Financial services threat intelligence report — 30 May – 5 June 2026
The financial-services collection picture this week has been shaped by the addition of three further CVEs to the CISA KEV catalogue on 02 and 03 June - CVE-2022-0492 (Linux Kernel cgroup releaseagent, revived for container-escape campaigns against cloud-banking workloads)…
- Reference: TI-2026-0605-001 (public edition)
- Sector: Financial services, banking, fintech and insurance
- Reporting period: 30 May – 5 June 2026
- Issued: 5 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The financial-services collection picture this week has been shaped by the addition of three further CVEs to the CISA KEV catalogue on 02 and 03 June - CVE-2022-0492 (Linux Kernel cgroup release_agent, revived for container-escape campaigns against cloud-banking workloads), CVE-2025-48595 (Android Framework integer overflow, with Google confirming limited targeted exploitation against high-value mobile-banking targets) and CVE-2026-45247 (Mirasvit Full Page Cache Warmer deserialisation, which is materially relevant to FS-adjacent payment processors operating Magento storefronts).
Perimeter scrubbing was dominated by sustained brute-force pressure against SSH and CMS surfaces from a familiar tail of IP Insights 'critical' sources - ServeTheWorld AS in Norway, Contabo DE, Offshore LC in Luxembourg, Viettel Group in Vietnam and JSC Kazakhtelecom in Kazakhstan - all of which carry threat_score 100 against seven or more blacklists. May 2026 ransomware telemetry from Check Point and BreachSense placed Qilin at 101 victims for the month (fifth consecutive month at the top of leak-site postings), TheGentlemen at 70, Akira at 52 and DragonForce at 41 - with the United Kingdom in second place globally on victim count (36) behind only the United States.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware and pure data-extortion crews - Qilin, TheGentlemen, Akira, DragonForce and the Lynx / ShinyHunters cluster - will continue to drive the majority of materially-disruptive activity affecting UK and European FS entities over the next reporting cycle, with Scattered Spider continuing as the dominant English-speaking IAB front-end. (HIGH confidence)
- It is highly likely that CVE-2026-35616 (Fortinet FortiClient EMS) will produce at least one publicly-disclosed UK FS exploitation event within the next two reporting cycles, given the prevalence of FortiClient EMS in retail-banking and insurance-broker estates and the live in-the-wild status confirmed by watchTowr. (MEDIUM-HIGH confidence)
- It is likely that the Microsoft Defender BlueHammer chain (CVE-2026-33825) will be incorporated into IAB tradecraft against FS Tier-2 entities, as the LPE / defence-evasion primitive is uniquely valuable against EDR-dependent SME and credit-union estates. (MEDIUM confidence)
- It is likely that the n8n self-hosted max-severity defect will be exploited against FS firms running self-hosted automation tooling for fraud-rules or reconciliation pipelines, with consequences ranging from credential-theft to wire-fraud automation. (MEDIUM confidence)
- It is highly likely that AI-driven KYC bypass - real-time deepfake voice and video, synthetic identity generation and automated spear-phish targeting of C-suite - will continue to grow as a fraud-adjacent risk for retail banking and insurance carriers, per FS-ISAC's standing AI-hardening advisory. (HIGH confidence)
2. Sector threat landscape
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. BreachSense's May 2026 retrospective records 646 victims across 61 active ransomware groups for the month, with Qilin alone accounting for 101 - its fifth consecutive month at the top of leak-site postings. The United Kingdom placed second globally with 36 victims, trailing only the United States. ESET's APT activity report covering October 2025 to March 2026 (released 28 May) flags North Korean Lazarus sub-clusters as continuing to target UK and EU cryptocurrency-adjacent FS firms via fake-recruiter campaigns, and Russian APT28 router-exploit campaigns continue against UK FS perimeter SOHO routers per the live NCSC advisory.
Edge-appliance and identity-provider exposure remains the most operationally consequential collection theme this week. The Fortinet FortiClient EMS zero-day CVE-2026-35616 was confirmed under active in-the-wild exploitation by watchTowr Labs on 02 June; the pre-authentication remote-code-execution surface against the EMS admin endpoint is acutely relevant to UK FS firms running FortiClient at scale, and any EMS instance reachable from a non-management network should be treated as a candidate compromise pending verification. CVE-2026-20182 against Cisco Catalyst SD-WAN remains under continuing exploitation by activity cluster UAT-8616, per joint CISA/NSA/NCSC-UK guidance.
