Defence and government contractors threat intelligence report — 11–17 July 2026
The R&D and defence-contractor vertical continues to be shaped by the sustained China-nexus dominance of intrusions against the defence industrial base identified by Google Cloud / Mandiant in the 2026 update, and by continued Russian and North Korean activity in the same space.
- Reference: TI-2026-0717-006 (public edition)
- Sector: R&D, military and government contractors
- Reporting period: 11–17 July 2026
- Issued: 17 July 2026 · Lead analyst: EmilyAI · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Research & Development and Military / Government Contractors sector during the period 11 Jul 2026 - 17 Jul 2026. It is intended to support security leadership and operational defenders within client organisations operating in the named vertical, and to inform decisions on detection priorities, defensive investment, and risk acceptance.
Sources are graded throughout against the Admiralty system, and analytic judgements are accompanied by an explicit confidence rating. The R&D and defence-contractor vertical continues to be shaped by the sustained China-nexus dominance of intrusions against the defence industrial base identified by Google Cloud / Mandiant in the 2026 update, and by continued Russian and North Korean activity in the same space. This reporting period the collection picture is dominated by three developments of direct relevance: the 19-agency joint advisory of 13 Jul 2026 attributing systematic router-perimeter compromise across CNI and defence networks to FSB Centre 16, together with a paired APT28 "FrostArmada" DNS-hijack campaign against ~18,000 SOHO routers stealing M365 credentials and OAuth tokens; the disclosure and exploitation of Microsoft AD FS CVE-2026-56155 with immediate CISA KEV listing on 14 Jul 2026 (federal remediation deadline 28 Jul 2026); and the disclosure and exploitation of SonicWall SMA1000 zero-days CVE-2026-15409 / -15410 from late June (federal BOD 26-04 deadline 17 Jul 2026).
Google Cloud Threat Intelligence "Threats to the Defense Industrial Base" (2026 update) continues to hold that China-nexus threat activity represents the highest volume of intrusion attempts against the defence industrial base by a considerable margin, with UNC3886 and UNC5221 highlighted as characteristic edge-device-focused actors. Ankura CTIX Flash Update (15 Jul 2026) reiterated the elevated posture required against Russian and China-nexus activity. NCI / Space ISAC bulletins during the reporting period continued to prioritise satellite-ground-segment and launch-provider adversary interest.
Weighting government and ISAC intelligence above vendor reporting, FSB Centre 16, UNC3886, UNC5221 and Kimsuky remain the four actors of most operational significance to the vertical over the next two reporting cycles.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that China-nexus actors will continue to represent the largest single tranche of intrusion attempts against UK and EU defence-contractor networks during the next two reporting cycles, with edge-device-focused tradecraft (UNC3886 / UNC5221-style) as the dominant vector (HIGH confidence).
- It is highly likely that FSB Centre 16 router-perimeter compromise will be found to have affected at least one UK or EU defence-adjacent network by the end of Q3 2026, given the 13 Jul 2026 advisory and the historical scope of Berserk Bear / Static Tundra targeting (HIGH confidence).
- It is highly likely that AD FS CVE-2026-56155 will be prioritised by nation-state actors for defence-contractor federated-M365 tenants during the next two reporting cycles, given the federation-server-to-tenant lift and the well-established value of identity federation in this vertical (HIGH confidence).
- It is likely that SonicWall SMA1000 CVE-2026-15409 / -15410 chained exploitation will affect at least one defence-adjacent SME during the next two reporting cycles, given the ransomware objective and the SMA1000 prevalence in mid-tier contractor remote access (MEDIUM-HIGH confidence).
- It is a realistic possibility that a DPRK Kimsuky or Lazarus subgroup social-engineering operation (LinkedIn-lure, fake-job-offer or fake-investment-approach model) will affect a UK defence-contractor engineer during the next two reporting cycles (MEDIUM confidence).
2. Sector threat landscape
The R&D and defence-contractor vertical continues to be shaped by the sustained China-nexus dominance of intrusions against the defence industrial base identified by Google Cloud / Mandiant in the 2026 update, and by continued Russian and North Korean activity in the same space. This reporting period the collection picture is dominated by three developments of direct relevance: the 19-agency joint advisory of 13 Jul 2026 attributing systematic router-perimeter compromise across CNI and defence networks to FSB Centre 16, together with a paired APT28 "FrostArmada" DNS-hijack campaign against ~18,000 SOHO routers stealing M365 credentials and OAuth tokens; the disclosure and exploitation of Microsoft AD FS CVE-2026-56155 with immediate CISA KEV listing on 14 Jul 2026 (federal remediation deadline 28 Jul 2026); and the disclosure and exploitation of SonicWall SMA1000 zero-days CVE-2026-15409 / -15410 from late June (federal BOD 26-04 deadline 17 Jul 2026).
Google Cloud Threat Intelligence "Threats to the Defense Industrial Base" (2026 update) continues to hold that China-nexus threat activity represents the highest volume of intrusion attempts against the defence industrial base by a considerable margin, with UNC3886 and UNC5221 highlighted as characteristic edge-device-focused actors. Ankura CTIX Flash Update (15 Jul 2026) reiterated the elevated posture required against Russian and China-nexus activity. NCI / Space ISAC bulletins during the reporting period continued to prioritise satellite-ground-segment and launch-provider adversary interest.
Weighting government and ISAC intelligence above vendor reporting, FSB Centre 16, UNC3886, UNC5221 and Kimsuky remain the four actors of most operational significance to the vertical over the next two reporting cycles. Estate ingest volume was 479.5M events over 7 days; 290k rule_level:>=12 alerts (dominated by known FP families).
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
FSB Centre 16 (Static Tundra / Berserk Bear)
- Aliases: Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra
- Suspected Origin: Russian Federation (FSB Centre 16)
- Suspected Sponsor: Nation state (Russian FSB)
- Primary Motivation: Espionage; strategic access; disruption-adjacent given target choice
- Sector Targeting: Energy, communications, defence industrial base, healthcare, financial services, government, critical national infrastructure globally
- Geographic Focus: Global; UK, US, EU and allied CNI
- Signature TTPs: Systematic router-perimeter compromise (Cisco IOS legacy CSRF resurfaced 13 Jul 2026), SNMP abuse, credential harvesting via man-in-the-middle, edge-appliance persistence
- Tooling / Malware Families: Custom implants on Cisco IOS, MikroTik, TP-Link; SNMP misuse; DNS hijacking
- Recent Activity: 19-agency joint advisory of 13 Jul 2026 attributing systematic router-perimeter compromise across CNI and defence-sector networks; paired APT28 "FrostArmada" DNS-hijack campaign against ~18,000 SOHO routers stealing M365 credentials and OAuth tokens
- Assessed Threat to Vertical: HIGH for CNI, defence, government; MEDIUM-HIGH elsewhere
- Analytic Confidence: HIGH
UNC3886 (China-nexus)
- Aliases: UNC3886 (Mandiant/Google Cloud)
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation state (China-nexus)
- Primary Motivation: Espionage; strategic access to defence and technology sectors
- Sector Targeting: Defence industrial base, technology, telecommunications, virtualisation platforms, government
- Geographic Focus: Global; US, UK, EU and allied defence sectors
- Signature TTPs: Zero-day exploitation of virtualisation platforms (VMware ESXi / vCenter), Fortinet FortiOS and adjacent edge devices; persistence via appliance-native mechanisms; discreet lateral movement
- Tooling / Malware Families: Custom implants targeting VMware and network appliance firmware; LOTL tooling
- Recent Activity: Continued edge-device-focused activity per Google Cloud 2026 Defense Industrial Base update; representative of the dominant China-nexus tradecraft against the DIB
- Assessed Threat to Vertical: HIGH for defence industrial base, technology and telecoms
- Analytic Confidence: HIGH
APT28 (Fancy Bear / GRU Unit 26165)
- Aliases: Fancy Bear, Sofacy, Sednit, Strontium, GRU Unit 26165, Forest Blizzard
- Suspected Origin: Russian Federation (GRU)
- Suspected Sponsor: Nation state (Russian military intelligence)
- Primary Motivation: Espionage; strategic intelligence collection
- Sector Targeting: Defence, government, aerospace, media, energy, IT sector, membership organisations of political salience
- Geographic Focus: Global; NATO allies, Ukraine, EU institutions, defence contractors
- Signature TTPs: "FrostArmada" DNS hijacking of SOHO routers to steal M365 credentials and OAuth tokens; spear-phishing with credential-harvesting landing pages; Zebrocy and X-Agent implants
- Tooling / Malware Families: X-Agent, X-Tunnel, Zebrocy, DealersChoice, Mimikatz, custom implants
- Recent Activity: "FrostArmada" campaign against ~18,000 MikroTik and TP-Link SOHO routers per 13 Jul 2026 advisory; sustained collection focus on defence, government and politically-salient targets
- Assessed Threat to Vertical: HIGH for defence, government and politically-salient membership organisations
- Analytic Confidence: HIGH
Kimsuky (DPRK)
- Aliases: Kimsuky, Velvet Chollima, Black Banshee, Emerald Sleet
- Suspected Origin: Democratic People's Republic of Korea
- Suspected Sponsor: Nation state (DPRK Reconnaissance General Bureau)
- Primary Motivation: Espionage; strategic intelligence collection
- Sector Targeting: Defence, government, think tanks, academia, cryptocurrency-adjacent research
- Geographic Focus: Global with focus on South Korea, Japan, US, UK and allies
- Signature TTPs: Long-tail spear-phishing with credential-harvesting landing pages; academic-lure tradecraft; use of legitimate cloud platforms (Google, Microsoft) as C2 stagers
- Tooling / Malware Families: BabyShark, ReconShark, custom RATs
- Recent Activity: Sustained targeting of defence and government analysts; academic conference and journal-invite lure tradecraft continued into H2 2026
- Assessed Threat to Vertical: MEDIUM-HIGH for defence, government and think-tank targets
- Analytic Confidence: MEDIUM-HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | This week the principal exploited public-facing systems observed by ISAC and government feeds are Microsoft SharePoint on-premises (CVE-2026-45659, rolling forward with Storm-2603 / Warlock ransomware use), SonicWall SMA1000 (CVE-2026-15409/-15410 zero-days, active from late June), AD FS (CVE-2026-56155 disclosed and added to KEV on 14 Jul), and three Joomla-family upload flaws added to CISA KEV in the trailing two weeks. All exploited within days of disclosure. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud Accounts | FSB Centre 16 / APT28 "FrostArmada" activity (13 Jul 2026 joint advisory) hijacked DNS on approximately 18,000 SOHO routers to intercept Microsoft 365 credential and OAuth token flows. Concurrently, sustained password-spray and smart-lockout activity against Entra ID sign-in endpoints across the tenants we monitor (Entra ID password-spray campaign) rotating through five Microsoft app vectors (Azure CLI, AAD PowerShell, One Outlook Web, Teams, OfficeHome). | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | IcedID, Latrodectus and DarkGate loader chains via ISO/IMG/OneNote continued to dominate the phishing tail; volume steady week-on-week per Proofpoint and Sophos public telemetry. Anubis affiliate spear-phish tradecraft (documented in the Adriatic Port Authority intrusion earlier this year) remains active and directly relevant to any organisation with limited external-mail sandboxing. | HIGH |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | CVE-2026-56155 (AD FS DKM container ACL weakness) provides a low-privileged local user with a route to full administrator on the federation server. Because AD FS bridges on-premises AD to Microsoft 365 / Azure AD, exploitation here confers identity-federation-level control on the joined tenant. | HIGH |
| Discovery | T1046 | Network Service Discovery | Automated port sweeps from datacentre-hosted infrastructure; IP Insights flagged multiple AS209605 (HOSTBALTIC), dmzhost and Tor-exit sources in the perimeter tail this period. | MEDIUM |
| Command and Control | T1071.001 | Application Layer Protocol: Web | Cobalt Strike, Sliver and Havoc HTTPS C2 beaconing observed in incident retrospectives via ISAC channels this period; JARM / JA3 fingerprint hunts remain the primary detection. | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone-to-Mega and rclone-to-Backblaze exfiltration patterns dominant in Qilin, Akira, DragonForce and The Gentlemen double-extortion intrusions this period. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Qilin, Akira, DragonForce, The Gentlemen and Interlock ransomware deployment observed against sector-adjacent peers per ransomware.live and ISAC reporting. Warlock (Storm-2603) reported this period on SharePoint CVE-2026-45659 chains. | HIGH |
| Initial Access | T1584.005 | Compromise Infrastructure: Botnet | APT28 "FrostArmada" campaign (per 13 Jul 2026 advisory) hijacked DNS settings on approximately 18,000 SOHO routers to intercept Microsoft 365 credential and OAuth token flows — an intermediate step between infrastructure compromise and cloud-account theft that is directly relevant to defence-contractor home-working populations. | HIGH |
| Initial Access | T1195.002 | Supply Chain Compromise: Software Supply Chain | UNC3886-style targeting of virtualisation platforms and network appliance software remains the dominant China-nexus initial-access pattern against the DIB per the Google Cloud 2026 update — continued relevance to defence-contractor environments running VMware, Fortinet, Ivanti, Cisco and Palo Alto edge devices. | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 14 Jul 2026 | Multiple SonicWall SMA1000 customers (global) | Unattributed / assessed ransomware precursor | SonicWall SMA1000 CVE-2026-15409/-15410 zero-days confirmed exploited from late June; Rapid7 MDR reports the observed goal is ransomware. Federal BOD 26-04 remediation deadline set to 17 Jul 2026. | Rapid7 / SonicWall / CISA KEV |
| 14 Jul 2026 | AD FS-federated Microsoft 365 tenants (global) | Unattributed | CVE-2026-56155 AD FS elevation-of-privilege added to CISA KEV on the day of disclosure with confirmation of active exploitation; DKM container ACL weakness allows a low-privileged local user to gain administrator on AD FS and therefore identity-federation control over the joined M365 / Azure AD tenant. | Microsoft / CISA KEV / KB5121391 |
| 13 Jul 2026 | Critical national infrastructure and defence sector networks (multiple jurisdictions) | FSB Centre 16 / Static Tundra / Berserk Bear (also APT28 "FrostArmada") | 19-agency joint advisory. Systematic compromise of Cisco, MikroTik and TP-Link routers at the perimeter of CNI and defence networks; separate APT28 "FrostArmada" campaign against ~18,000 SOHO routers hijacking DNS to steal Microsoft 365 credentials and OAuth tokens. | NCSC / CISA / 19-agency joint advisory |
| 11 Jul 2026 | The Gentlemen ransomware brand | The Gentlemen | The Gentlemen retained first place among ransomware brands with 121 leak-site postings in June 2026 (vs Qilin 78) and reportedly 300 postings across Q2, edging Qilin at 289. Sustained UK / EU mid-market victim cadence into the reporting period, at a 90% affiliate profit share. | Halcyon / SOCRadar / ransomware.live |
| 15 Jul 2026 | Global CNI and defence sector (multi-jurisdiction) | FSB Centre 16 / Static Tundra / Berserk Bear | Ankura CTIX Flash Update highlighted continued Russian activity against CNI and defence-adjacent infrastructure, echoing the 13 Jul 19-agency advisory. Recommended posture escalation and edge-device audit. | Ankura CTIX Flash Update 15 Jul 2026 |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-15410 | SonicWall SMA1000 Appliance Management Console - post-authentication OS command injection | 7.2 | Yes | Yes | Applied by the same 12.4.3-02962 patch; observed chained with CVE-2026-15409 to gain unauthenticated code execution. Restrict management console to management VLAN and enable MFA on admin logins. Added to CISA KEV 14 Jul 2026. |
| CVE-2026-45659 | Microsoft SharePoint Server SubEd / 2019 / 2016 - deserialisation RCE (Site Member+ authenticated) | 8.8 | Yes | Yes | Rolling forward from prior weeks. Microsoft May 2026 patch. Storm-2603 / Warlock ransomware operators observed exploiting during this period. Audit Site Member permissions; hunt w3wp.exe child processes (cmd.exe, powershell.exe, rundll32.exe) under the SharePoint application pool; restrict /_layouts/15 uploader paths at the WAF. |
| CVE-2026-48939 | Joomla iCagenda extension - unrestricted upload of file with dangerous type | 9.8 | Yes | Yes | Update iCagenda immediately; audit uploads directories for webshells; added to CISA KEV 10 Jul 2026. |
| CVE-2026-56291 | Joomla Balbooa Forms extension - unrestricted upload of file with dangerous type | 9.8 | Yes | Yes | Update Balbooa Forms immediately; audit uploads directories; added to CISA KEV 10 Jul 2026. Third Joomla-family upload flaw added to KEV in the trailing two weeks. |
| CVE-2026-48908 | JoomShaper SP Page Builder (Joomla) - unrestricted file upload of dangerous type | 9.8 | Yes | Yes | Rolling forward from prior week. Update SP Page Builder; audit uploads directories for webshells. Added to CISA KEV 07 Jul 2026. |
| CVE-2026-56290 | Joomlack Page Builder (Joomla) - improper access control on administration endpoints | 9.1 | Yes | Yes | Rolling forward from prior week. Update the extension; restrict administrator paths at the WAF. Added to CISA KEV 07 Jul 2026. |
| CVE-2026-55255 | Langflow - authorisation bypass through user-controlled key | 9.1 | Yes | Yes | Rolling forward from prior week. Restrict LLM-tooling admin interfaces to internal networks. Added to CISA KEV 07 Jul 2026. |
| CVE-2026-8451 | Citrix NetScaler ADC / Gateway - memory overread (CitrixBleed 3 follow-on) | 9.3 | Yes | Yes | Rolling forward. Apply fixed builds 14.1-66.59 / 13.1-62.23 / 13.1-37.262 FIPS/NDcPP; MUST run "kill icaconnection -all", "kill pcoipConnection -all", "kill aaa session -all" post-patch to invalidate stolen sessions. Exploited within 24h of 30 Jun 2026 disclosure. |
| CVE-2026-50751 | Check Point Security Gateway - improper authentication (Qilin-affiliate exploitation) | 9.8 | Yes | Yes | Rolling forward. Apply Check Point R81.20 / R81.10 / R80.40 hotfixes; hunt admin sessions from non-management source addresses; Qilin affiliates observed leveraging as initial-access vector. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IPv6 prefix | 2a06:b440::/32 | 16 Jul 2026 | HIGH | Ninth documented family in the Entra ID password-spray campaign, first IPv6-only family; 40 events/7d against 9 named targets; observed across Microsoft Azure CLI, Azure Active Directory PowerShell, One Outlook Web and Microsoft Teams applications. |
| IP | 185[.]220[.]100[.]240 | 11 Jul 2026 | HIGH | F3 Netze e.V. AS205100 Tor exit (DE, tor-exit-13.zbau.f3netze.de). IP Insights threat score 100/critical, 7 active blacklists (IPInsights Honeypot, AbuseIPDB, ipsum, Dan.me.uk, Checkpoint TOR, malicious-ip); sustained perimeter tail against multiple estates during the reporting period. |
| IP | 45[.]148[.]10[.]240 | 12 Jul 2026 | HIGH | dmzhost bulletproof (NL). IP Insights threat score 100/critical, 5 blacklists including IPInsights Honeypot capture categorised "SSH/Telnet Brute Force"; SSH / RDWeb brute-force tail against monitored estates. |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| FSB Centre 16 / Static Tundra router-perimeter compromise of edge devices | H | H | CRITICAL |
| APT28 FrostArmada SOHO-router DNS hijack against remote-working populations | H | H | CRITICAL |
| AD FS CVE-2026-56155 exploitation against defence-contractor M365 tenants | M | H | HIGH |
| China-nexus (UNC3886 / UNC5221) edge-device-focused intrusion against defence supply chain | H | H | CRITICAL |
| SonicWall SMA1000 CVE-2026-15409/-15410 chained exploitation of contractor remote-access estate | M | H | HIGH |
| DPRK Kimsuky / Lazarus social-engineering of technical engineering staff | M | H | HIGH |
| Insider risk / cleared-personnel targeting | L | H | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Implement SonicWall SMA1000 outbound-request hunts. Audit every internet-facing router by firmware version and last-changed date; alert on any router responding to unauthenticated SNMP or providing a Berserk-Bear-family fingerprint response.
On Entra ID, add specific hunts for M365 sign-ins from SOHO-consumer-ASN IPs where the user population is normally corporate-egress-only. Retain SharePoint w3wp.exe child-process hunts. Add explicit LinkedIn-lure email content hunts and file-download hunts on engineering endpoints for BlueNoroff / Kimsuky-style social engineering (RustBucket, KANDYKORN, ObjCShellz families).
Defend
Preventive priorities: apply the SonicWall SMA1000 12.4.3-02962 patch immediately. Apply the July 2026 Patch Tuesday for AD FS (KB5121391) — the 28 Jul federal deadline is a useful anchor for private-sector defence contractors even where they are not federally mandated. Given the 13 Jul router-perimeter advisory, verify router firmware currency on every internet-facing edge device — Cisco, MikroTik, TP-Link, Fortinet, Palo Alto, Juniper. Disable SNMP/RMI/UPnP on WAN interfaces. Lift Microsoft 365 conditional access to enforce MFA on every sign-in from a non-managed device. Consider explicit blocks on SOHO-ASN inbound M365 activity for cleared populations. Review VMware, Fortinet and Ivanti edge-device fleets against the UNC3886 / UNC5221 tradecraft profiles.
Disrupt
Disruption activity within client lawful authority should focus on: (i) coordinated engagement with the DSbD / MoD / NCSC national CNI point of contact on the FSB Centre 16 advisory; (ii) intelligence-sharing with NCI / Space ISAC and cleared-defence forums; (iii) honeypot deployment mimicking edge-device fingerprints (SonicWall SMA1000 Workplace, Fortinet SSL VPN, Ivanti Sentry admin) with capture routed to NCSC coordination; (iv) tabletop of the AD FS-compromise-into-M365-tenant scenario against cleared-user populations specifically.
10. Forward outlook
Looking forward to the next reporting period (18 Jul - 24 Jul 2026), it is likely that further public reporting will emerge on the FSB Centre 16 router campaign, including sector-specific advisories from NCSC / CISA. It is likely that AD FS CVE-2026-56155 will feature in at least one public attribution to a nation-state actor before the 28 Jul federal remediation deadline. It is a realistic possibility that a UK defence contractor will publicly disclose a breach with a China-nexus attribution within the next two reporting cycles.
Trigger conditions that would prompt revision of this outlook include: (a) any UK defence contractor publicly disclosing a breach linked to CVE-2026-56155, CVE-2026-15409/-15410 or CVE-2026-45659; (b) sector-specific NCSC / CISA advisories following on from the 13 Jul FSB Centre 16 joint advisory; (c) attribution of a specific UK-terminated breach to Static Tundra, UNC3886, UNC5221, APT28 or Kimsuky; (d) Space ISAC or NCI TLP-shared indicator batches with cross-sector R&D relevance; (e) any indication of a novel edge-device zero-day being weaponised by a China-nexus or Russia-nexus actor.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities catalogue (daily updates) | CISA | A1 |
| 3 | CISA KEV additions 14 Jul 2026 (SonicWall SMA1000 CVE-2026-15409, CVE-2026-15410; Microsoft AD FS CVE-2026-56155; Cisco IOS CVE-2008-4128 re-listing) | CISA | A1 |
| 4 | CISA KEV additions 10 Jul 2026 (Joomla iCagenda CVE-2026-48939; Balbooa Forms CVE-2026-56291) | CISA | A1 |
| 5 | CISA KEV additions 07 Jul 2026 (JoomShaper SP Page Builder CVE-2026-48908; Langflow CVE-2026-55255; Joomlack Page Builder CVE-2026-56290) | CISA | A1 |
| 6 | Microsoft July 2026 Patch Tuesday - 622 CVEs including two actively-exploited zero-days (AD FS CVE-2026-56155, SharePoint CVE-2026-45659 rolling forward) | Microsoft MSRC / Zero Day Initiative | A1 |
| 7 | SonicWall product notice - SMA1000 series multiple vulnerabilities and 12.4.3-02962 patch guidance | SonicWall | A2 |
| 8 | Rapid7 MDR blog - SonicWall SMA1000 zero-day exploitation with ransomware objective (CVE-2026-15409, CVE-2026-15410) | Rapid7 | A2 |
| 9 | Sophos X-Ops blog - SonicWall SMA1000 vulnerabilities in active exploitation | Sophos | A2 |
| 10 | 19-agency joint advisory - FSB Centre 16 (Static Tundra / Berserk Bear) systematic router compromise; APT28 "FrostArmada" 18,000-router DNS hijack | NCSC / CISA / 17 partner agencies | A1 |
| 11 | Google Cloud Mandiant - Threats to the Defense Industrial Base (2026 update, China-nexus dominance) | Google Cloud / Mandiant | A2 |
| 12 | The Hacker News / bytevanguard - CVE-2026-56155 AD FS DKM ACL hardening, active exploitation confirmed | Third-party technical media | B2 |
| 13 | ransomware.live daily leak-site tracker (Qilin, The Gentlemen, DragonForce, Akira, Interlock, Warlock) | ransomware.live | B2 |
| 14 | Halcyon / SOCRadar - The Gentlemen 483 lifetime victims; 121 in June 2026, first month above Qilin | Halcyon / SOCRadar | B2 |
| 15 | MOXFIVE / Infosecurity Magazine - Qilin ransomware 2026 profile (1,496 leak-site victims trailing 12 months) | MOXFIVE / Infosecurity Magazine | B2 |
| 16 | NCSC Anubis ransomware advisory (VPN credential abuse and RMM tradecraft) | National Cyber Security Centre | A1 |
| 17 | Bitdefender July 2026 Threat Debrief | Bitdefender | B2 |
| 18 | Check Point Q1 2026 State of Ransomware / ReliaQuest Q2 2026 Ransomware & Cyber Extortion | Check Point Research / ReliaQuest | B2 |
| 19 | CISA KEV entry rolling forward for CVE-2026-45659 (SharePoint deserialisation) - Storm-2603 / Warlock ransomware use | CISA / Microsoft / hard2bit | A1 |
| 20 | IP Insights REST API enrichment (multiple lookups during the reporting period - AS200373 DREI-K-TECH-GMBH pivot on the Entra ID password-spray campaign) | IP Insights / UK Cyber Defence Ltd | A1 |
| 22 | Cybersecurity Breaches Survey 2025/2026 - UK statutory dataset (rolling reference) | DSIT / GOV.UK | A1 |
| 23 | Verizon Data Breach Investigations Report 2026 - sector chapters (rolling reference) | Verizon | B2 |
| 24 | Google Cloud Threat Intelligence - Threats to the Defense Industrial Base (2026 update) | Google Cloud / Mandiant | A2 |
| 25 | Space ISAC / National Council of ISACs bulletins (TLP:CLEAR) | NCI / Space ISAC | A1 |
| 26 | Ankura CTIX Flash Update 15 Jul 2026 (defence sector overview) | Ankura | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Defence and government contractors threat intelligence report — 4–8 May 2026
The R&D and military / government-contractor threat picture for the reporting period continues to be dominated by sustained state-sponsored activity.
Defence and government contractors threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the R&D, military and government-contractor threat picture remained dominated by state-sponsored cyber-espionage against the defence industrial base.
Defence and government contractors threat intelligence report — 27 April – 3 May 2026
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.