SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Financial services threat intelligence report — 13–19 June 2026

All assessments use estimative language and confidence ratings per Section 11.

  • Reference: TI-2026-0619-001 (public edition)
  • Sector: Financial services, banking, fintech and insurance
  • Reporting period: 13–19 June 2026
  • Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Financial Services, Banking, Fintech and Insurance sector during the period 13 Jun 2026 - 19 Jun 2026. All assessments use estimative language and confidence ratings per Section 11.

During the reporting period the principal observations affecting this vertical were the addition of six further vulnerabilities to the CISA Known Exploited Vulnerabilities catalogue across 09, 15 and 16 June, three of them confirmed under active in-the-wild exploitation and at least two (Cisco Catalyst SD-WAN Manager CVE-2026-20245 and CVE-2026-20262, Arista EOS CVE-2026-7473) carrying material relevance to FS perimeter and core-routing estates. NCSC has reissued advisories on Citrix NetScaler ADC / Gateway (CVE-2026-3055 and CVE-2026-4368). FS-ISAC continues to flag the Scattered Spider / DragonForce cluster as the dominant initial-access-broker risk for UK consumer-banking and retail-fintech estates following the 2025 M&S / Co-op / Harrods campaign. Ransomware leak-site activity for the period was led by Qilin and DragonForce, both directly active against finance-adjacent victims. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that ransomware and pure data-extortion crews - Qilin, TheGentlemen, Akira, DragonForce and the Lynx / ShinyHunters cluster - will continue to drive the majority of materially-disruptive incidents against UK and EU FS firms during the next reporting cycle. [HIGH]
  2. It is highly likely that CVE-2026-20245 and CVE-2026-20262 (Cisco Catalyst SD-WAN Manager) will produce at least one publicly disclosed exploitation event affecting a UK or EU FS firm within the next two reporting cycles, given confirmed in-the-wild exploitation, the absence of an upstream patch for the highest-severity CLI defect and the prevalence of SD-WAN Manager in the FS WAN-edge estate. [HIGH]
  3. It is likely that the Arista EOS tunnel-decap defect (CVE-2026-7473) will be repurposed by initial-access brokers as a lateral-movement primitive against FS data-centre estates where Arista is deployed, since the no-patch mitigation-only posture forces configuration discipline that will not be uniformly applied. [MEDIUM-HIGH]
  4. It is likely that AI-driven KYC bypass - real-time deepfake voice and video, synthetic-identity generation and automated spear-phish targeting C-suite finance functions - will continue to expand as a fraud-adjacent threat vector through Q3 2026, consistent with the FS-ISAC AI advisory of April 2026. [MEDIUM]

2. Sector threat landscape

The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. The collection picture for this period is dominated by edge-appliance and identity-provider exposure - specifically Cisco Catalyst SD-WAN Manager, Arista EOS, Citrix NetScaler ADC / Gateway, and LiteSpeed cPanel - against a steady backdrop of ransomware leak-site posting led by Qilin, DragonForce, Akira and the relatively young TheGentlemen group. The Scattered Spider / DragonForce cluster that materially disrupted M&S, Co-op and Harrods through April and May 2025 continues to define the operational threat picture for FS-adjacent retail banking, payment processing and insurance-quote platforms, with social-engineering of IT service desks and outsourced helpdesk staff the principal initial-access mechanism.

Edge-appliance and identity-provider exposure remains the most operationally consequential collection theme this week. CISA added the Cisco Catalyst SD-WAN Manager defect CVE-2026-20245 to the KEV catalogue on 09 June with confirmed in-the-wild exploitation; a second SD-WAN Manager defect (CVE-2026-20262, path traversal) was added on 15 June. The Arista EOS tunnel-decap defect (CVE-2026-7473) was added on 09 June. CISA's 16 June addition (CVE-2026-48907, Joomla Widget Factory editor improper access control) is relevant to FS marketing / consumer-facing micro-sites where Joomla remains in use. On 15 June, CISA also added the LiteSpeed cPanel plugin symlink-following defect (CVE-2026-54420), relevant to FS-adjacent SaaS and hosting providers in scope under DORA outsourced-ICT controls.

Ransomware leak-site activity over the period was led, in volume terms, by Qilin (multiple posts targeting manufacturing and energy, with at least one finance-adjacent victim posted on 16 June) and DragonForce (seven posts during the period including a 16 June fastening-systems manufacturer in EMEA that supplies FS-aligned facilities). Akira, TheGentlemen and the Lynx / ShinyHunters cluster rounded out the leading set.

NCSC continues to flag CVE-2026-3055 and CVE-2026-4368 in Citrix NetScaler ADC / Gateway as immediate mitigation priorities for UK organisations and the FS estate inherits this directly: NetScaler Gateway sits in front of remote-working and contractor-VDI access across most UK retail banks and a significant share of UK insurance firms. FS-ISAC sector risk advisories from April 2026 continue to underline AI-driven fraud (deepfake KYC bypass, automated spear-phish) as a strategic risk that should drive controls investment, with the global sector strategy refresh announced at the FS-ISAC Americas Spring Summit in March 2026 explicitly naming supply-chain risk, geopolitical shifts and fraud as the principal collection priorities for the rest of the year.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Qilin (a.k.a. Agenda)

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + leak-site extortion
  • Sector Targeting: Manufacturing, energy, financial services, healthcare, professional services
  • Geographic Focus: Global; sustained EU and UK targeting through 2026
  • Signature TTPs: Initial access via phishing and exposed VPN / RDP; lateral movement via valid accounts; rapid escalation and AD-wide encryption; data exfiltration via Rclone to Mega / Backblaze prior to encryption
  • Tooling / Malware Families: Qilin / Agenda ransomware (Rust and Go builders), Cobalt Strike, AnyDesk, Rclone, PsExec
  • Recent Activity: Active leak-site posting through the reporting period including a 16 June FS-adjacent post; broad volume leadership across manufacturing and energy with at least one finance-adjacent victim
  • Assessed Threat to Vertical: HIGH - dominant volume across FS-adjacent verticals during the reporting period
  • Analytic Confidence: HIGH

DragonForce / Scattered Spider cluster

  • Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
  • Suspected Origin: Western (UK / US) English-speaking criminal cluster + DragonForce RaaS infrastructure
  • Suspected Sponsor: Criminal
  • Primary Motivation: Financial - extortion via encryption and data leak
  • Sector Targeting: Retail, financial services, hospitality, telecoms, BPO / outsourced helpdesk providers
  • Geographic Focus: UK and US primary; spreading EMEA
  • Signature TTPs: IT-service-desk social engineering for MFA reset and password reset; Okta / Entra session hijack; rapid AD compromise; data theft via Rclone; deployment of DragonForce affiliate ransomware
  • Tooling / Malware Families: Okta admin abuse, Teleport, Ngrok, Mimikatz, Cobalt Strike, DragonForce ransomware
  • Recent Activity: Continued leak-site activity during the period; reporting indicates ongoing UK targeting in retail-banking and insurance ahead of summer-trading peaks
  • Assessed Threat to Vertical: HIGH - direct UK FS targeting with proven business-disruption capability from the 2025 M&S / Co-op campaign
  • Analytic Confidence: HIGH

Akira

  • Aliases: Akira, Storm-1567 (some Microsoft attribution overlaps)
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + extortion
  • Sector Targeting: Financial services, professional services, manufacturing, education
  • Geographic Focus: Global; consistent UK / EU presence
  • Signature TTPs: Initial access via Cisco ASA / FTD SSL VPN brute force and exposed admin panels; abuse of valid accounts; rapid network mapping; data exfiltration; ChaCha20 ransomware encryption
  • Tooling / Malware Families: Akira ransomware (Linux and Windows variants), AnyDesk, RustDesk, WinSCP, Mimikatz
  • Recent Activity: Continued leak-site activity through the reporting period including 16 June FS-adjacent posts
  • Assessed Threat to Vertical: HIGH - persistent direct FS leak-site activity
  • Analytic Confidence: HIGH

BlueNoroff / Sapphire Sleet (DPRK)

  • Aliases: APT38, BlueNoroff, Sapphire Sleet, Dangerous Password, CryptoCore
  • Suspected Origin: Democratic People's Republic of Korea
  • Suspected Sponsor: Nation-state (DPRK Reconnaissance General Bureau, Lab 110)
  • Primary Motivation: Revenue generation for the DPRK regime - crypto theft, SWIFT-style fraud, fintech and FS targeting
  • Sector Targeting: Cryptocurrency exchanges, fintech, banking, defi platforms, FS sub-contractors
  • Geographic Focus: Global; FS-aligned firms in UK, US, EU, JP, KR
  • Signature TTPs: Social-engineering pretext (recruiter / venture-capitalist), LinkedIn / Telegram targeting of FS staff, malicious macOS / Windows installers, credentialed cloud access, in-memory tooling
  • Tooling / Malware Families: RustBucket, KandyKorn, ObjCShellz, custom Go / Rust loaders
  • Recent Activity: Continuing DPRK fintech targeting consistent with reporting trends through Q1-Q2 2026
  • Assessed Threat to Vertical: MEDIUM-HIGH for crypto / fintech sub-vertical, MEDIUM for traditional retail banking
  • Analytic Confidence: MEDIUM

[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1190Exploit Public-Facing ApplicationMass exploitation of Cisco Catalyst SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) at WAN-edge appliances feeding FS estatesHIGH
Initial AccessT1078Valid AccountsScattered Spider / DragonForce social-engineering of helpdesk and BPO staff for MFA reset; Akira valid-account abuse against Cisco SSL VPNHIGH
Initial AccessT1566.001Spearphishing AttachmentBlueNoroff / Sapphire Sleet pretext lures to FS / fintech staff via LinkedIn and Telegram; recruiter-themed targetingMEDIUM
ExecutionT1059.001Command and Scripting Interpreter: PowerShellCobalt Strike beacon execution post-initial-access during Qilin / Akira intrusionsHIGH
PersistenceT1136Create AccountScattered Spider creation of attacker-controlled federation accounts in Entra ID / Okta after initial helpdesk compromiseHIGH
Defense EvasionT1562.001Disable or Modify ToolsTampering with EDR services prior to encryption; Defender registry-disable patterns continue to feed Blackbit-shape detectionsMEDIUM
Collection / ExfiltrationT1567.002Exfiltration to Cloud StorageRclone to Mega / Backblaze / Wasabi consistently observed across Qilin and DragonForce campaigns prior to encryptionHIGH
ImpactT1486Data Encrypted for ImpactEncryption phase of Qilin, Akira, DragonForce and TheGentlemen across the reporting periodHIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
09 Jun 2026Cisco Catalyst SD-WAN Manager (vendor)UnattributedCVE-2026-20245 added to CISA KEV with confirmed in-the-wild exploitation; FS WAN-edge estates exposed pending mitigationCISA KEV / Cisco PSIRT
09 Jun 2026Arista EOS (vendor)UnattributedCVE-2026-7473 added to CISA KEV; tunnel-decap defect with no-patch mitigation-only posture affecting FS data-centre estatesCISA KEV / Arista Networks
15 Jun 2026Cisco Catalyst SD-WAN Manager (vendor)UnattributedSecond SD-WAN Manager defect CVE-2026-20262 (path traversal) added to KEV; FS-aligned firms with SD-WAN Manager required to act within CISA timelinesCISA KEV / Cisco PSIRT
15 Jun 2026LiteSpeed cPanel plugin (vendor)UnattributedCVE-2026-54420 symlink following added to KEV; FS-adjacent SaaS and hosting providers in scope under DORA outsourced-ICT controlsCISA KEV / LiteSpeed Technologies
16 Jun 2026Joomla Widget Factory editor (vendor)UnattributedCVE-2026-48907 added to KEV; affects FS marketing micro-sites and consumer-facing portals still on JoomlaCISA KEV
16 Jun 2026FS-adjacent (Qilin leak-site post)QilinLeak-site posting on 16 June consistent with FS supply-chain targeting; victim attribution withheld pending corroborationransomware.live / Insikt Group
15 Jun 2026Manufacturing supplier to FS facilities (DragonForce leak)DragonForceTecfi (fastening systems) posted to DragonForce leak site, estimated attack date 15 June; supplier exposure into FS branch / building servicesransomware.live
17 Jun 2026UK CNI (NCSC public commentary)Multiple state actorsNCSC CEO at RUSI: more than 200 CNI incidents in the year to May, ~75% assessed state-actor; FS is a designated CNI sub-sector and inherits the threat profile directlyNCSC / RUSI / The Record

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-20262Cisco Catalyst SD-WAN Manager - directory / path traversal8.6YesYesApply vendor mitigation; restrict management plane to jumpbox-only access; monitor file-system access patterns
CVE-2026-7473Arista EOS - tunnel decap incomplete comparison (no patch as of period)7.5YesYesEnforce tunnel allow-list; deploy ACLs on decap interfaces; harden BGP / OSPF authentication
CVE-2026-3055Citrix NetScaler ADC / Gateway - memory disclosure7.4No (NCSC advisory)SuspectedApply Citrix advisory mitigation; rotate session secrets; monitor for anomalous gateway sessions
CVE-2026-4368Citrix NetScaler ADC / Gateway - authentication bypass9.1No (NCSC advisory)SuspectedPatch immediately per NCSC; rotate gateway service accounts; force session reset for all interactive users
CVE-2026-54420LiteSpeed cPanel plugin - symlink following7.5YesYesPatch per LiteSpeed advisory; FS firms in scope under DORA outsourced-ICT controls should confirm with hosting providers
CVE-2026-48907Joomla Widget Factory / JCE editor - improper access control8.6YesYesPatch JCE editor on FS marketing / micro-sites; remove unused Joomla deployments
CVE-2026-11645Google Chromium V8 - out-of-bounds read / write8.8YesYesForce Chrome / Edge update in FS workstation estate via Intune / SCCM; verify against KEV due-date
CVE-2026-45247Mirasvit / Magento storefront platform - mass-scanning candidate8.2NoSuspectedAudit FS-adjacent payment processors and insurance-quote platforms; deploy WAF virtual patches

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]100[.]24011 May 2026HIGHF3 Netze AS205100 Tor exit; IP Insights threat score 100/critical; seven active blocklists; observed in FS-perimeter brute-force tail
IP45[.]142[.]122[.]4114 Jun 2026MEDIUMFirst Server Limited (VG / BVI); IP Insights low score but persistent SSH / OWA brute pattern; recommend WAF blocklist
IP194[.]180[.]48[.]13915 Jun 2026MEDIUMServerion (NL) hosting; persistent OWA / Citrix Gateway brute pattern; recommend perimeter blocklist
IP146[.]70[.]180[.]1312 Jun 2026MEDIUMM247 (RO) hosting; sustained credential-stuffing pattern against FS public-facing portals
IP23[.]95[.]87[.]4516 Jun 2026MEDIUMHostPapa (US) hosting; flagged as hosting + datacenter; persistent low-volume scanning
Domainsecure-fs-login[.]top13 Jun 2026HIGHNewly registered phishing infrastructure for FS portal impersonation; recommended takedown via NCSC
URLhxxps://files[.]bbnewsbrief[.]com/invoice-jun26.pdf16 Jun 2026MEDIUMBEC lure observed in FS finance-function inbox cohort; redirect chain terminates on Cloudflare-fronted credential-harvest page
Email-senderno-reply@swift-paymentnet[.]com17 Jun 2026MEDIUMSpoofed SWIFT payment-notification sender used in FS BEC attempts during the period

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Ransomware deployment via Cisco SD-WAN Manager exploitationHHCRITICAL
Business email compromise targeting finance function with deepfake voice authorisationHHCRITICAL
Supply-chain compromise via shared SaaS payment processor or insurance quote platformMHHIGH
Helpdesk social-engineering enabling Scattered Spider-style Okta / Entra session hijackHHCRITICAL

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Defend

Preventive priorities follow Section 6 directly: there is no vendor patch for CVE-2026-20245 or CVE-2026-7473 as at issue date, so mitigation-only postures must be enforced - restrict netadmin role membership, rotate netadmin credentials, restrict management plane to jumpbox-only access, enforce ACLs on Arista tunnel-decap interfaces, harden BGP / OSPF authentication. Apply NCSC mitigation for NetScaler ADC / Gateway (CVE-2026-3055 and CVE-2026-4368) and rotate gateway session secrets / service accounts. Patch LiteSpeed cPanel plugin (CVE-2026-54420), the Joomla Widget Factory editor (CVE-2026-48907) and force-update Chrome / Edge across the workstation estate for the V8 defect CVE-2026-11645. Reinforce helpdesk MFA-reset playbooks against Scattered Spider-style social-engineering: mandatory callback to directory-verified number, mandatory manager attestation, mandatory cooling-off period for high-privilege accounts. Validate deepfake-resistant out-of-band authorisation for high-value payments per the April 2026 FS-ISAC AI advisory.

Disrupt

10. Forward outlook

Looking forward to the next reporting period (20-26 Jun 2026), it is likely that at least one UK FS firm will publicly disclose an incident traceable to one of the Cisco SD-WAN Manager, Arista EOS, Citrix NetScaler or LiteSpeed cPanel defects in Section 6, given the combination of confirmed in-the-wild exploitation, no-patch mitigation-only postures on the two most severe defects, and the prevalence of these products in the UK FS WAN / edge estate. We assess it is highly likely that Qilin, DragonForce and Akira will maintain leak-site volume leadership, with at least one further FS-adjacent leak-site posting expected within the period. We assess it is a realistic possibility that Scattered Spider will conduct at least one helpdesk-engineered intrusion against a UK retail-banking or insurance firm; the M&S / Co-op / Harrods template remains operationally proven and continues to be reused.

Trigger conditions that would prompt revision of this outlook include: (a) a UK FS firm publicly attributing a breach to Cisco SD-WAN Manager or Arista EOS exploitation, which would warrant immediate out-of-cycle reporting; (b) emergence of a vendor patch for CVE-2026-20245 or CVE-2026-7473, which would shift the risk profile substantially; (c) a UK retail-banking helpdesk compromise matching the Scattered Spider / DragonForce template, which would warrant immediate FS-ISAC and CISP trust-group escalation; (d) observation of any IP Insights 'critical' tail indicator showing successful authentication into a client FS estate.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC-UK weekly threat reports and reports/advisories portalNational Cyber Security CentreA1
2CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feedCybersecurity & Infrastructure Security AgencyA1
3MITRE ATT&CK Enterprise v15.1 framework and technique catalogueMITRE CorporationA1
4Mandiant M-Trends 2026 and Threat Intelligence advisoriesGoogle / MandiantB2
5Microsoft Threat Intelligence operational reports and Tempest namingMicrosoft CorporationB2
6CrowdStrike Global Threat Report 2026 and Adversary Universe updatesCrowdStrike HoldingsB2
7Cisco Talos research and weekly threat round-upCisco Talos Intelligence GroupB2
8Sophos X-Ops research blog and quarterly threat reportsSophos LtdB2
9Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo TrackerSpamhaus / abuse.chB2
10Ransomware.live aggregated leak-site monitoringransomware.liveC2
11Recorded Future Insikt Group operational reportsRecorded Future, Inc.B2
12GreyNoise scanning intelligence and tag observationsGreyNoise Intelligence, Inc.B2
13IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feedsUK Cyber Defence LtdA1
15CISP indicator and incident summaries (peer-shared, trust-group)NCSC Cyber Security Information Sharing PartnershipA2
16FS-ISAC AI Cybersecurity Hardening Advisory (April 2026)Financial Services Information Sharing and Analysis CenterA1
17FS-ISAC 2026 Americas Spring Summit strategy refresh (Mar 2026)Financial Services Information Sharing and Analysis CenterA1
18Cisco PSIRT advisories cisco-sa-sdwan-manager-2026 (CVE-2026-20245 / 20262)Cisco Systems, Inc.A1
19Citrix NetScaler ADC / Gateway advisory (CVE-2026-3055 / 4368)Citrix / Cloud Software GroupA1
20NCSC CEO speech, RUSI Annual Security Lecture, 17 June 2026National Cyber Security Centre / RUSIB1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.