SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Financial services threat intelligence report — 23–29 May 2026

The collection picture this week has been dominated by the continued exploitation of edge-appliance vulnerabilities — Cisco Catalyst SD-WAN (CVE-2026-20182) under Emergency Directive 26-03, the Ivanti EPMM credential-reuse chain (CVE-2026-6973)…

  • Reference: TI-2026-0529-001 (public edition)
  • Sector: Financial services, banking, fintech and insurance
  • Reporting period: 23–29 May 2026
  • Issued: 29 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Financial Services, Banking, Fintech and Insurance vertical during the period 23 May 2026 to 29 May 2026. The collection picture this week has been dominated by the continued exploitation of edge-appliance vulnerabilities — Cisco Catalyst SD-WAN (CVE-2026-20182) under Emergency Directive 26-03, the Ivanti EPMM credential-reuse chain (CVE-2026-6973), the Microsoft Exchange Server zero-day (CVE-2026-42897) confirmed in active exploitation by Microsoft on 14 May, and the Trend Micro Apex One directory-traversal flaw (CVE-2026-34926) added to CISA KEV on 21 May. Ransomware leak-site activity from Qilin, TheGentlemen, Akira and DragonForce continued at the elevated Q1 cadence; the Scattered Spider IAB front-end remains operationally focused on banking BPO and outsourced helpdesks supporting regulated FS firms. Sources are graded against the Admiralty System and analytic judgements carry explicit confidence ratings.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that ransomware and pure data-extortion crews — Qilin, TheGentlemen, Akira, DragonForce, Cl0p and the Lynx / ShinyHunters cluster — will continue to drive the majority of the materially-disruptive activity affecting UK and European financial-services entities over the next reporting cycle, with the Scattered Spider IAB front-end continuing to focus on outsourced helpdesks and BPO vendors. (HIGH confidence)
  2. It is highly likely that CVE-2026-20182 (Cisco Catalyst SD-WAN, CVSS 10.0) will produce at least one publicly-disclosed UK financial-services exploitation event within the next two reporting cycles. CISA, NCSC-UK, NSA and partners have published joint guidance citing active in-the-wild exploitation by UAT-8616, with post-exploitation activity including SSH key addition, NETCONF manipulation and privilege escalation to root. (MEDIUM-HIGH confidence)
  3. It is likely that the Microsoft Exchange Server zero-day CVE-2026-42897 (CVSS 8.1, KEV 15 May 2026) will be weaponised against UK FS Outlook Web Access tenants over the next reporting cycle, with the OWA crafted-email primitive proving a credible foothold against legacy on-prem mailbox estates. UK FS organisations still operating on-prem Exchange should treat the 14 May OOB update as the second highest-priority patch action of the reporting cycle, behind the Cisco SD-WAN advisory. (MEDIUM confidence)
  4. It is likely that the Ivanti EPMM CVE-2026-6973 chain (CVSS 7.2, in CISA KEV from 7 May 2026) will continue to be exploited against EPMM tenants whose admin credentials were harvested by the earlier CVE-2026-1340 wave in January 2026. UK FS organisations operating on-prem EPMM should treat any admin credential issued prior to 1 February 2026 as untrusted until rotated. (MEDIUM confidence)
  5. It is highly likely that AI-driven KYC bypass — real-time deepfake voice and video, synthetic identity generation, automated spear-phish targeting of C-suite — will continue to grow as a fraud-adjacent risk for retail banking and insurance carriers, per FS-ISAC's 2026 AI hardening advisory. (HIGH confidence)

2. Sector threat landscape

The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. ReliaQuest's Q1 2026 retrospective places ransomware leak-site postings at 2,638 for the quarter, up 22% on the same quarter a year earlier, and Check Point Research places Qilin as the most active ransomware operation for the third consecutive quarter. The four most active groups — Qilin, Akira, TheGentlemen and LockBit — together accounted for 41% of all named victims in Q1, a notable consolidation from prior quarters and consistent with the formal LockBit / Qilin / DragonForce alliance reporting first surfaced in spring 2026. Qilin alone in Q1 posted more victims than the bottom fifty groups combined, which materially changes the threat-actor prioritisation calculus for FS-sector defenders.

Edge-appliance and identity-provider exposure remains the single most operationally consequential collection theme for FS this week. CVE-2026-20182 against the Cisco Catalyst SD-WAN Controller and Manager has been added to CISA's KEV catalogue under Emergency Directive 26-03 and is the subject of a joint advisory from CISA, NSA, NCSC-UK, ASD's ACSC, CCCS and NCSC-NZ. Cisco Talos has confirmed in-the-wild exploitation by activity cluster UAT-8616 — previously linked to the February 2026 CVE-2026-20127 SD-WAN campaign — with post-exploitation tradecraft centred on SSH key addition, NETCONF manipulation across the SD-WAN fabric, and escalation to root. Any UK FS organisation operating Catalyst SD-WAN should treat this as the highest-priority patch action of the reporting cycle.

Microsoft's 14 May out-of-band advisory for the on-prem Exchange Server zero-day CVE-2026-42897 (CVSS 8.1) confirms active exploitation via a crafted-email OWA primitive: an attacker sending a specially-crafted email can execute arbitrary JavaScript in the browser context of any OWA user who opens it under specific interaction conditions. The vulnerability affects Exchange Server Subscription Edition RTM, 2019 and 2016; Exchange Online is not affected. CISA added the CVE to KEV on 15 May. The exploitation primitive matters operationally for FS firms because OWA is a frequent residual access vector for executive and back-office staff in mid-tier banks, regional insurers and outsourced fund administrators that still maintain on-prem mailbox estates.

The Scattered Spider / DragonForce campaign that materially disrupted M&S, Co-op and Harrods in April–May 2025 has continued to shape the threat picture, but the operational pivot in 2026 is towards banking BPO, outsourced helpdesk and the customer-service supply chain of regulated FS firms. M&S's annual results published 20 May confirm the cyber attack cost £300m in lost trading and supply-chain disruption, putting adjusted pre-tax profit down 23.8% to £671.4m for the year to 29 March; Co-op separately put revenue losses at £206m. The financial scale is now common knowledge inside boardrooms and is reshaping resilience expectations for FS firms with similar outsourced-helpdesk topologies. UK retail-banking clients should assume their inbound helpdesk channel is a credible attack surface and exercise their voice-authentication, callback and ID-verification controls against an explicit Scattered Spider scenario before the next quarter close.

Geopolitical pressure on the vertical has not eased. NCSC-UK's Middle East cyber posture guidance remains live for any UK FS entity with regional exposure, and the long-standing Russian state-aligned hacktivist posture (NoName057(16) successor clusters) against UK FS firms with sanctions-regime exposure or visible support for Ukraine remains a credible source of disruption-grade DDoS and brand-damage activity. ESET's APT activity report for October 2025 to March 2026 — released 28 May — flags sustained China-nexus pressure on payment infrastructure across the sector, with edge-appliance compromise the consistent initial-access story. The Citrix NetScaler ADC and Gateway advisories CVE-2026-3055 and CVE-2026-4368, highlighted in NCSC's alert published this week, are particularly relevant to FS firms using NetScaler in their VPN and load-balancer tiers.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Qilin (a.k.a. Agenda, Qilin.B)

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russia
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — extortion / data theft
  • Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
  • Geographic Focus: Global; UK, EU, US, ANZ
  • Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
  • Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)

Scattered Spider / DragonForce affiliate cluster

  • Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine
  • Suspected Origin: UK / US / English-speaking community
  • Suspected Sponsor: Criminal (IAB into DragonForce / LockBit / Qilin cartel)
  • Primary Motivation: Financial — extortion via partner ransomware
  • Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
  • Geographic Focus: UK, US, increasing reach into EU and outsourced helpdesks abroad
  • Signature TTPs: Voice-phishing of IT helpdesks, SIM-swap, MFA fatigue, OAuth consent-phishing, RMM (AnyDesk / TeamViewer / ScreenConnect)
  • Tooling / Malware Families: DragonForce / LockBit / Qilin partner encryptors; ESXi-targeted mass-encryption
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — NCSC, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty A2.
  • Analytic Confidence: HIGH — NCSC, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced

Cl0p

  • Aliases: TA505 affiliate, FIN11-adjacent
  • Suspected Origin: Russia / CIS
  • Suspected Sponsor: Criminal
  • Primary Motivation: Financial — pure data extortion
  • Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
  • Geographic Focus: Cross-sector, global
  • Signature TTPs: Mass zero-day exploitation of managed file transfer products (MOVEit, GoAnywhere, Cleo); staged leak-site disclosure; no encryption since 2023
  • Tooling / Malware Families: Custom Cl0p data-extortion toolkit; preference for MFT zero-days
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. MEDIUM-HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: MEDIUM-HIGH

TheGentlemen

  • Aliases:
  • Suspected Origin: Unattributed (likely Russian-speaking criminal milieu)
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — extortion
  • Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
  • Geographic Focus: Cross-sector, global
  • Signature TTPs: Rapid affiliate onboarding; multi-platform encryptor (Windows/Linux/BSD/NAS); SystemBC C2
  • Tooling / Malware Families: Go-based encryptor; SystemBC; partner-supplied IAB access
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. MEDIUM-HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: MEDIUM-HIGH

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1566.002Spear-phishing LinkHelpdesk social-engineering with pre-built identity-verification scripts; voice-phishing of Tier-1 outsourced support staff; OAuth consent-phishing against M365 tenants.HIGH
Initial AccessT1190Exploit Public-Facing ApplicationMass exploitation of Cisco Catalyst SD-WAN Controller (CVE-2026-20182), Ivanti EPMM (CVE-2026-6973), Trend Micro Apex One (CVE-2026-34926), Microsoft Exchange OWA (CVE-2026-42897) and Citrix NetScaler (CVE-2026-3055/4368) against unpatched internet-facing instances.HIGH
Initial AccessT1078.004Valid Accounts: CloudReuse of IAB-purchased VPN credentials and harvested EPMM admin credentials originating from the CVE-2026-1340 wave in January 2026.HIGH
ExecutionT1059.001Command and Scripting: PowerShellEncoded PowerShell loaders invoking SystemBC and Cobalt Strike Beacon in Qilin and TheGentlemen operations.MEDIUM
PersistenceT1136.002Create Account: DomainCreation of attacker-controlled domain admin and break-glass accounts as a precursor to encryption / extortion.MEDIUM
Defence EvasionT1562.001Impair Defences: Disable Security ToolsTargeting of EDR control planes via stolen admin credentials; Trend Micro Apex One directory-traversal CVE-2026-34926 added to CISA KEV during the reporting period heightens this risk.MEDIUM
ExfiltrationT1567.002Exfiltration to Cloud StorageUse of rclone, MEGAcmd and AzCopy to push data to attacker-controlled cloud storage prior to encryption stage.HIGH
ImpactT1486Data Encrypted for ImpactESXi-aware Qilin.B and DragonForce encryptors; mass-encryption of hypervisor estates.HIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
24 May 2026Global Retool Group (Business Services, FS-adjacent)QilinPosted to Qilin leak-site 24 May; data-extortion ongoing.Ransomware.live
21 May 2026Trend Micro Apex One (vendor)UnattributedCVE-2026-34926 directory-traversal added to CISA KEV 21 May after in-the-wild exploitation; elevates EDR-control-plane risk across regulated FS estates running Apex One.CISA / Trend Micro
20 May 2026M&S — annual results disclosure of April 2025 attackScattered Spider / DragonForceConfirmed £300m cyber-attack cost; pre-tax profit down 23.8%. FS-adjacent retail-banking lessons on outsourced helpdesk exposure.ITV / Computer Weekly
15 May 2026Microsoft Exchange Server tenants (on-prem)MultipleCVE-2026-42897 OWA XSS confirmed in active exploitation; KEV added 15 May; FS firms running on-prem Exchange materially exposed.Microsoft / Help Net Security

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN Controller / Manager (auth bypass; UAT-8616 in-the-wild)10.0YesYesPatch immediately; rotate SSH keys; review NETCONF logs
CVE-2026-6973Ivanti EPMM (post-CVE-2026-1340 credential reuse chain)7.2YesYesPatch and rotate any admin credential issued before 1 Feb 2026
CVE-2026-34926Trend Micro Apex One (On-Premise) — directory traversal9.4YesYesPatch to build ≥17079; treat as EDR-control-plane exposure until verified
CVE-2026-42897Microsoft Exchange Server (Subscription Edition / 2019 / 2016) — XSS via crafted email8.1YesYesApply 14 May 2026 OOB update; disable OWA externally pending patch
CVE-2025-34291Langflow — origin validation error (added KEV 21 May 2026)9.1YesSuspectedPatch and restrict admin endpoints to trusted networks
CVE-2026-8398 / CVE-2026-45321 / CVE-2026-48027DAEMON Tools Lite / TanStack packages / Nx Console developer extension (supply-chain trio added KEV 27 May)8.0–8.8YesYesAudit developer endpoints; remove compromised package versions
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler ADC and Gateway (NCSC alert week of 24 May)9.0 / 7.5NoSuspectedApply Citrix advisory updates; review session tokens

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]101[.]5ongoingMTOR exit node — Network Attack + tor_exit categories, IP Insights suggestion: block
IP193[.]32[.]162[.]157ongoingMBrute-force / malware family — listed on 6 blacklists per IP Insights
Domainglobal-retool-leaks[.]onion24 May 2026MQilin leak-site post — Global Retool Group disclosure

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Ransomware deployment via initial-access broker (Scattered Spider → DragonForce / Qilin)HIGHHIGHCRITICAL
Edge-appliance exploitation (Cisco Catalyst SD-WAN / Ivanti EPMM / Citrix NetScaler) leading to admin compromiseHIGHHIGHCRITICAL
Business email compromise / OAuth consent-phish against finance functions, fund administrators and treasuryHIGHMEDIUMHIGH
Supply-chain compromise via BPO helpdesk or third-party SaaS (TCS-style chain)MEDIUMHIGHHIGH
AI-enabled deepfake KYC bypass / synthetic identity fraud in retail banking and insuranceHIGHMEDIUMHIGH
Russian-aligned hacktivist DDoS against UK FS public-facing servicesMEDIUMMEDIUMMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection engineering should treat the Cisco Catalyst SD-WAN compromise pattern as the highest-priority hunting hypothesis for the next reporting cycle. Cross-walk EPMM admin logins against the documented CVE-2026-1340 / CVE-2026-6973 credential set, rotating any admin token issued before 1 February 2026 as untrusted. For Microsoft Exchange tenants still on-prem, instrument OWA crafted-email telemetry against CVE-2026-42897 — IIS access logs paired with mailbox event 41 should surface the exploitation primitive. Trend Micro Apex One administrators should monitor for directory-traversal probes against the ApexOne web-admin endpoint and treat any EDR-control-plane configuration change without a corresponding change-management record as a P1 trigger. For FS-specific tenants, instrument FS-ISAC indicator feeds against the EDR control plane, and watch for OAuth consent grants to non-allow-listed enterprise applications across retail-banking and insurance M365 tenants. Helpdesk identity-verification call-recording should be indexed for the Scattered Spider linguistic markers identified in NCSC's voice-phishing alert.

Defend

Preventive priorities follow Section 6 directly: patch Cisco Catalyst SD-WAN Controller and Manager out of band as the single highest-value action of the reporting cycle, treat any pre-patch SD-WAN admin credential as untrusted, and rotate. EPMM tenants should rotate all admin credentials issued before 1 February 2026 and apply the CVE-2026-6973 patch. Trend Micro Apex One should be patched to build 17079 or later; until then, isolate the Apex web-admin interface behind a management VPN. Microsoft Exchange tenants should apply the OOB update for CVE-2026-42897, and restrict OWA external exposure to MFA-protected paths only. Hardening should follow ISO/IEC 27001 Annex A controls A.5.7 (threat intelligence), A.5.23 (information security for cloud services), A.8.8 (management of technical vulnerabilities), A.8.16 (monitoring activities) and A.8.23 (web filtering); under the NIST CSF mapping, the bulk of these controls land under Identify-AM, Protect-AC and Detect-CM. Helpdesk identity-verification scripts should be exercised against an explicit Scattered Spider / DragonForce voice-phishing scenario before the next quarter close. Map controls onto the FCA / PRA operational-resilience regime (SS1/21, SYSC 15A) and the DORA Article 28 third-party ICT risk regime where European exposure is in scope. SwiftCSP control framework should be re-tested against the current voice-phishing scenario as part of the annual attestation.

Disrupt

Disruption activity within client lawful authority should focus on: (i) participation in the relevant ISAC indicator-exchange channel — FS-ISAC, H-ISAC, RH-ISAC, Aviation-ISAC, MTS-ISAC and the National Council of ISACs aggregator each provide indicator-sharing forums whose value compounds with active participation; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through the registrar-abuse channel and Cloudflare / Microsoft / Google trust-and-safety forms where attribution is sufficient; (iii) deception deployment in the helpdesk-identity-verification path — honey-identities seeded with watch-listed credential signatures will surface IAB front-end activity early; and (iv) tabletop exercise of the Scattered Spider / DragonForce playbook against the inbound helpdesk channel, scoped to a realistic voice-phishing-to-encryption window of 4 to 12 hours. Participation in FS-ISAC's indicator-exchange and the CiSP FS trust group is table stakes for credible FS sector reporting; analysts should ensure all in-scope FS clients have at least one named indicator-sharing contact and that the contact is exercising the channel monthly.

10. Forward outlook

*Looking forward to the next reporting period (30 May – 5 June 2026), it is likely that one or more UK FS firms will publicly disclose an incident traceable to the Cisco SD-WAN, EPMM, Exchange OWA or Apex One vulnerabilities flagged in Section 6, with MEDIUM-HIGH confidence based on the breadth of in-the-wild exploitation already observed. It is highly likely that Qilin and TheGentlemen will continue at their current leak-site cadence, with at least one UK or EU FS or FS-adjacent professional services victim per week.

*Trigger conditions that would prompt revision of this outlook include: (a) a UK FS firm publicly attributing a breach to UAT-8616 SD-WAN exploitation, which would raise the actor from background activity to active campaign status; (b) the appearance of a Qilin or Akira leak-site post naming a UK regulated FS entity, which would warrant an immediate amber-level client advisory; (c) any FS-ISAC TLP:CLEAR advisory pointing to a sector-wide credential-stuffing or token-theft campaign; or (d) novel Scattered Spider linguistic markers in helpdesk call recordings.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1CISA KEV Catalog updates — 15, 20, 21, 27 May 2026 — https://www.cisa.gov/known-exploited-vulnerabilities-catalogCISAA1
2Cisco Catalyst SD-WAN Auth Bypass (CVE-2026-20182) — joint advisory CISA / NSA / FBI / NCSC-UK / ACSC / CCCS / NCSC-NZCISA et al.A1
3Talos Intelligence — Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616)Cisco TalosB2
4Trend Micro Apex One CVE-2026-34926 — CISA KEV addition 21 May 2026CISA / Trend MicroA1
5Microsoft Exchange Server CVE-2026-42897 — active exploitation confirmed by MicrosoftMicrosoft / Help Net SecurityB1
6NCSC weekly threat reports and advisory feed (NCSC-UK)NCSCA1
7ESET APT Activity Report — Oct 2025 to Mar 2026ESETB2
8Check Point Research — The State of Ransomware Q1 2026Check Point ResearchB2
9Ransomware.live — leak-site tracker (Qilin / Akira / DragonForce / TheGentlemen postings, week ending 28 May 2026)Ransomware.liveC2
10IP Insights — IP reputation enrichment (https://www.ipinsights.io)UK Cyber Defence LtdB2
11FS-ISAC — sector resilience and AI-fraud advisories (subscription)FS-ISACA2
12NCSC alert — Citrix NetScaler ADC / Gateway CVE-2026-3055 and CVE-2026-4368NCSCA1
13ReliaQuest — Q1 2026 ransomware leak-site retrospectiveReliaQuestB2
14Marks & Spencer — annual results 20 May 2026 (£300m cyber cost)M&S / ITV NewsB2
15ESET APT Activity Report Oct 2025–Mar 2026 (released 28 May 2026)ESETB2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.