Financial services threat intelligence report — 20–26 June 2026
The collection picture this week is dominated by edge-appliance exposure - the three Ubiquiti UniFi OS defects added to the CISA Known Exploited Vulnerabilities catalogue on 23 June chain to unauthenticated root RCE under the Bishop Fox proof-of-concept and present a material risk to FS branch and…
- Reference: TI-2026-0626-001 (public edition)
- Sector: Financial services, banking, fintech and insurance
- Reporting period: 20–26 June 2026
- Issued: 26 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Financial Services, Banking, Fintech and Insurance sector during the period 20 Jun 2026 - 26 Jun 2026. The collection picture this week is dominated by edge-appliance exposure - the three Ubiquiti UniFi OS defects added to the CISA Known Exploited Vulnerabilities catalogue on 23 June chain to unauthenticated root RCE under the Bishop Fox proof-of-concept and present a material risk to FS branch and back-office networks where UniFi hardware has been deployed - alongside continued leak-site activity from Qilin, Akira and the DragonForce / Scattered Spider cluster against FS-aligned victims.
CISA's mandatory remediation deadline for the new Ubiquiti and Lantronix KEV entries is 26 June, which falls on the issue date of this report - any FS client that has not actioned by issue is now in breach of the BOD 26-04 timeline and is treated as a priority remediation engagement.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware and pure data-extortion crews - Qilin, Akira, DragonForce and the LockBit 5.0 cluster - will continue to drive the majority of materially-disruptive incidents against UK and EU FS firms during the next two reporting cycles, consistent with this week's ransomware.live volume leadership and the Qilin posting of the Central Bank of Libya on 22 June (HIGH confidence).
- It is highly likely that the three Ubiquiti UniFi OS defects (CVE-2026-34908, -34909, -34910) will be exploited at scale against unpatched edge devices within the next 14 days, given the public Bishop Fox PoC chain, CISA's three-day BOD 26-04 timeline and the prevalence of UniFi hardware in FS branch and back-office networks (HIGH confidence).
- It is likely that the Lantronix EDS5000 defect (CVE-2025-67038) will be exploited against FS-adjacent OT / building-management estates within the next reporting cycle, since the device is used as a serial-to-IP bridge for ATMs, HVAC, UPS and physical access systems in branch networks (MEDIUM confidence).
- It is likely that AI-driven KYC bypass - deepfake voice and video authorisation of payments and synthetic-identity onboarding - will continue to expand as a fraud-adjacent threat vector through Q3 2026, consistent with FS-ISAC's April 2026 AI Cybersecurity Hardening Advisory (MEDIUM-HIGH confidence).
- It is a realistic possibility that one of the BlueNoroff / Sapphire Sleet sub-clusters will conduct a credentialed intrusion against a UK or EU fintech or crypto-adjacent FS firm within the next two reporting cycles (MEDIUM confidence).
2. Sector threat landscape
The Ubiquiti UniFi OS chain published on 23 June is operationally significant for FS. UniFi hardware is prevalent in branch networks, broker offices, insurance-agent franchises and back-office IT functions. The three CVEs (CVE-2026-34908 improper access control, CVE-2026-34909 path traversal, CVE-2026-34910 input validation) carry CVSS 10.0 in chain and Bishop Fox have demonstrated unauthenticated root RCE. CISA's BOD 26-04 deadline of 26 June is operationally aggressive and several monitored FS clients had not actioned by issue.
Ransomware leak-site activity over the period was led, in volume terms, by Qilin (multiple posts including the 22 June posting of the Central Bank of Libya), Akira (NTD Apparel posted 22 June; sustained mid-week activity) and DragonForce (22 June posts of BITS Pilani and mihana-v.com, estimated attack date 20 June). FS-adjacent supply-chain victims continue to appear consistently and the FS-ISAC trust group surfaced two additional finance-adjacent incidents during the period under embargo.
NCSC continued to flag the prior-period Citrix NetScaler defects (CVE-2026-3055 and CVE-2026-4368) as immediate mitigation priorities for UK organisations and the FS estate inherits this directly: NetScaler Gateway sits in front of remote-working and contractor access for the majority of monitored UK FS clients. The APT28 router-exploitation pattern flagged by NCSC remains current and is operationally relevant to FS firms with branch routers and home-worker CPE that are not under enterprise management.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B, Water Galura
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Manufacturing, energy, financial services, healthcare, professional services, retail
- Geographic Focus: Global; sustained EU and UK targeting through 2026
- Signature TTPs: Initial access via phishing and exposed VPN / RDP; abuse of valid accounts; rapid AD escalation; data exfiltration via Rclone to Mega / Backblaze prior to encryption
- Tooling / Malware Families: Qilin / Agenda ransomware (Rust and Go builders), Cobalt Strike, AnyDesk, Rclone, PsExec
- Recent Activity: 22 Jun leak-site posting of Central Bank of Libya; sustained volume leadership across the reporting period (Insikt / ransomware.live)
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
DragonForce / Scattered Spider cluster
- Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
- Suspected Origin: Western (UK / US) English-speaking criminal cluster + DragonForce RaaS infrastructure
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - extortion via encryption and data leak
- Sector Targeting: Retail, financial services, hospitality, telecoms, BPO / outsourced helpdesk providers, education
- Geographic Focus: UK and US primary; spreading EMEA
- Signature TTPs: IT-service-desk social engineering for MFA reset; Okta / Entra session hijack; rapid AD compromise; data theft via Rclone; deployment of DragonForce affiliate ransomware
- Tooling / Malware Families: Okta admin abuse, Teleport, Ngrok, Mimikatz, Cobalt Strike, DragonForce ransomware
- Recent Activity: 22 Jun leak-site posts of BITS Pilani and mihana-v.com (estimated attack 20 Jun); sustained UK retail / hospitality activity through the period
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
Akira
- Aliases: Akira, Storm-1567 (some Microsoft attribution overlaps)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Financial services, professional services, manufacturing, education, legal, retail
- Geographic Focus: Global; consistent UK / EU presence
- Signature TTPs: Initial access via Cisco ASA / FTD SSL VPN brute force and exposed admin panels; abuse of valid accounts; rapid network mapping; ChaCha20 ransomware encryption
- Tooling / Malware Families: Akira ransomware (Linux and Windows variants), AnyDesk, RustDesk, WinSCP, Mimikatz
- Recent Activity: 22 Jun NTD Apparel posted to leak site; continued mid-week activity against professional-services sub-verticals
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
BlueNoroff / Sapphire Sleet (DPRK)
- Aliases: APT38, BlueNoroff, Sapphire Sleet, Dangerous Password, CryptoCore
- Suspected Origin: Democratic People's Republic of Korea
- Suspected Sponsor: Nation-state (DPRK Reconnaissance General Bureau, Lab 110)
- Primary Motivation: Revenue generation for the DPRK regime - crypto theft, SWIFT-style fraud, fintech targeting
- Sector Targeting: Cryptocurrency exchanges, fintech, banking, defi platforms, FS sub-contractors
- Geographic Focus: Global; FS-aligned firms in UK, US, EU, JP, KR
- Signature TTPs: Recruiter / VC social-engineering on LinkedIn and Telegram; malicious macOS / Windows installers; in-memory tradecraft; cloud credential theft
- Tooling / Malware Families: RustBucket, KandyKorn, ObjCShellz, custom Go / Rust loaders
- Recent Activity: Continued DPRK fintech targeting consistent with Q2 2026 trend reporting
- Assessed Threat to Vertical: MEDIUM-HIGH for crypto / fintech, MEDIUM for traditional banking
- Analytic Confidence: MEDIUM
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Anticipated mass-exploitation of Ubiquiti UniFi OS chain (CVE-2026-34908 / -34909 / -34910) and continuing exposure of Cisco Catalyst SD-WAN Manager (CVE-2026-20245 / 20262) | HIGH |
| Initial Access | T1078 | Valid Accounts | Scattered Spider / DragonForce social-engineering of helpdesk and BPO staff for MFA reset; Akira valid-account abuse against Cisco SSL VPN | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | BlueNoroff / Sapphire Sleet pretext lures to FS / fintech staff via LinkedIn and Telegram; recruiter and VC themed targeting | MEDIUM |
| Persistence | T1136 | Create Account | Scattered Spider creation of attacker-controlled federation accounts in Entra ID / Okta after initial helpdesk compromise | HIGH |
| Defense Evasion | T1562.001 | Disable or Modify Tools | Tampering with EDR services prior to encryption; Defender registry-disable patterns continue to feed our Blackbit-shape detections | MEDIUM |
| Collection / Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone to Mega / Backblaze / Wasabi consistently observed across Qilin and DragonForce campaigns prior to encryption | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Encryption phase of Qilin, Akira and DragonForce across the reporting period | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 23 Jun 2026 | Ubiquiti UniFi OS Server (vendor) | Unattributed | Three CVEs added to CISA KEV; CVSS 10.0 chain to unauthenticated root RCE; FS branch and back-office estates with UniFi hardware directly in scope | CISA KEV / Bishop Fox PoC |
| 23 Jun 2026 | Lantronix EDS5000 (vendor) | Unattributed | CVE-2025-67038 added to KEV; FS-adjacent OT / branch building-management estates using serial-to-IP bridges in scope | CISA KEV / Lantronix advisory |
| 22 Jun 2026 | Central Bank of Libya | Qilin | Public leak-site posting on the Qilin site; central-bank exposure relevant to UK / EU FS firms with Libyan correspondent-banking relationships | ransomware.live / Insikt Group |
| 22 Jun 2026 | FS-adjacent professional services (NTD Apparel) | Akira | Leak-site posting on Akira; supply-chain exposure into FS marketing / merchandise channels | ransomware.live |
| 20 Jun 2026 | FS-adjacent education / fintech research (BITS Pilani) | DragonForce | Estimated attack date 20 Jun; data theft confirmed via leak-site claim posted 22 Jun | ransomware.live |
| 19 Jun 2026 | Klue (cybersecurity vendor to FS firms) | Icarus extortion cluster | Breach claimed publicly; FS firms using Klue competitive-intelligence platform inherit data-exposure risk | Infosecurity Magazine |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8 immediately per CISA BOD 26-04 (due 26 Jun 2026); audit management plane exposure |
| CVE-2026-34909 | Ubiquiti UniFi OS Server < 5.0.8 - path traversal | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; restrict management plane to dedicated VLAN; review for file-system access anomalies |
| CVE-2026-34910 | Ubiquiti UniFi OS Server < 5.0.8 - improper input validation (chains to root RCE) | 10.0 | Yes | Yes | Patch immediately - Bishop Fox PoC chains the three UniFi defects to unauthenticated root RCE |
| CVE-2025-67038 | Lantronix EDS5000 Device Server - HTTP RPC command injection (root) | 9.8 | Yes | Yes | Apply Lantronix firmware update; remove internet exposure; segregate serial-to-IP devices to OT zone |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command injection | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; apply vendor mitigation; monitor for CLI abuse |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager - directory traversal | 8.6 | Yes | Yes | Apply vendor mitigation; restrict management plane to jumpbox-only; monitor file-system access patterns |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply Citrix advisory; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately per NCSC; rotate gateway service accounts; force session reset for all interactive users |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read / write | 8.8 | Yes | Yes | Force Chrome / Edge update across workstation estate via Intune / SCCM; verify against KEV due-date |
| CVE-2025-48595 | Android Framework - integer overflow leading to local privilege escalation | 7.8 | Yes | Yes | Push June 2026 Android security patch via MDM; require minimum patch level on BYOD enrolments |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 21 Jun 2026 | HIGH | F3 Netze AS205100 Tor exit (DE); IP Insights threat score 100 / critical; observed in EmilyAI-tagged perimeter brute-force tail this period |
| IP | 92[.]118[.]39[.]95 | 23 Jun 2026 | HIGH | UNMANAGED LTD (AS47890, GB-registered); IP Insights critical / suggest=block; appears in SSH and OWA brute-force tail |
| IP | 80[.]94[.]95[.]115 | 24 Jun 2026 | HIGH | SS-Net (RO) AS204428; IP Insights critical / suggest=block; sustained mass-scan against management plane endpoints |
| IP | 134[.]122[.]114[.]42 | 23 Jun 2026 | MEDIUM | DigitalOcean droplet IP; IP Insights critical / suggest=block; pattern-matches NetScaler probe traffic |
| IP | 198[.]235[.]24[.]31 | 20 Jun 2026 | MEDIUM | Google Cloud Platform US (AS396982); IP Insights critical / suggest=block; aggressive web-scan against client portals |
| IP | 162[.]142[.]125[.]34 | 25 Jun 2026 | LOW | Censys research scanner; benign but high-volume - exclude from alerting via known-scanner allow-list to reduce noise |
| IP | 64[.]227[.]107[.]117 | 24 Jun 2026 | MEDIUM | DigitalOcean droplet; IP Insights suggest=block; new this period - submitted to ipinsights.io reciprocal feed via EmilyAI |
| IP | 152[.]32[.]143[.]49 | 22 Jun 2026 | MEDIUM | UCloud HK (AS135377) hosting / datacenter, NG geolocation; observed in SaaS-tenant credential-stuffing tail |
| IP | 146[.]70[.]180[.]13 | 21 Jun 2026 | MEDIUM | M247 (RO) hosting; persistent credential-stuffing pattern against public-facing portals across multiple verticals |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via Ubiquiti UniFi OS chain at branch / back-office edge | H | H | CRITICAL |
| Business email compromise targeting finance function with deepfake voice authorisation | H | H | CRITICAL |
| Supply-chain compromise via shared SaaS payment processor or insurance quote platform | M | H | HIGH |
| Helpdesk social-engineering enabling Scattered Spider-style Okta / Entra session hijack | H | H | CRITICAL |
| DPRK BlueNoroff credentialed intrusion against fintech / crypto-adjacent client | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat the Ubiquiti UniFi OS chain as the principal hunting hypothesis for the next reporting cycle. Hunt actively for Rclone to Mega / Backblaze / Wasabi destinations and for new federation account creation in Entra ID and Okta consistent with Scattered Spider tradecraft.
Defend
Preventive priorities follow Section 6 directly. The Ubiquiti UniFi OS 5.0.8 patch must be applied across the FS estate by 26 June to meet CISA BOD 26-04; clients that have not actioned by issue are escalated to priority remediation engagement. Restrict UniFi management plane to dedicated VLANs with jumpbox-only access pending patch. Lantronix EDS5000 firmware update applies similarly to FS branch / OT estates. The Cisco SD-WAN Manager and Arista EOS prior-period defects remain mitigation-only and require sustained ACL and netadmin-role discipline. Force-update Chrome / Edge across the workstation estate to remediate CVE-2026-11645. For identity hardening, enforce number-matching MFA on all Okta / Entra tenants, audit federation trust relationships, and ensure helpdesk has out-of-band identity-verification procedures for MFA reset requests in line with FS-ISAC guidance.
Disrupt
Disruption activity within client lawful authority should focus on: (i) sustained participation in the FS-ISAC indicator exchange, with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) honeypot deployment fronting NetScaler Gateway and UniFi controller management interfaces to capture Bishop Fox PoC variant probes; (iii) coordination with NCSC and CISP on the Ubiquiti chain and the APT28 router-exploitation pattern; (iv) takedown coordination via NCSC ACD for the FS-themed phishing infrastructure flagged in Section 7 and submitted to ipinsights.io.
10. Forward outlook
Ransomware leak-site volume is highly likely to remain at or above the current 5-victims-per-day average across Qilin, Akira, DragonForce and TheGentlemen, with at least one FS-adjacent posting expected in the next reporting cycle.*
Trigger conditions that would prompt revision of this outlook include: (a) a UK FS firm publicly attributing a breach to Ubiquiti UniFi OS exploitation, which would warrant immediate out-of-cycle reporting; (b) emergence of a vendor patch for the Cisco SD-WAN Manager or Arista EOS defects, which would shift the recommended posture from mitigation-only to patching; (c) public DPRK attribution of a successful crypto-exchange compromise affecting a UK or EU fintech, which would elevate the BlueNoroff threat to HIGH; (d) any NCSC or FS-ISAC bulletin escalating the Citrix NetScaler defects to confirmed in-the-wild exploitation, which would trigger an immediate emergency advisory to all monitored FS clients. The principal intelligence gap remains visibility into peer FS-firm incident telemetry outside of FS-ISAC trust-group disclosures.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | CISA Alert: Three Ubiquiti UniFi OS Flaws Added to KEV (23 Jun 2026) | CISA | A1 |
| 4 | CISA Alert: CVE-2025-67038 Lantronix EDS5000 added to KEV (23 Jun 2026) | CISA | A1 |
| 5 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 6 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 7 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 8 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 9 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 10 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 11 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 12 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 13 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 14 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 15 | IP Insights (ipinsights.io) IP enrichment, blocklists and STIX 2.1 feed | UK Cyber Defence Ltd | A1 |
| 17 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 18 | FS-ISAC AI Cybersecurity Hardening Advisory (April 2026) | Financial Services Information Sharing and Analysis Center | A1 |
| 19 | FS-ISAC trust-group indicator and incident summaries (Week 26, 2026) | Financial Services Information Sharing and Analysis Center | A1 |
| 20 | Bishop Fox UniFi OS root RCE chain technical write-up (Jun 2026) | Bishop Fox | B1 |
| 21 | Citrix NetScaler ADC / Gateway advisory (CVE-2026-3055 / 4368) | Citrix / Cloud Software Group | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Financial services threat intelligence report — 4–8 May 2026
During the reporting period the financial-services threat picture continued to be dominated by ransomware and pure data-extortion crews…
Financial services threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the financial-services threat picture remained dominated by ransomware and pure data-extortion crews against a backdrop of continued AI-accelerated patch-wave dynamics.
Financial services threat intelligence report — 27 April – 3 May 2026
During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers.