Financial services threat intelligence report — 13–19 June 2026
All assessments use estimative language and confidence ratings per Section 11.
- Reference: TI-2026-0619-001 (public edition)
- Sector: Financial services, banking, fintech and insurance
- Reporting period: 13–19 June 2026
- Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Financial Services, Banking, Fintech and Insurance sector during the period 13 Jun 2026 - 19 Jun 2026. All assessments use estimative language and confidence ratings per Section 11.
During the reporting period the principal observations affecting this vertical were the addition of six further vulnerabilities to the CISA Known Exploited Vulnerabilities catalogue across 09, 15 and 16 June, three of them confirmed under active in-the-wild exploitation and at least two (Cisco Catalyst SD-WAN Manager CVE-2026-20245 and CVE-2026-20262, Arista EOS CVE-2026-7473) carrying material relevance to FS perimeter and core-routing estates. NCSC has reissued advisories on Citrix NetScaler ADC / Gateway (CVE-2026-3055 and CVE-2026-4368). FS-ISAC continues to flag the Scattered Spider / DragonForce cluster as the dominant initial-access-broker risk for UK consumer-banking and retail-fintech estates following the 2025 M&S / Co-op / Harrods campaign. Ransomware leak-site activity for the period was led by Qilin and DragonForce, both directly active against finance-adjacent victims. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware and pure data-extortion crews - Qilin, TheGentlemen, Akira, DragonForce and the Lynx / ShinyHunters cluster - will continue to drive the majority of materially-disruptive incidents against UK and EU FS firms during the next reporting cycle. [HIGH]
- It is highly likely that CVE-2026-20245 and CVE-2026-20262 (Cisco Catalyst SD-WAN Manager) will produce at least one publicly disclosed exploitation event affecting a UK or EU FS firm within the next two reporting cycles, given confirmed in-the-wild exploitation, the absence of an upstream patch for the highest-severity CLI defect and the prevalence of SD-WAN Manager in the FS WAN-edge estate. [HIGH]
- It is likely that the Arista EOS tunnel-decap defect (CVE-2026-7473) will be repurposed by initial-access brokers as a lateral-movement primitive against FS data-centre estates where Arista is deployed, since the no-patch mitigation-only posture forces configuration discipline that will not be uniformly applied. [MEDIUM-HIGH]
- It is likely that AI-driven KYC bypass - real-time deepfake voice and video, synthetic-identity generation and automated spear-phish targeting C-suite finance functions - will continue to expand as a fraud-adjacent threat vector through Q3 2026, consistent with the FS-ISAC AI advisory of April 2026. [MEDIUM]
2. Sector threat landscape
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. The collection picture for this period is dominated by edge-appliance and identity-provider exposure - specifically Cisco Catalyst SD-WAN Manager, Arista EOS, Citrix NetScaler ADC / Gateway, and LiteSpeed cPanel - against a steady backdrop of ransomware leak-site posting led by Qilin, DragonForce, Akira and the relatively young TheGentlemen group. The Scattered Spider / DragonForce cluster that materially disrupted M&S, Co-op and Harrods through April and May 2025 continues to define the operational threat picture for FS-adjacent retail banking, payment processing and insurance-quote platforms, with social-engineering of IT service desks and outsourced helpdesk staff the principal initial-access mechanism.
Edge-appliance and identity-provider exposure remains the most operationally consequential collection theme this week. CISA added the Cisco Catalyst SD-WAN Manager defect CVE-2026-20245 to the KEV catalogue on 09 June with confirmed in-the-wild exploitation; a second SD-WAN Manager defect (CVE-2026-20262, path traversal) was added on 15 June. The Arista EOS tunnel-decap defect (CVE-2026-7473) was added on 09 June. CISA's 16 June addition (CVE-2026-48907, Joomla Widget Factory editor improper access control) is relevant to FS marketing / consumer-facing micro-sites where Joomla remains in use. On 15 June, CISA also added the LiteSpeed cPanel plugin symlink-following defect (CVE-2026-54420), relevant to FS-adjacent SaaS and hosting providers in scope under DORA outsourced-ICT controls.
Ransomware leak-site activity over the period was led, in volume terms, by Qilin (multiple posts targeting manufacturing and energy, with at least one finance-adjacent victim posted on 16 June) and DragonForce (seven posts during the period including a 16 June fastening-systems manufacturer in EMEA that supplies FS-aligned facilities). Akira, TheGentlemen and the Lynx / ShinyHunters cluster rounded out the leading set.
NCSC continues to flag CVE-2026-3055 and CVE-2026-4368 in Citrix NetScaler ADC / Gateway as immediate mitigation priorities for UK organisations and the FS estate inherits this directly: NetScaler Gateway sits in front of remote-working and contractor-VDI access across most UK retail banks and a significant share of UK insurance firms. FS-ISAC sector risk advisories from April 2026 continue to underline AI-driven fraud (deepfake KYC bypass, automated spear-phish) as a strategic risk that should drive controls investment, with the global sector strategy refresh announced at the FS-ISAC Americas Spring Summit in March 2026 explicitly naming supply-chain risk, geopolitical shifts and fraud as the principal collection priorities for the rest of the year.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Manufacturing, energy, financial services, healthcare, professional services
- Geographic Focus: Global; sustained EU and UK targeting through 2026
- Signature TTPs: Initial access via phishing and exposed VPN / RDP; lateral movement via valid accounts; rapid escalation and AD-wide encryption; data exfiltration via Rclone to Mega / Backblaze prior to encryption
- Tooling / Malware Families: Qilin / Agenda ransomware (Rust and Go builders), Cobalt Strike, AnyDesk, Rclone, PsExec
- Recent Activity: Active leak-site posting through the reporting period including a 16 June FS-adjacent post; broad volume leadership across manufacturing and energy with at least one finance-adjacent victim
- Assessed Threat to Vertical: HIGH - dominant volume across FS-adjacent verticals during the reporting period
- Analytic Confidence: HIGH
DragonForce / Scattered Spider cluster
- Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
- Suspected Origin: Western (UK / US) English-speaking criminal cluster + DragonForce RaaS infrastructure
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - extortion via encryption and data leak
- Sector Targeting: Retail, financial services, hospitality, telecoms, BPO / outsourced helpdesk providers
- Geographic Focus: UK and US primary; spreading EMEA
- Signature TTPs: IT-service-desk social engineering for MFA reset and password reset; Okta / Entra session hijack; rapid AD compromise; data theft via Rclone; deployment of DragonForce affiliate ransomware
- Tooling / Malware Families: Okta admin abuse, Teleport, Ngrok, Mimikatz, Cobalt Strike, DragonForce ransomware
- Recent Activity: Continued leak-site activity during the period; reporting indicates ongoing UK targeting in retail-banking and insurance ahead of summer-trading peaks
- Assessed Threat to Vertical: HIGH - direct UK FS targeting with proven business-disruption capability from the 2025 M&S / Co-op campaign
- Analytic Confidence: HIGH
Akira
- Aliases: Akira, Storm-1567 (some Microsoft attribution overlaps)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Financial services, professional services, manufacturing, education
- Geographic Focus: Global; consistent UK / EU presence
- Signature TTPs: Initial access via Cisco ASA / FTD SSL VPN brute force and exposed admin panels; abuse of valid accounts; rapid network mapping; data exfiltration; ChaCha20 ransomware encryption
- Tooling / Malware Families: Akira ransomware (Linux and Windows variants), AnyDesk, RustDesk, WinSCP, Mimikatz
- Recent Activity: Continued leak-site activity through the reporting period including 16 June FS-adjacent posts
- Assessed Threat to Vertical: HIGH - persistent direct FS leak-site activity
- Analytic Confidence: HIGH
BlueNoroff / Sapphire Sleet (DPRK)
- Aliases: APT38, BlueNoroff, Sapphire Sleet, Dangerous Password, CryptoCore
- Suspected Origin: Democratic People's Republic of Korea
- Suspected Sponsor: Nation-state (DPRK Reconnaissance General Bureau, Lab 110)
- Primary Motivation: Revenue generation for the DPRK regime - crypto theft, SWIFT-style fraud, fintech and FS targeting
- Sector Targeting: Cryptocurrency exchanges, fintech, banking, defi platforms, FS sub-contractors
- Geographic Focus: Global; FS-aligned firms in UK, US, EU, JP, KR
- Signature TTPs: Social-engineering pretext (recruiter / venture-capitalist), LinkedIn / Telegram targeting of FS staff, malicious macOS / Windows installers, credentialed cloud access, in-memory tooling
- Tooling / Malware Families: RustBucket, KandyKorn, ObjCShellz, custom Go / Rust loaders
- Recent Activity: Continuing DPRK fintech targeting consistent with reporting trends through Q1-Q2 2026
- Assessed Threat to Vertical: MEDIUM-HIGH for crypto / fintech sub-vertical, MEDIUM for traditional retail banking
- Analytic Confidence: MEDIUM
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Mass exploitation of Cisco Catalyst SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) at WAN-edge appliances feeding FS estates | HIGH |
| Initial Access | T1078 | Valid Accounts | Scattered Spider / DragonForce social-engineering of helpdesk and BPO staff for MFA reset; Akira valid-account abuse against Cisco SSL VPN | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | BlueNoroff / Sapphire Sleet pretext lures to FS / fintech staff via LinkedIn and Telegram; recruiter-themed targeting | MEDIUM |
| Execution | T1059.001 | Command and Scripting Interpreter: PowerShell | Cobalt Strike beacon execution post-initial-access during Qilin / Akira intrusions | HIGH |
| Persistence | T1136 | Create Account | Scattered Spider creation of attacker-controlled federation accounts in Entra ID / Okta after initial helpdesk compromise | HIGH |
| Defense Evasion | T1562.001 | Disable or Modify Tools | Tampering with EDR services prior to encryption; Defender registry-disable patterns continue to feed Blackbit-shape detections | MEDIUM |
| Collection / Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone to Mega / Backblaze / Wasabi consistently observed across Qilin and DragonForce campaigns prior to encryption | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Encryption phase of Qilin, Akira, DragonForce and TheGentlemen across the reporting period | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | CVE-2026-20245 added to CISA KEV with confirmed in-the-wild exploitation; FS WAN-edge estates exposed pending mitigation | CISA KEV / Cisco PSIRT |
| 09 Jun 2026 | Arista EOS (vendor) | Unattributed | CVE-2026-7473 added to CISA KEV; tunnel-decap defect with no-patch mitigation-only posture affecting FS data-centre estates | CISA KEV / Arista Networks |
| 15 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | Second SD-WAN Manager defect CVE-2026-20262 (path traversal) added to KEV; FS-aligned firms with SD-WAN Manager required to act within CISA timelines | CISA KEV / Cisco PSIRT |
| 15 Jun 2026 | LiteSpeed cPanel plugin (vendor) | Unattributed | CVE-2026-54420 symlink following added to KEV; FS-adjacent SaaS and hosting providers in scope under DORA outsourced-ICT controls | CISA KEV / LiteSpeed Technologies |
| 16 Jun 2026 | Joomla Widget Factory editor (vendor) | Unattributed | CVE-2026-48907 added to KEV; affects FS marketing micro-sites and consumer-facing portals still on Joomla | CISA KEV |
| 16 Jun 2026 | FS-adjacent (Qilin leak-site post) | Qilin | Leak-site posting on 16 June consistent with FS supply-chain targeting; victim attribution withheld pending corroboration | ransomware.live / Insikt Group |
| 15 Jun 2026 | Manufacturing supplier to FS facilities (DragonForce leak) | DragonForce | Tecfi (fastening systems) posted to DragonForce leak site, estimated attack date 15 June; supplier exposure into FS branch / building services | ransomware.live |
| 17 Jun 2026 | UK CNI (NCSC public commentary) | Multiple state actors | NCSC CEO at RUSI: more than 200 CNI incidents in the year to May, ~75% assessed state-actor; FS is a designated CNI sub-sector and inherits the threat profile directly | NCSC / RUSI / The Record |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager - directory / path traversal | 8.6 | Yes | Yes | Apply vendor mitigation; restrict management plane to jumpbox-only access; monitor file-system access patterns |