The Microsoft Defender BlueHammer disclosure (CVE-2026-33825) presents an unusually consequential local-privilege-escalation / defence-evasion primitive against the very EDR control plane on which most FS detection programmes depend. Real-world intrusions chaining BlueHammer to compromised FortiGate SSL-VPN credentials from source IPs in Russia, Singapore and Switzerland have been observed, raising the prospect of EDR-resident attackers operating beneath the visibility of cloud-managed Defender tenants until MoCAMP build 4.18.26040.1011 is forced down. UK FS firms should treat any unpatched Defender platform as untrusted for purposes of post-incident triage.
The Scattered Spider / DragonForce cluster that materially disrupted M&S, Co-op and Harrods through April-May 2025 continues to define the operational threat picture for FS-adjacent retail banking and insurance, with the 2026 pivot remaining toward banking BPO, outsourced helpdesk and the customer-service supply chain of regulated FS firms. FS-ISAC's standing AI-hardening advisory and the H-ISAC findings on AI-enabled threats both reinforce that AI-driven social engineering - deepfake voice-phishing of finance staff, synthetic-identity onboarding through automated KYC bypass and LLM-authored spear-phish - is the largest new fraud vector for the cycle.
Perimeter scrubbing handled sustained brute-force pressure from a familiar tail of IP Insights 'critical' sources - 85[.]137[.]228[.]167 (ServeTheWorld AS), 79[.]143[.]178[.]79 (Contabo), 176[.]65[.]139[.]151 (Offshore LC), 212[.]19[.]134[.]75 (JSC Kazakhtelecom) and the Viettel / Megacore VN cluster - all carrying threat_score 100 against seven-to-nine blacklists. None of this pressure produced a successful authentication event against an FS client.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda, Qilin.B)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russia
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion / data theft
- Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
- Geographic Focus: Global; UK, EU, US, ANZ
- Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
- Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
- Recent Activity: 101 victims posted in May 2026 - fifth consecutive month at top of leak-site postings (Check Point / BreachSense).
- Assessed Threat to Vertical: HIGH - sustained FS targeting; Admiralty B2.
- Analytic Confidence: HIGH - multiply sourced (Check Point Research, BreachSense, Ransomware.live)
TheGentlemen
- Aliases: -
- Suspected Origin: Unattributed (likely Russian-speaking)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion
- Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
- Geographic Focus: Cross-sector, global
- Signature TTPs: Rapid affiliate onboarding; multi-platform encryptor (Windows/Linux/BSD/NAS); SystemBC C2
- Tooling / Malware Families: Go-based encryptor; SystemBC; partner-supplied IAB access
- Recent Activity: 70 victims posted in May 2026 - second only to Qilin (BreachSense).
- Assessed Threat to Vertical: HIGH - FS-relevant pattern; Admiralty B2.
- Analytic Confidence: MEDIUM-HIGH
Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine
- Suspected Origin: UK / US / English-speaking community
- Suspected Sponsor: Criminal (IAB into DragonForce / LockBit / Qilin)
- Primary Motivation: Financial - extortion via partner ransomware
- Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
- Geographic Focus: UK, US, increasing EU and outsourced helpdesks abroad
- Signature TTPs: Voice-phishing of IT helpdesks, SIM-swap, MFA fatigue, OAuth consent-phish, RMM abuse (AnyDesk / ScreenConnect)
- Tooling / Malware Families: DragonForce / LockBit / Qilin partner encryptors; ESXi mass-encryption
- Recent Activity: DragonForce 41 victims in May 2026 (down from 63 in April per BreachSense); FS-adjacent retail and BPO continuing primary target set.
- Assessed Threat to Vertical: HIGH - Admiralty A2.
- Analytic Confidence: HIGH - NCSC-UK, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced
Lazarus / DangerousPassword sub-clusters
- Aliases: APT38, BlueNoroff, Sapphire Sleet
- Suspected Origin: Democratic People's Republic of Korea
- Suspected Sponsor: State (Reconnaissance General Bureau)
- Primary Motivation: Financial - revenue generation for DPRK; cryptocurrency theft
- Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
- Geographic Focus: Global; UK and EU FS firms with crypto exposure
- Signature TTPs: Fake-recruiter LinkedIn lures; trojanised PDF readers; living-off-the-land in CI/CD pipelines
- Tooling / Malware Families: AppleJeus, ManageBus, RustBucket, custom Python loaders
- Recent Activity: ESET APT activity report (28 May) flags continuing UK / EU crypto-FS targeting; aligned with US-CERT joint advisory.
- Assessed Threat to Vertical: HIGH - for crypto-FS subset; Admiralty B2.
- Analytic Confidence: HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Mass exploitation of Fortinet FortiClient EMS (CVE-2026-35616), Cisco Catalyst SD-WAN (CVE-2026-20182), Ivanti EPMM (CVE-2026-6973) and Exchange OWA (CVE-2026-42897) against FS perimeters. | HIGH |
| Initial Access | T1566.002 | Spear-phishing Link | Voice-phishing of outsourced IT helpdesks and OAuth consent-phishing of M365 tenants; Scattered Spider continuing tradecraft. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud | Reuse of IAB-purchased VPN credentials and harvested EPMM admin credentials from the CVE-2026-1340 wave. | HIGH |
| Execution | T1059.001 | Command and Scripting: PowerShell | Encoded PowerShell loaders staging SystemBC and Cobalt Strike Beacon in Qilin and TheGentlemen tradecraft. | MEDIUM |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Microsoft Defender BlueHammer chain (CVE-2026-33825) used to obtain SYSTEM and disable AV telemetry. | MEDIUM |
| Defence Evasion | T1562.001 | Impair Defences: Disable Security Tools | Targeting of EDR control plane via BlueHammer LPE; relevant to FS Defender estates. | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGAcmd / AzCopy push to attacker-controlled cloud destinations prior to encryption. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | ESXi-aware Qilin.B and DragonForce encryptors continue mass-encryption of hypervisor estates. | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 02 Jun 2026 | Fortinet FortiClient EMS (vendor) | Unattributed | CVE-2026-35616 confirmed in-the-wild by watchTowr Labs; pre-auth RCE against EMS - direct FS perimeter relevance. | watchTowr Labs |
| 02 Jun 2026 | Microsoft Defender platform (vendor) | Multiple - RU / SG / CH transit | BlueHammer (CVE-2026-33825) LPE chain disclosed; observed in real-world intrusions via compromised FortiGate SSL-VPN credentials. | Microsoft / The Hacker News |
| 02 Jun 2026 | CISA KEV - CVE-2022-0492 (Linux cgroup) revived | Unattributed | Container-escape primitive resurfacing against cloud-banking workloads; FCEB remediation by 23 Jun 2026. | CISA |
| 03 Jun 2026 | CISA KEV - CVE-2026-45247 (Mirasvit / Magento) | Unattributed | Deserialisation in Full Page Cache Warmer - payment-processor / FS-adjacent storefront relevance. | CISA |
| Ongoing | Qilin / TheGentlemen / Akira / DragonForce leak sites | Multiple | May 2026: Qilin 101, TheGentlemen 70, Akira 52, DragonForce 41. UK = 36 victims globally (2nd). | BreachSense |
| Continuing | Scattered Spider / DragonForce campaign | UNC3944 | Continuing focus on banking BPO, outsourced helpdesk and customer-service supply chain. | NCSC / Sophos X-Ops |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-35616 | Fortinet FortiClient EMS - pre-auth RCE; active in-the-wild exploitation reported by watchTowr 02 Jun 2026 | 9.8 | Yes | Yes | Patch to 7.4.2 or later; restrict EMS admin interface to management VLAN |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform - BlueHammer LPE / defence-evasion (<4.18.26040.1011) | 8.4 | Yes | Yes | Force MoCAMP rollout; hunt for FortiGate SSL-VPN sessions terminating from RU/SG/CH |
| CVE-2026-45585 | Microsoft Windows BitLocker - YellowKey bypass; in-the-wild PoC live | 7.1 | Yes | Suspected | Apply June mitigation guidance; enforce TPM+PIN on regulated workstations |
| CVE-2026-42897 | Microsoft Exchange Server (SE / 2019 / 2016) - OWA crafted-email XSS (continuing exploitation) | 8.1 | Yes | Yes | Apply 14 May 2026 OOB update if not already; disable external OWA pending patch |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller / Manager - auth bypass; UAT-8616 continuing campaign | 10.0 | Yes | Yes | Verify Emergency Directive 26-03 closure; rotate SSH keys; review NETCONF logs |
| CVE-2026-6973 | Ivanti EPMM - admin credential reuse chain (post CVE-2026-1340) | 7.2 | Yes | Yes | Rotate any EPMM admin credential issued before 01 Feb 2026; confirm patch level |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer (Magento) - deserialisation; KEV 03 Jun 2026 | 9.8 | Yes | Yes | Patch immediately; isolate Magento admin behind WAF; hunt for unsigned PHP cache entries |
| CVE-2025-48595 | Android Framework - integer-overflow LPE; KEV 02 Jun 2026; limited/targeted exploitation observed by Google | 7.8 | Yes | Yes | Push June 2026 Android security patch to MDM-managed handsets |
| CVE-2022-0492 | Linux Kernel cgroup release_agent - KEV 02 Jun 2026 for revived container-escape campaigns | 7.8 | Yes | Yes | Validate kernels >=5.17; audit container hosts for unconfined cgroup mounts |
| CVE-2026-41091 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-45498 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-N8N-CRIT | n8n self-hosted - max-severity authentication-bypass per CyberScoop research (defenders rushing PoC) | 9.8 | Yes | Suspected | Upgrade to patched build; restrict n8n console to private network only |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 85[.]137[.]228[.]167 | 30 May 2026 | H | ServeTheWorld AS (NO); IP Insights threat_score 100, 8 blacklists incl. Emerging Threats Compromised, Brute Force Blocker, Malicious IP - SSH/brute-force cluster |
| IP | 79[.]143[.]178[.]79 | 31 May 2026 | H | contabo.DE; threat_score 100, 7 blacklists incl. ThreatFox malware family - staged loader infrastructure |
| IP | 176[.]65[.]139[.]151 | 01 Jun 2026 | H | Offshore LC (LU); threat_score 100, 7 blacklists - recurring bullet-proof hosting for brute-force |
| IP | 212[.]19[.]134[.]75 | 02 Jun 2026 | H | JSC Kazakhtelecom (KZ); threat_score 100, 8 blacklists; SSH/Telnet brute force at scale |
| IP | 27[.]79[.]41[.]68 | 03 Jun 2026 | H | Viettel Group (VN); threat_score 100, 7 blacklists; SSH brute force |
| IP | 103[.]77[.]246[.]158 | 04 Jun 2026 | H | Megacore Technology (VN); threat_score 100, 7 blacklists; sustained brute-force |
| IP | 34[.]86[.]81[.]254 | 31 May 2026 | M | Google LLC datacentre (US); IP Insights flagged 'critical'; abuse of cloud egress for compromised-stack traffic |
| IP | 136[.]117[.]199[.]185 | 02 Jun 2026 | M | Google LLC datacentre (US); IP Insights 'critical'; cloud-egress abuse |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via initial-access broker (Scattered Spider -> DragonForce / Qilin) | HIGH | HIGH | CRITICAL |
| Edge-appliance exploitation (Fortinet EMS / Cisco SD-WAN / Ivanti EPMM / Exchange OWA) | HIGH | HIGH | CRITICAL |
| EDR-control-plane compromise via Microsoft Defender BlueHammer chain | MEDIUM | HIGH | HIGH |
| Business email compromise / OAuth consent-phishing against finance functions and treasury | HIGH | MEDIUM | HIGH |
| Supply-chain compromise via BPO helpdesk or shared SaaS | MEDIUM | HIGH | HIGH |
| AI-enabled deepfake KYC bypass / synthetic-identity fraud in retail banking and insurance | HIGH | MEDIUM | HIGH |
| Russian-aligned hacktivist DDoS against UK FS public-facing services | MEDIUM | MEDIUM | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat Fortinet FortiClient EMS exploitation as the highest-priority hunting hypothesis for the next reporting cycle. Layer in BlueHammer hunting: any Defender MoCAMP build below 4.18.26040.1011, combined with a parent-process chain terminating in MsMpEng.exe writing to user-writable paths, should generate a high-priority case. Cross-walk EPMM admin logins against the documented CVE-2026-1340 / CVE-2026-6973 credential set and treat any login from pre-Feb-2026 admin credentials as suspect.
Defend
Preventive priorities follow Section 6 directly: patch Fortinet FortiClient EMS to 7.4.2 or later as the single highest-value action of the reporting cycle and restrict the admin endpoint to a management VLAN; verify Emergency Directive 26-03 closure on Cisco SD-WAN Controller and Manager and rotate any pre-patch SSH keys; force Microsoft Defender MoCAMP roll-up to 4.18.26040.1011 across FS endpoint estates; apply June 2026 Android security patch via MDM to any handset enrolled to a mobile-banking app. Rotate all EPMM admin credentials issued before 01 February 2026. For FS firms running self-hosted n8n, restrict the console to private network until the published patch is verified. Apply the BitLocker YellowKey mitigation and enforce TPM+PIN on regulated workstations. Reference ISO/IEC 27001 Annex A controls A.5.7 (threat intelligence), A.5.23 (information security for use of cloud services) and A.8.8 (management of technical vulnerabilities).
Disrupt
10. Forward outlook
Looking forward to the next reporting period (06 - 12 June 2026), it is likely that at least one UK FS firm will publicly disclose an incident traceable to the Fortinet FortiClient EMS, Cisco SD-WAN, EPMM or Exchange OWA vulnerabilities flagged in Section 6, with MEDIUM-HIGH confidence based on breadth of in-the-wild exploitation. It is highly likely that Qilin and TheGentlemen will continue at their current leak-site cadence, with at least one UK or EU FS or FS-adjacent professional-services entity named in the cycle. It is a realistic possibility that the n8n max-severity defect will be incorporated into Qilin or DragonForce affiliate tradecraft within 21 days of disclosure.
Trigger conditions that would prompt revision of this outlook include: (a) a UK FS firm publicly attributing a breach to FortiClient EMS exploitation, which would warrant immediate amber-level client advisories; (b) the appearance of a Qilin or Akira leak-site post naming a UK regulated FS entity; (c) FS-ISAC TLP:CLEAR notification of a sector-wide credential-stuffing or token-theft campaign; or (d) novel Scattered Spider tradecraft confirmed by NCSC-UK or partners that materially shifts the helpdesk threat model.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | CISA KEV Catalog updates 27 May, 02 Jun and 03 Jun 2026 - https://www.cisa.gov/known-exploited-vulnerabilities-catalog | CISA | A1 |
| 2 | CISA Alert - CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2022-0492, CVE-2025-48595), 02 Jun 2026 | CISA | A1 |
| 3 | CISA Alert - CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-45247), 03 Jun 2026 | CISA | A1 |
| 4 | NCSC-UK weekly threat report and advisory feed (week ending 05 Jun 2026) - https://www.ncsc.gov.uk/section/keep-up-to-date/threat-reports | NCSC | A1 |
| 5 | ESET APT Activity Report - October 2025 to March 2026 | ESET | B2 |
| 6 | Health-ISAC Heartbeat & 2026 Global Health Sector Threat Landscape Report | Health-ISAC | A2 |
| 7 | Check Point Research - Ransomware Quarterly Insights and May 2026 retrospective | Check Point Research | B2 |
| 8 | BreachSense - May 2026 Ransomware Report (646 victims, 61 groups) | BreachSense | C2 |
| 9 | Ransomware.live - leak-site tracker (Qilin / TheGentlemen / Akira / DragonForce postings, w/e 05 Jun 2026) | Ransomware.live | C2 |
| 10 | watchTowr Labs - Fortinet FortiClient EMS Zero-Day CVE-2026-35616, 02 Jun 2026 | watchTowr | B2 |
| 11 | The Hacker News - Microsoft mitigation for YellowKey BitLocker bypass CVE-2026-45585 | The Hacker News | B2 |
| 12 | The Hacker News - Microsoft warns of two actively exploited Defender vulnerabilities (BlueHammer) | Microsoft / The Hacker News | B1 |
| 13 | CyberScoop - researchers warn of max-severity defect in n8n self-hosted | CyberScoop | B2 |
| 14 | IP Insights - IP reputation enrichment (https://www.ipinsights.io) | UK Cyber Defence Ltd | B2 |
| 16 | FS-ISAC standing AI-hardening and deepfake-fraud advisory | FS-ISAC | A2 |
| 17 | BreachSense - May 2026 Ransomware Report: 646 victims, 61 groups; UK 2nd globally with 36 victims | BreachSense | C2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Financial services threat intelligence report — 4–8 May 2026
During the reporting period the financial-services threat picture continued to be dominated by ransomware and pure data-extortion crews…
Financial services threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the financial-services threat picture remained dominated by ransomware and pure data-extortion crews against a backdrop of continued AI-accelerated patch-wave dynamics.
Financial services threat intelligence report — 27 April – 3 May 2026
During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers.