Financial services threat intelligence report — 6–12 June 2026
The financial-services collection picture this week has been dominated by the addition of six further vulnerabilities to the CISA KEV catalogue, three of them confirmed under active in-the-wild exploitation against FS-relevant edge infrastructure: Cisco Catalyst SD-WAN Manager (CVE-2026-20245…
- Reference: TI-2026-0612-001 (public edition)
- Sector: Financial services, banking, fintech and insurance
- Reporting period: 6–12 June 2026
- Issued: 12 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Financial Services, Banking, Fintech and Insurance sector during the period 06 Jun 2026 - 12 Jun 2026. It is intended to support security leadership and operational defenders within the vertical and is issued under TLP:CLEAR.
The financial-services collection picture this week has been dominated by the addition of six further vulnerabilities to the CISA KEV catalogue, three of them confirmed under active in-the-wild exploitation against FS-relevant edge infrastructure: Cisco Catalyst SD-WAN Manager (CVE-2026-20245, the seventh SD-WAN zero-day of 2026, no patch available), Arista EOS tunnel-decap (CVE-2026-7473, no patch planned) and Chromium V8 (CVE-2026-11645). The Mirasvit Magento deserialisation defect (CVE-2026-45247) is acutely relevant to FS-adjacent storefronts and payment-processor estates. The Citrix NetScaler ADC / Gateway advisories (CVE-2026-3055 / -4368) issued by NCSC during the period continue to demand priority attention across UK FS perimeters.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware and pure data-extortion crews - Qilin, TheGentlemen, Akira, DragonForce and the Lynx / ShinyHunters cluster - will continue to drive the majority of materially-disruptive activity affecting UK and European FS entities over the next reporting cycle, with the Scattered Spider IAB front-end continuing to target outsourced helpdesk and customer-service supply chains. (HIGH confidence)
- It is highly likely that CVE-2026-20245 (Cisco Catalyst SD-WAN Manager) will produce at least one publicly-disclosed exploitation event affecting a UK or EU FS firm within the next two reporting cycles, given the no-patch status, the prevalence of Cisco SD-WAN in retail-banking and insurance-broker estates, and the seventh-of-the-year cadence of SD-WAN zero-days. (MEDIUM-HIGH confidence)
- It is likely that the Arista EOS tunnel-decap defect (CVE-2026-7473) will be repurposed by IABs as a lateral-movement primitive against FS data-centre estates where Arista is deployed, since the no-patch posture combined with the protocol-conflation primitive provides a durable foothold path. (MEDIUM confidence)
- It is likely that Mirasvit / Magento storefronts attached to FS-adjacent payment processors and insurance-quote platforms will see opportunistic mass-scanning against CVE-2026-45247 within the next reporting cycle. (MEDIUM confidence)
- It is highly likely that AI-driven KYC bypass - real-time deepfake voice and video, synthetic identity generation and automated spear-phish targeting the C-suite - will continue to grow as a fraud-adjacent risk for retail banking and insurance carriers, consistent with FS-ISAC's April 2026 sector advisory on AI-driven cyber risk. (HIGH confidence)
2. Sector threat landscape
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. Check Point Research's State of Ransomware Q1 2026 records 338 victims claimed by Qilin alone in the quarter; BreachSense's May 2026 retrospective places Qilin at 97-101 victims for the month, its fifth consecutive month at the top of leak-site postings. TheGentlemen, Akira and DragonForce occupy the next three positions with 70, 64 and 32 victims respectively, and the trailing thirty-day window across all groups represents approximately 115 TB of reportedly-stolen data. The United Kingdom continues to place second globally in victim count, behind only the United States.
Edge-appliance and identity-provider exposure remains the most operationally consequential collection theme this week. The Cisco Catalyst SD-WAN Manager defect CVE-2026-20245 was added to the CISA KEV catalogue on 09 June with active in-the-wild exploitation already confirmed by Cisco PSIRT; the authenticated CLI command-injection primitive elevates to root via crafted-file upload, and Cisco have observed at least one case where exploitation has been used to push configuration changes down to edge devices. No patch is available at issue. The Arista EOS tunnel-decap defect CVE-2026-7473, also added to KEV on 09 June, carries no planned vendor patch; the protocol-conflation behaviour allows attacker-controlled tunnels of one type to be accepted at decap interfaces configured only for another, providing a durable lateral-movement primitive against FS data-centre and inter-DC fabric estates.
The Citrix NetScaler ADC / Gateway advisories (CVE-2026-3055 and CVE-2026-4368) flagged by NCSC during the period continue to demand priority attention across UK FS perimeters. NCSC's NetScaler take-action notice combines with the still-warm Fortinet FortiClient EMS CVE-2026-35616 (pre-auth RCE; watchTowr confirmed in-the-wild on 02 June) to define a perimeter-edge threat picture in which two FS-prevalent VPN / identity-broker platforms are simultaneously under active targeting. The Microsoft Defender BlueHammer disclosure (CVE-2026-33825) presents an unusually consequential local-privilege-escalation / defence-evasion primitive against the very EDR control plane on which most FS detection programmes depend.
The Scattered Spider / DragonForce cluster that materially disrupted M&S, Co-op and Harrods through April-May 2025 continues to define the operational threat picture for FS-adjacent retail banking and insurance, with the 2026 pivot remaining toward banking BPO, outsourced helpdesk and the customer-service supply chain of regulated FS firms. FS-ISAC's standing AI-hardening advisory (April 2026) and the H-ISAC / FS-ISAC joint deepfake-fraud notes continue to apply.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda, Qilin.B)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russia (Russian-speaking)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion / data theft
- Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
- Geographic Focus: Global; UK, EU, US, ANZ
- Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
- Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
- Recent Activity: 97-101 victims posted in May 2026 - fifth consecutive month at top of leak-site postings (BreachSense / Check Point).
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: HIGH - multiply sourced (Check Point Research, BreachSense, Ransomware.live)
TheGentlemen
- Aliases: -
- Suspected Origin: Unattributed (likely Russian-speaking)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion
- Sector Targeting: Cross-sector with sustained Financial Services, Banking, Fintech and Insurance relevance.
- Geographic Focus: Cross-sector, global
- Signature TTPs: Rapid affiliate onboarding; multi-platform encryptor (Windows / Linux / BSD / NAS); SystemBC C2
- Tooling / Malware Families: Go-based encryptor; SystemBC; partner-supplied IAB access
- Recent Activity: 70 victims posted in May 2026 - second only to Qilin (BreachSense).
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: MEDIUM-HIGH
Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine
- Suspected Origin: UK / US / English-speaking community
- Suspected Sponsor: Criminal (IAB into DragonForce / LockBit / Qilin)
- Primary Motivation: Financial - extortion via partner ransomware
- Sector Targeting: Cross-sector with sustained FS relevance via banking BPO and outsourced helpdesks.
- Geographic Focus: UK, US, increasing EU and outsourced helpdesks abroad
- Signature TTPs: Voice-phishing of IT helpdesks, SIM-swap, MFA fatigue, OAuth consent-phish, RMM abuse (AnyDesk / ScreenConnect)
- Tooling / Malware Families: DragonForce / LockBit / Qilin partner encryptors; ESXi mass-encryption
- Recent Activity: DragonForce 32 victims in May 2026 (down from 41 in April per BreachSense); BPO / outsourced-helpdesk pattern continues.
- Assessed Threat to Vertical: HIGH - Admiralty A2.
- Analytic Confidence: HIGH - NCSC-UK, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced
Lazarus / BlueNoroff sub-clusters
- Aliases: APT38, BlueNoroff, Sapphire Sleet, DangerousPassword
- Suspected Origin: Democratic People's Republic of Korea
- Suspected Sponsor: State (Reconnaissance General Bureau)
- Primary Motivation: Financial - revenue generation for DPRK; cryptocurrency theft
- Sector Targeting: FS with crypto / digital-asset exposure primary.
- Geographic Focus: Global; UK and EU FS firms with crypto exposure
- Signature TTPs: Fake-recruiter LinkedIn lures; trojanised PDF readers; living-off-the-land in CI/CD pipelines
- Tooling / Malware Families: AppleJeus, ManageBus, RustBucket, custom Python loaders
- Recent Activity: ESET APT activity report (May 2026) flags continuing UK / EU crypto-FS targeting; aligned with US-CERT joint advisory.
- Assessed Threat to Vertical: HIGH - for crypto-FS subset; Admiralty B2.
- Analytic Confidence: HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Mass exploitation of Cisco Catalyst SD-WAN Manager (CVE-2026-20245), Arista EOS tunnel-decap (CVE-2026-7473), Fortinet FortiClient EMS (CVE-2026-35616) and Citrix NetScaler (CVE-2026-3055 / -4368) against FS perimeters. | HIGH |
| Initial Access | T1566.002 | Spear-phishing Link | Voice-phishing of outsourced IT helpdesks and OAuth consent-phishing of M365 tenants; Scattered Spider continuing tradecraft. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud | Reuse of IAB-purchased VPN credentials, harvested NetScaler session tokens and FortiClient EMS admin credentials. | HIGH |
| Execution | T1059.001 | Command and Scripting: PowerShell | Encoded PowerShell loaders staging SystemBC and Cobalt Strike Beacon in Qilin and TheGentlemen tradecraft. | MEDIUM |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Cisco SD-WAN Manager CLI command-injection (CVE-2026-20245) and Microsoft Defender BlueHammer chain (CVE-2026-33825) used to obtain root / SYSTEM. | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGAcmd / AzCopy push to attacker-controlled cloud destinations prior to encryption. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | ESXi-aware Qilin.B and DragonForce encryptors continue mass-encryption of hypervisor estates. | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | CVE-2026-20245 added to CISA KEV; ITW exploitation confirmed by Cisco PSIRT - seventh SD-WAN zero-day of 2026; configuration push to edge devices observed; no patch available. | CISA / Cisco PSIRT / The Hacker News |
| 09 Jun 2026 | Arista EOS (vendor) | Unattributed | CVE-2026-7473 added to CISA KEV; tunnel-decap conflation primitive; no patch planned. | CISA / Arista Security Advisory 0137 |
| 09 Jun 2026 | Google Chromium V8 (browser) | Unattributed | CVE-2026-11645 added to CISA KEV; FS-relevant browser-side RCE. | CISA / Google |
| 03 Jun 2026 | Mirasvit Magento (vendor) | Unattributed | CVE-2026-45247 deserialisation; payment-processor / FS-adjacent storefront relevance. | CISA |
| 02 Jun 2026 | Fortinet FortiClient EMS (vendor) | Unattributed | CVE-2026-35616 ITW confirmed by watchTowr Labs; pre-auth RCE. | watchTowr Labs |
| Ongoing | Qilin / TheGentlemen / Akira / DragonForce leak sites | Multiple | May 2026: Qilin 97-101, TheGentlemen 70, Akira 64, DragonForce 32; UK = second highest national victim count. | BreachSense / Check Point Research |
| Continuing | Scattered Spider / DragonForce campaign | UNC3944 | Continuing focus on banking BPO, outsourced helpdesk and customer-service supply chain. | NCSC / Sophos X-Ops |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command-injection (authenticated, netadmin) | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; ACL Manager to management VLAN; monitor for crafted file uploads. No vendor patch at issue. |
| CVE-2026-7473 | Arista EOS - tunnel-protocol type not validated on decap interface (no patch planned) | 6.9 | Yes | Yes | Apply Arista mitigation: explicit per-protocol decap-group configuration; ACL the tunnel-endpoint IP; consider removal of decap on edge. |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read/write, browser-side RCE | 8.8 | Yes | Yes | Force-update Chrome and Chromium-derived browsers (Edge, Brave) across the fleet; enforce Site Isolation; verify SmartScreen / SafeBrowsing telemetry. |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer for Magento - deserialisation of untrusted data | 9.8 | Yes | Yes | Patch Mirasvit extension to vendor-supplied build; restrict admin/cache endpoints to internal IP space; rotate any captured admin tokens. |
| CVE-2025-48595 | Android Framework - integer overflow, limited targeted exploitation | 7.8 | Yes | Yes | Enforce June 2026 Android security patch level on managed devices via MDM; deprovision devices unable to receive the update. |
| CVE-2022-0492 | Linux Kernel cgroup release_agent - container escape (revived for cloud workloads) | 7.8 | Yes | Yes | Enforce seccomp / AppArmor / SELinux on container hosts; verify kernel >= 5.16.4 or backported patches; restrict unprivileged user namespaces. |
| CVE-2026-35616 | Fortinet FortiClient EMS - pre-auth RCE; watchTowr confirmed ITW exploitation 02 Jun (carry) | 9.8 | Yes | Yes | Patch to 7.4.2 or later; restrict EMS admin interface to management VLAN; hunt for new local accounts and outbound HTTP from EMS hosts. |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform - BlueHammer LPE / defence-evasion (carry) | 8.4 | Yes | Yes | Force MoCAMP rollout to 4.18.26040.1011 or later; hunt for FortiGate SSL-VPN sessions terminating from RU/SG/CH source IPs. |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - NCSC take-action notice (carry) | 9.1 | No | Suspected | Apply Citrix firmware; rotate NetScaler session tokens; force re-authentication across Gateway tenants; review for AAA-vserver tampering. |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - companion NCSC advisory (carry) | 8.8 | No | Suspected | Apply Citrix firmware bundle; baseline configuration drift; monitor for new admin or read-only accounts. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 85[.]137[.]228[.]167 | 24 May 2026 | HIGH | ServeTheWorld AS (NO, AS34989) - perimeter SSH/CMS brute-force; IP Insights threat=critical, 9 blacklists. |
| IP | 79[.]143[.]178[.]79 | 24 May 2026 | HIGH | Contabo (DE) - perimeter brute-force; IP Insights threat=critical, 8 blacklists. |
| IP | 51[.]68[.]226[.]87 | 02 Jun 2026 | HIGH | OVH SAS (FR, AS16276) - datacentre IP; carry-IOC sweep; IP Insights threat=critical, 6 blacklists. |
| IP | 136[.]232[.]11[.]10 | 02 Jun 2026 | HIGH | Reliance Jio (IN, AS55836) - carry-IOC; IP Insights threat=critical, 7 blacklists. |
| IP | 165[.]154[.]105[.]128 | 02 Jun 2026 | HIGH | UCLOUD HK (VN, AS135377) - datacentre; carry-IOC; IP Insights threat=critical, 7 blacklists. |
| ASN | AS135377 (UCLOUD HK) | 12 Jun 2026 | HIGH | IP Insights ASN risk=critical (81); 807/1000 sampled IPs blacklisted; recommend AS-level edge denial for low-business-need ASNs. |
| ASN | AS60729 (TorServers / Stiftung Erneuerbare Freiheit) | 12 Jun 2026 | HIGH | 190/191 sampled IPs blacklisted; treat Tor egress as inherently suspect for client estates. |
| ASN | AS51167 (Contabo) | 12 Jun 2026 | MEDIUM | IP Insights risk=high (52); 553/1000 sampled IPs blacklisted; common scanner / brute-force source. |
| Domain | login-citrix-portal-update[.]com | 10 Jun 2026 | MEDIUM | Suspected NetScaler-themed credential-phish; matches FS-helpdesk pattern. |
| SHA-256 | a1f3...2b9c (BlueHammer LPE loader fragment) | 04 Jun 2026 | MEDIUM | Microsoft BlueHammer / CVE-2026-33825 chain. |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via Cisco SD-WAN Manager or NetScaler initial-access broker | H | H | CRITICAL |
| Business email compromise / OAuth consent-phishing targeting M365 finance function | H | H | HIGH |
| Supply-chain compromise via shared SaaS platform or outsourced helpdesk (Scattered Spider pattern) | H | H | HIGH |
| Deepfake-assisted authorised-push-payment fraud or KYC bypass against retail banking / insurance | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat Cisco Catalyst SD-WAN Manager and Arista EOS exploitation as the two highest-priority hunting hypotheses for the next reporting cycle. Layer in BlueHammer LPE detection via process-create events for the signed-binary chain and antimalware service-state changes correlated against MoCAMP version. Maintain the standing FS-ISAC indicator ingestion pipeline.
Defend
Preventive priorities follow Section 6 directly: there is no patch available for CVE-2026-20245 or CVE-2026-7473, so mitigation-only postures must be enforced - restrict netadmin role membership, rotate netadmin credentials, restrict SD-WAN Manager access to a hardened management VLAN with MFA; apply Arista's per-protocol decap-group configuration and ACL the tunnel-endpoint IP; patch Fortinet FortiClient EMS to 7.4.2 or later as the single highest-value vendor-patch action of the reporting cycle and restrict the admin endpoint to a management VLAN; apply Citrix NetScaler firmware and rotate session tokens; force Microsoft Defender MoCAMP roll-up to 4.18.26040.1011 across FS endpoints; force Chromium update for CVE-2026-11645. Verify the Mirasvit / Magento Full Page Cache Warmer extension is patched on any payment-processor storefront.
Disrupt
Disruption activity within client lawful authority should focus on: (i) sustained participation in FS-ISAC indicator exchange, with this week's IP Insights 'critical' tail submitted as the highest-value contribution; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through registrar-abuse and Cloudflare / Microsoft / Google trust-and-safety channels; (iii) deception deployment on FS-relevant honeypot domains modelled on NetScaler and SD-WAN Manager landing pages; (iv) sector-level coordination through FS-ISAC of any UK-attributed Scattered Spider helpdesk-phish indicators surfaced during the reporting period.
10. Forward outlook
Looking forward to the next reporting period (13-19 Jun 2026), it is likely that at least one UK FS firm will publicly disclose an incident traceable to one of the Cisco SD-WAN Manager, Arista EOS, Fortinet FortiClient EMS, Citrix NetScaler or Microsoft Defender vulnerabilities flagged in Section 6, with MEDIUM-HIGH confidence based on the breadth of in-the-wild exploitation and the no-patch posture of both new SD-WAN and Arista defects. It is highly likely that Qilin and TheGentlemen will continue at the top of leak-site posting volumes, with the UK retaining its position as second-most-targeted nation. AI-driven KYC bypass and deepfake-assisted authorised-push-payment fraud is assessed as a realistic possibility for the retail-banking subset over the period.
Trigger conditions that would prompt revision of this outlook include: (a) a UK FS firm publicly attributing a breach to Cisco SD-WAN Manager or Arista EOS exploitation, which would warrant immediate amber-level client advisories; (b) the appearance of a Qilin, Akira or DragonForce leak-site post naming a UK regulated FS entity; (c) FS-ISAC TLP:CLEAR notification of a sector-wide credential-stuffing or token-theft campaign; (d) NCSC issuance of a follow-up Citrix NetScaler advisory escalating beyond the current take-action posture; or (e) confirmation that the Scattered Spider arrest cohort has not materially degraded the IAB front-end's operational capacity.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports & advisories index, https://www.ncsc.gov.uk/section/keep-up-to-date/reports-advisories | A1 | |
| 2 | CISA Known Exploited Vulnerabilities Catalogue, additions of 02 / 03 / 09 Jun 2026, https://www.cisa.gov/known-exploited-vulnerabilities-catalog | A1 | |
| 3 | CISA Adds Three KEV (Arista EOS, Chromium V8, Cisco SD-WAN Manager), 09 Jun 2026, https://www.cisa.gov/news-events/alerts/2026/06/09/cisa-adds-three-known-exploited-vulnerabilities-catalog | A1 | |
| 4 | 'Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited - No Patch Available', Jun 2026 | The Hacker News | B2 |
| 5 | 'No Patch Planned for Exploited Arista EOS Vulnerability (CVE-2026-7473)', Jun 2026 | SecurityWeek | B2 |
| 6 | Fortinet FortiClient EMS CVE-2026-35616 in-the-wild exploitation confirmation, 02 Jun 2026 | watchTowr Labs | B2 |
| 7 | May 2026 ransomware retrospective (Qilin 97-101, TheGentlemen 70, Akira 64, DragonForce 32; 115 TB stolen) | BreachSense | B2 |
| 8 | 'The State of Ransomware - Q1 2026', https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/ | Check Point Research | B2 |
| 10 | IP Insights threat-assessment lookups (X-API-Key authenticated), https://www.ipinsights.io | A2 | |
| 11 | MITRE ATT&CK Enterprise framework v15, https://attack.mitre.org | A1 | |
| 12 | Cisco Security Advisory cisco-sa-sdwan-privesc-4uxFrdzx, Jun 2026 | A1 | |
| 13 | EOS tunnel decap protocol-type validation | Arista Security Advisory 0137 | A1 |
| 14 | FS-ISAC sector risk advisory on AI-driven cyber risk, Apr 2026 | B2 | |
| 15 | DPRK financial-services targeting | ESET APT Activity Report May 2026 | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Financial services threat intelligence report — 4–8 May 2026
During the reporting period the financial-services threat picture continued to be dominated by ransomware and pure data-extortion crews…
Financial services threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the financial-services threat picture remained dominated by ransomware and pure data-extortion crews against a backdrop of continued AI-accelerated patch-wave dynamics.
Financial services threat intelligence report — 27 April – 3 May 2026
During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers.