operationally significant for R&D and defence. Successful exploitation would give an authenticated attacker RCE on the SharePoint server, with downstream access to any document held there. In an intelligence-collection context this is high-value: contract award data, subcontractor mapping, technology roadmaps and IRAD programme documentation are all typical SharePoint holdings that are directly of interest to state adversaries.
Salt Typhoon activity remains the highest-signal state-sponsored threat during the period. Its confirmed victim set includes government agencies, defence contractors, technology companies, consulting firms, chemical manufacturers, transportation providers, hospitality businesses and non-profits per the AA25-239A joint advisory. Its typical initial-access vector is exploitation of edge-device and collaboration-platform vulnerabilities - Ivanti, SharePoint, Fortinet - which places CVE-2026-45659 directly in its exploitation set. Volt Typhoon's pre-positioning activity against CNI continues in parallel with lower operational tempo but higher strategic significance.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Salt Typhoon (PRC)
- Aliases: OPERATOR PANDA, RedMike, UNC5807, GhostEmperor, FamousSparrow, Earth Estries
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation state (Ministry of State Security)
- Primary Motivation: Espionage, intelligence collection, positional advantage
- Sector Targeting: Telecoms, defence contractors, government, technology, consulting, chemical, transportation, hospitality, non-profit
- Geographic Focus: Global with heavy Western / Five Eyes focus
- Signature TTPs: Edge device exploitation (Ivanti, SharePoint, Fortinet), stolen valid credentials, LOLBins, long-dwell persistence, careful lateral movement, exfiltration via legitimate cloud services
- Tooling / Malware Families: GhostEmperor rootkit, SnappyBee, ShadowPad, PlugX, custom loaders, LOLBins
- Recent Activity: Continuing AA25-239A campaign; Army National Guard breach exposed admin credentials and network diagrams per DHS reporting
- Assessed Threat to Vertical: HIGH - primary state-sponsored threat to R&D / defence vertical
- Analytic Confidence: HIGH
Volt Typhoon (PRC)
- Aliases: BRONZE SILHOUETTE, Vanguard Panda, DEV-0391
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation state (MSS)
- Primary Motivation: Pre-positioning for disruptive attack against CNI
- Sector Targeting: Communications, energy, transportation, water; defence contractor adjacency
- Geographic Focus: US, Five Eyes and allied nations
- Signature TTPs: LOLBins, stolen valid credentials, SOHO router exploitation, prolonged persistence with minimal on-endpoint tooling, long dwell
- Tooling / Malware Families: Minimal - reliance on native binaries and stolen credentials
- Recent Activity: Continued CISA / NCSC joint advisory pressure; c. one-year US grid dwell time referenced in recent public reporting
- Assessed Threat to Vertical: MEDIUM-HIGH - lower operational tempo, strategic significance
- Analytic Confidence: MEDIUM
APT28 (Fancy Bear, GRU)
- Aliases: Fancy Bear, Sofacy, STRONTIUM, Forest Blizzard, BlueDelta
- Suspected Origin: Russian Federation
- Suspected Sponsor: Nation state (GRU 26165)
- Primary Motivation: Espionage, intelligence collection, occasional disruption
- Sector Targeting: Government, defence, defence contractors, aerospace, media, dissident targeting
- Geographic Focus: US, EU, UK, Ukraine, wider NATO
- Signature TTPs: Router exploitation (Cisco IOS XE, Fortinet), credential harvest, targeted spearphishing, Outlook / Exchange abuse, OAuth token theft
- Tooling / Malware Families: X-Agent, Zebrocy, Cannon, GreyEnergy, various custom loaders
- Recent Activity: Continuing NCSC public advisories on Middle-East-adjacent GRU activity; router-hijack DNS activity referenced by NCSC
- Assessed Threat to Vertical: HIGH - persistent, well-resourced threat to defence vertical
- Analytic Confidence: HIGH
APT35 (Charming Kitten, IRGC)
- Aliases: Charming Kitten, Phosphorus, Mint Sandstorm, TA453, APT42
- Suspected Origin: Islamic Republic of Iran
- Suspected Sponsor: Nation state (IRGC)
- Primary Motivation: Espionage against defence, policy, academia
- Sector Targeting: Defence, aerospace, academia, journalism, policy institutes, dissidents
- Geographic Focus: US, UK, EU, Israel, wider anti-Iran policy sphere
- Signature TTPs: Sophisticated spearphishing (long-conversation lures, credential-harvest via fake conference and academic pretexts), OAuth token theft, cloud-first pivoting
- Tooling / Malware Families: GhostEcho, BellaCiao, custom loaders, credential-harvest kits
- Recent Activity: Continued targeting under NCSC public advisory on Middle-East-conflict-adjacent activity
- Assessed Threat to Vertical: MEDIUM-HIGH - persistent threat to defence policy / research staff
- Analytic Confidence: MEDIUM
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1566.001 | Spearphishing Attachment | Malicious ISO / IMG / OneNote attachments delivering IcedID, Latrodectus and DarkGate loaders continued to dominate the phishing tail this period; volume steady week-on-week per Proofpoint and Sophos | HIGH |
| Initial Access | T1078.004 | Cloud Accounts | OAuth token replay and refresh-token abuse against Microsoft 365 tenants; credential-stuffing tail from Tor exits and bulletproof ranges | MEDIUM |
| Persistence | T1053.005 | Scheduled Task/Job | Post-exploitation scheduled-task creation observed in Akira intrusions, particularly on domain controllers immediately following DCSync activity | MEDIUM |
| Discovery | T1046 | Network Service Discovery | Automated port sweeps from datacentre-hosted infrastructure - IP Insights flagged multiple AS135771 and AS14061 sources in the perimeter tail | MEDIUM |
| Command and Control | T1071.001 | Web Protocols | Cobalt Strike, Sliver and Havoc HTTPS C2 beaconing observed in incident retrospectives from FS-ISAC and H-ISAC partners this period; JARM / JA3 fingerprint hunts remain the primary detection | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone-to-Mega and rclone-to-MEGAsync exfiltration patterns dominant in Qilin double-extortion intrusions; Akira favours MEGA and Backblaze B2 | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Qilin, Akira and DragonForce ransomware deployment observed against sector-adjacent peers this period per ransomware.live and FS-ISAC / H-ISAC reporting | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 01 Jul 2026 | Microsoft SharePoint Server (vendor) | Unattributed publicly; likely PRC state-sponsored exploitation | CVE-2026-45659 KEV entry; direct exploitation target for Salt Typhoon and adjacent PRC clusters | CISA KEV / Microsoft / IT Pro July rundown |
| Ongoing | Army National Guard (US) | Salt Typhoon | DHS reporting of Salt Typhoon breach exposing admin credentials and network diagrams | DHS / Industrial Cyber reporting |
| Ongoing | Multiple US telecommunications carriers | Salt Typhoon | Continuing AA25-239A campaign impact; relevant to UK defence contractors given telecommunications-supply-chain adjacency | CISA / Congressional Research Service / House Oversight testimony |
| Ongoing | US electric grid (long-tail) | Volt Typhoon | c. one-year dwell time referenced in recent public reporting | CISA / NCSC joint advisory follow-through |
| Continuing | NCSC Middle-East cyber alert (UK) | IRGC / GRU-adjacent | NCSC continuing to advise UK organisations to review cyber posture in response to Middle-East geopolitical activity | NCSC public advisory |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-45659 | Microsoft SharePoint Server SubEd / 2019 / 2016 - deserialisation RCE | 8.8 | Yes | Yes | Patch immediately per CISA KEV entry 01 Jul 2026, remediation deadline 04 Jul 2026; audit Site Member permissions; restrict inbound SharePoint /_layouts and /_vti_bin paths at the WAF; hunt w3wp.exe child processes |
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; BOD 26-04 deadline 26 Jun 2026 has passed; restrict management plane to dedicated VLAN |
| CVE-2026-34909 | Ubiquiti UniFi OS Server - path traversal | 9.8 | Yes | Yes | As per -34908; component of the Bishop Fox unauthenticated root RCE chain |
| CVE-2026-34910 | Ubiquiti UniFi OS Server - improper input validation | 9.8 | Yes | Yes | As per -34908; component of the Bishop Fox unauthenticated root RCE chain |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory overread (CitrixBleed 3) | 9.3 | Yes | Yes | Fixed builds 14.1-66.59, 13.1-62.23, 13.1-37.262 FIPS/NDcPP; must run 'kill icaconnection -all', 'kill pcoipConnection -all', 'kill aaa session -all' post-patch |
| CVE-2026-4368 | Citrix NetScaler Gateway / AAA vserver - race condition | 7.7 | Yes | Yes | Applied by the same patches as -3055; session mix-up risk against Gateway and AAA virtual servers |
| CVE-2025-67038 | Lantronix EDS5000 serial-to-IP bridge - command injection | 9.6 | Yes | Suspected | Vendor patch pending; segment device management to dedicated OT VLAN |
| CVE-2026-50751 | Check Point Security Gateway - improper authentication | 9.8 | Yes | Yes | Apply Check Point R81.20 / R81.10 / R80.40 hotfixes; hunt admin sessions from non-management source addresses |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - authenticated RCE | 8.4 | Yes | Suspected | Cisco fixed release train; disable public-facing vManage where feasible |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]101[.]34 | 28 Jun 2026 | HIGH | for-privacy.net Tor exit; IP Insights score 100 / critical; 8 blacklists; observed in credential-spray tail against Entra ID sign-in endpoints |
| IP | 194[.]180[.]48[.]18 | 30 Jun 2026 | HIGH | serverion (NL); IP Insights score 85 / critical; 2 active + 3 degraded blacklists; observed in SSH brute-force tail against perimeter jump hosts |
| IP | 141[.]98[.]11[.]90 | 02 Jul 2026 | MEDIUM | UAB Host Baltic AS209605 (LT); IP Insights score 10 / low but datacentre-flagged; source of scripted OAuth token replay against Microsoft 365 |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| SharePoint (CVE-2026-45659) targeted exploitation by state-sponsored actors | H | H | CRITICAL |
| Salt Typhoon intrusion into defence prime or tier-1 supplier | M | H | HIGH |
| Volt Typhoon pre-positioning into UK CNI defence-adjacent estate | L | H | MEDIUM |
| Ransomware deployment via CitrixBleed 3 against defence SME | M | H | HIGH |
| Supply-chain compromise of defence-adjacent software vendor | M | H | HIGH |
| IRGC / GRU spearphishing of defence policy / research staff | M | H | HIGH |
| Insider or credential-harvest compromise via long-dwell OAuth token abuse | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat CVE-2026-45659 as the principal hunting hypothesis for the next reporting cycle, with an assumption that state-sponsored exploitation will precede volume criminal exploitation. Deploy w3wp.exe child-process hunts and ULS deserialisation exception rules. Extend hunts to Salt Typhoon-specific patterns: unexpected management-agent activity on edge devices, LOLBin execution chains on SharePoint / IIS hosts, and unexpected M365 admin activity on defence-adjacent tenants. Deploy long-dwell detection heuristics: OAuth token issuance to unusual client-app IDs, refresh-token abuse against defence-relevant mailboxes, and anomalous PIM / Global Admin activation.
Defend
Preventive priorities follow Section 6 directly. SharePoint patching must be applied to meet the CISA KEV 04 Jul deadline as an absolute floor - defence estates should prioritise this above other work. Complete NetScaler patching and session-invalidation. Deploy phishing-resistant MFA (FIDO2, hardware token) on all IT-admin, defence-project and senior-officer accounts. Enforce Conditional Access rules limiting sensitive session issuance to compliant / hybrid-joined devices only. Baseline network segmentation between corporate IT, engineering / CAD environments, and any classified enclave. Verify SOHO router estate posture for remote workers - Volt Typhoon's exploitation of small-office routers is a documented pattern.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the Defence Cyber Protection Partnership (DCPP) indicator exchange and NCSC CiSP under the defence and government-contractor vertical, with this week's IP Insights critical / block tail contributed; (ii) intelligence-sharing under the joint AA25-239A framework where the client is a Salt Typhoon-relevant target; (iii) coordinated response with MoD cyber teams for any confirmed state-sponsored intrusion; (iv) participation in DCPP and NCSC-facilitated tabletop exercises for state-sponsored incident-response playbook validation.
10. Forward outlook
Looking forward to the next reporting period (04 Jul - 10 Jul 2026), it is likely that Salt Typhoon exploitation of CVE-2026-45659 against defence and government targets will begin within the reporting window, given the strategic value of the vulnerability set. Volt Typhoon activity is expected to remain at low operational tempo but continuing strategic significance. IRGC and GRU spearphishing volumes against defence targets are expected to remain steady or slightly elevated given the ongoing Middle-East geopolitical context.
Trigger conditions that would prompt revision of this outlook include: (a) any publicly-disclosed defence or government-contractor SharePoint incident; (b) any confirmed Salt Typhoon or Volt Typhoon intrusion against a UK defence prime or tier-1 supplier, which would warrant immediate out-of-cycle advisory; (c) any significant Middle-East geopolitical escalation increasing the IRGC / GRU threat picture; (d) further CISA / NCSC joint advisories under the AA25-239A framework.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities catalogue (daily updates) | CISA | A1 |
| 3 | CISA KEV addition of CVE-2026-45659 SharePoint deserialisation RCE, 01 Jul 2026 | CISA | A1 |
| 4 | CISA KEV addition of CVE-2026-34908, -34909, -34910 Ubiquiti UniFi OS chain, 23 Jun 2026 | CISA | A1 |
| 5 | Citrix Security Bulletin CTX696300 for CVE-2026-3055 and CVE-2026-4368 | Citrix / Cloud Software Group | A2 |
| 6 | Microsoft Security Update Guide entry for CVE-2026-45659 | Microsoft | A2 |
| 7 | SharePoint RCE CVE-2026-45659 added to CISA KEV after active exploitation | The Hacker News | B2 |
| 8 | CISA warns of actively exploited Microsoft SharePoint vulnerability | SecurityWeek | B2 |
| 9 | Rapid7 vulnerability database: Microsoft SharePoint CVE-2026-45659 | Rapid7 | B1 |
| 10 | NHS England Digital cyber alert CC-4759 - Citrix critical security updates | NHS Digital | A1 |
| 11 | ransomware.live daily leak-site tracker | ransomware.live | B2 |
| 12 | The State of Ransomware - Q1 2026 | Check Point Research | A2 |
| 13 | Global ransomware activity for May 2026 | Industrial Cyber | B2 |
| 14 | FS-ISAC daily indicator exchange (member portal - TLP:CLEAR) | FS-ISAC | A1 |
| 15 | H-ISAC daily bulletin (member portal - TLP:CLEAR) | H-ISAC | A1 |
| 16 | MTS-ISAC daily bulletin and Cyware indicator exchange (TLP:CLEAR) | MTS-ISAC | A1 |
| 17 | Retail and Hospitality ISAC member exchange (TLP:CLEAR) | RH-ISAC | A1 |
| 18 | NCA arrests four for attacks on M&S, Co-op and Harrods (30 Jun 2026) | National Crime Agency | A1 |
| 19 | AA25-239A: Countering Chinese State-Sponsored Actors | CISA / NSA / NCSC / partners | A1 |
| 20 | July rundown - Salt Typhoon and SharePoint scares | IT Pro | B2 |
| 21 | NHS South East London / Synnovis long-tail update | Recorded Future News | B2 |
| 22 | NHS pathology reports backlog update (Q1 2026) | Digital Health | B2 |
| 23 | NCSC Cyber Threat Report: UK Legal Sector | National Cyber Security Centre | A1 |
| 24 | Cyber attacks on law firms jump by 77% (Jun 2026) | Law Society Gazette | B2 |
| 25 | 226 UK law firms suffered data breaches in the past year | Chaucer Group | C3 |
| 26 | SRA 2024 Risk Outlook (ongoing reference) | Solicitors Regulation Authority | A2 |
| 27 | M&S, Co-op & Harrods cyber-attacks - lessons for retailers | Brabners | B2 |
| 28 | Cyber-attacks on M&S, Co-op, Harrods post-incident summary | Air IT Group | C2 |
| 29 | NCSC Cyber Threat Report: UK Charity Sector | National Cyber Security Centre | A1 |
| 30 | GOV.UK: protect your charity from cyber crime | Cabinet Office / DCMS | A1 |
| 31 | IP Insights REST API enrichment (multiple lookups during the reporting period) | IP Insights / UK Cyber Defence Ltd | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Defence and government contractors threat intelligence report — 4–8 May 2026
The R&D and military / government-contractor threat picture for the reporting period continues to be dominated by sustained state-sponsored activity.
Defence and government contractors threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the R&D, military and government-contractor threat picture remained dominated by state-sponsored cyber-espionage against the defence industrial base.
Defence and government contractors threat intelligence report — 27 April – 3 May 2026
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.