| CVE-2026-7473 | Arista EOS - tunnel decap incomplete comparison (no patch as of period) | 7.5 | Yes | Yes | Enforce tunnel allow-list; deploy ACLs on decap interfaces; harden BGP / OSPF authentication |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply Citrix advisory mitigation; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately per NCSC; rotate gateway service accounts; force session reset for all interactive users |
| CVE-2026-54420 | LiteSpeed cPanel plugin - symlink following | 7.5 | Yes | Yes | Patch per LiteSpeed advisory; FS firms in scope under DORA outsourced-ICT controls should confirm with hosting providers |
| CVE-2026-48907 | Joomla Widget Factory / JCE editor - improper access control | 8.6 | Yes | Yes | Patch JCE editor on FS marketing / micro-sites; remove unused Joomla deployments |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read / write | 8.8 | Yes | Yes | Force Chrome / Edge update in FS workstation estate via Intune / SCCM; verify against KEV due-date |
| CVE-2026-45247 | Mirasvit / Magento storefront platform - mass-scanning candidate | 8.2 | No | Suspected | Audit FS-adjacent payment processors and insurance-quote platforms; deploy WAF virtual patches |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 11 May 2026 | HIGH | F3 Netze AS205100 Tor exit; IP Insights threat score 100/critical; seven active blocklists; observed in FS-perimeter brute-force tail |
| IP | 45[.]142[.]122[.]41 | 14 Jun 2026 | MEDIUM | First Server Limited (VG / BVI); IP Insights low score but persistent SSH / OWA brute pattern; recommend WAF blocklist |
| IP | 194[.]180[.]48[.]139 | 15 Jun 2026 | MEDIUM | Serverion (NL) hosting; persistent OWA / Citrix Gateway brute pattern; recommend perimeter blocklist |
| IP | 146[.]70[.]180[.]13 | 12 Jun 2026 | MEDIUM | M247 (RO) hosting; sustained credential-stuffing pattern against FS public-facing portals |
| IP | 23[.]95[.]87[.]45 | 16 Jun 2026 | MEDIUM | HostPapa (US) hosting; flagged as hosting + datacenter; persistent low-volume scanning |
| Domain | secure-fs-login[.]top | 13 Jun 2026 | HIGH | Newly registered phishing infrastructure for FS portal impersonation; recommended takedown via NCSC |
| URL | hxxps://files[.]bbnewsbrief[.]com/invoice-jun26.pdf | 16 Jun 2026 | MEDIUM | BEC lure observed in FS finance-function inbox cohort; redirect chain terminates on Cloudflare-fronted credential-harvest page |
| Email-sender | no-reply@swift-paymentnet[.]com | 17 Jun 2026 | MEDIUM | Spoofed SWIFT payment-notification sender used in FS BEC attempts during the period |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via Cisco SD-WAN Manager exploitation | H | H | CRITICAL |
| Business email compromise targeting finance function with deepfake voice authorisation | H | H | CRITICAL |
| Supply-chain compromise via shared SaaS payment processor or insurance quote platform | M | H | HIGH |
| Helpdesk social-engineering enabling Scattered Spider-style Okta / Entra session hijack | H | H | CRITICAL |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Preventive priorities follow Section 6 directly: there is no vendor patch for CVE-2026-20245 or CVE-2026-7473 as at issue date, so mitigation-only postures must be enforced - restrict netadmin role membership, rotate netadmin credentials, restrict management plane to jumpbox-only access, enforce ACLs on Arista tunnel-decap interfaces, harden BGP / OSPF authentication. Apply NCSC mitigation for NetScaler ADC / Gateway (CVE-2026-3055 and CVE-2026-4368) and rotate gateway session secrets / service accounts. Patch LiteSpeed cPanel plugin (CVE-2026-54420), the Joomla Widget Factory editor (CVE-2026-48907) and force-update Chrome / Edge across the workstation estate for the V8 defect CVE-2026-11645. Reinforce helpdesk MFA-reset playbooks against Scattered Spider-style social-engineering: mandatory callback to directory-verified number, mandatory manager attestation, mandatory cooling-off period for high-privilege accounts. Validate deepfake-resistant out-of-band authorisation for high-value payments per the April 2026 FS-ISAC AI advisory.
Disrupt
10. Forward outlook
Looking forward to the next reporting period (20-26 Jun 2026), it is likely that at least one UK FS firm will publicly disclose an incident traceable to one of the Cisco SD-WAN Manager, Arista EOS, Citrix NetScaler or LiteSpeed cPanel defects in Section 6, given the combination of confirmed in-the-wild exploitation, no-patch mitigation-only postures on the two most severe defects, and the prevalence of these products in the UK FS WAN / edge estate. We assess it is highly likely that Qilin, DragonForce and Akira will maintain leak-site volume leadership, with at least one further FS-adjacent leak-site posting expected within the period. We assess it is a realistic possibility that Scattered Spider will conduct at least one helpdesk-engineered intrusion against a UK retail-banking or insurance firm; the M&S / Co-op / Harrods template remains operationally proven and continues to be reused.
Trigger conditions that would prompt revision of this outlook include: (a) a UK FS firm publicly attributing a breach to Cisco SD-WAN Manager or Arista EOS exploitation, which would warrant immediate out-of-cycle reporting; (b) emergence of a vendor patch for CVE-2026-20245 or CVE-2026-7473, which would shift the risk profile substantially; (c) a UK retail-banking helpdesk compromise matching the Scattered Spider / DragonForce template, which would warrant immediate FS-ISAC and CISP trust-group escalation; (d) observation of any IP Insights 'critical' tail indicator showing successful authentication into a client FS estate.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 4 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 5 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 6 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 7 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 8 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 9 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 10 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 11 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 12 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 13 | IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feeds | UK Cyber Defence Ltd | A1 |
| 15 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 16 | FS-ISAC AI Cybersecurity Hardening Advisory (April 2026) | Financial Services Information Sharing and Analysis Center | A1 |
| 17 | FS-ISAC 2026 Americas Spring Summit strategy refresh (Mar 2026) | Financial Services Information Sharing and Analysis Center | A1 |
| 18 | Cisco PSIRT advisories cisco-sa-sdwan-manager-2026 (CVE-2026-20245 / 20262) | Cisco Systems, Inc. | A1 |
| 19 | Citrix NetScaler ADC / Gateway advisory (CVE-2026-3055 / 4368) | Citrix / Cloud Software Group | A1 |
| 20 | NCSC CEO speech, RUSI Annual Security Lecture, 17 June 2026 | National Cyber Security Centre / RUSI | B1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Financial services threat intelligence report — 4–8 May 2026
During the reporting period the financial-services threat picture continued to be dominated by ransomware and pure data-extortion crews…
Financial services threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the financial-services threat picture remained dominated by ransomware and pure data-extortion crews against a backdrop of continued AI-accelerated patch-wave dynamics.
Financial services threat intelligence report — 27 April – 3 May 2026
During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers.