SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Financial services threat intelligence report — 4–10 July 2026

The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets.

  • Reference: TI-2026-0710-001 (public edition)
  • Sector: Financial services, banking, fintech and insurance
  • Reporting period: 4–10 July 2026
  • Issued: 10 July 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Financial Services, Banking, Fintech and Insurance sector during the period 04 Jul 2026 - 10 Jul 2026. The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. The collection picture for this period is dominated by three developments: the rapid exploitation of CVE-2026-8451 (CitrixBleed 3 follow-on) within 24 hours of vendor disclosure; the emergence of Qilin-affiliate exploitation of CVE-2026-50751 (Check Point VPN) as a fresh initial-access vector; and the continuing ascent of The Gentlemen ransomware brand, which overtook Qilin in June leak-site volume and has maintained pace into July.

FS-ISAC daily indicator exchange during the period surfaces a consistent set of source ranges probing OWA, NetScaler Gateway and Entra ID sign-in endpoints across peer FS estates. Weighting ISAC intelligence above vendor reporting, the analyst's view is that the Qilin, The Gentlemen and DragonForce / Scattered Spider clusters are the three actors of most operational significance to the vertical over the coming two reporting cycles, with Anubis and BlueNoroff carrying secondary but non-trivial weight.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that CVE-2026-8451 (CitrixBleed 3 follow-on) will drive credentialled intrusion attempts against NetScaler-fronted FS remote-working estates over the next two reporting cycles, given the 24-hour exploitation timeline and residual population of not-yet-session-invalidated deployments (HIGH confidence).
  2. It is highly likely that ransomware and pure data-extortion crews - Qilin, Akira, DragonForce and the fast-rising The Gentlemen - will continue to drive the majority of materially-disruptive incidents against UK and EU FS firms during the next two reporting cycles; Qilin's newly-observed exploitation of Check Point VPN CVE-2026-50751 is a specific initial-access risk (HIGH confidence).
  3. It is likely that CVE-2026-45659 (SharePoint deserialisation) exposure remains material for FS document-management estates that have not fully audited SharePoint Site Member permissions since the 04 Jul deadline; residual risk sits with mid-market firms without dedicated SharePoint governance (MEDIUM-HIGH confidence).
  4. It is likely that AI-driven KYC bypass - deepfake voice and video authorisation of payments and synthetic-identity onboarding - will continue to expand as a fraud-adjacent threat vector through Q3 2026 (MEDIUM-HIGH confidence).
  5. It is a realistic possibility that one of the BlueNoroff / Sapphire Sleet sub-clusters will conduct a credentialed intrusion against a UK or EU fintech or crypto-adjacent FS firm within the next two reporting cycles (MEDIUM confidence).

2. Sector threat landscape

The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. The collection picture for this period is dominated by three developments: the rapid exploitation of CVE-2026-8451 (CitrixBleed 3 follow-on) within 24 hours of vendor disclosure; the emergence of Qilin-affiliate exploitation of CVE-2026-50751 (Check Point VPN) as a fresh initial-access vector; and the continuing ascent of The Gentlemen ransomware brand, which overtook Qilin in June leak-site volume and has maintained pace into July.

FS-ISAC daily indicator exchange during the period surfaces a consistent set of source ranges probing OWA, NetScaler Gateway and Entra ID sign-in endpoints across peer FS estates. Weighting ISAC intelligence above vendor reporting, the analyst's view is that the Qilin, The Gentlemen and DragonForce / Scattered Spider clusters are the three actors of most operational significance to the vertical over the coming two reporting cycles, with Anubis and BlueNoroff carrying secondary but non-trivial weight.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Qilin (a.k.a. Agenda)

  • Aliases: Agenda, Qilin.B, Water Galura
  • Suspected Origin: Russian-speaking (unattributed)
  • Suspected Sponsor: Organised criminal RaaS
  • Primary Motivation: Financial (double extortion)
  • Sector Targeting: Financial services, healthcare, manufacturing, retail, professional services, logistics
  • Geographic Focus: Global; UK and EU disproportionately represented in H1 2026 leak-site postings
  • Signature TTPs: Initial access via brokered credentials, Check Point VPN CVE-2026-50751 exploitation, RMM abuse (AnyDesk, SplashTop), PowerShell + Rust ransomware payload; ESXi Linux variant
  • Tooling / Malware Families: Qilin.B ransomware (Rust), Cobalt Strike, Rclone-to-Mega, Mimikatz, SharpHound
  • Recent Activity: 1,496 leak-site victims across trailing 12 months (dominant RaaS); 78 postings in June 2026 (temporarily overtaken by The Gentlemen at 115); continued CVE-2026-50751 exploitation reported this period
  • Assessed Threat to Vertical: HIGH - dominant RaaS operator across UK/EU
  • Analytic Confidence: HIGH

DragonForce / Scattered Spider cluster

  • Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
  • Suspected Origin: Anglophone (UK/US); further four arrests 10 Jul 2026 per NCA
  • Suspected Sponsor: Organised criminal alliance / RaaS
  • Primary Motivation: Financial (ransomware + data extortion)
  • Sector Targeting: Retail, hospitality, telecoms, technology, real estate, manufacturing, construction, FS (payments)
  • Geographic Focus: Anglophone western targets
  • Signature TTPs: Voice-phishing IT service desk to reset MFA, help-desk social engineering, EDR bypass via legitimate RMM tooling, DragonForce Linux/ESXi ransomware, aggressive cloud-tenant pivot
  • Tooling / Malware Families: DragonForce ransomware, Ngrok, AnyDesk, SplashTop, Impacket, Chisel
  • Recent Activity: 7 leak-site postings in trailing 24h (Real Estate, Manufacturing, Construction focus); 4 additional UK arrests connected to M&S/Co-op/Harrods case 10 Jul 2026; alliance-affiliate operations continue
  • Assessed Threat to Vertical: HIGH - social-engineering methodology transfers directly across verticals
  • Analytic Confidence: HIGH

The Gentlemen

  • Aliases: The Gentlemen (single-name RaaS brand)
  • Suspected Origin: Unattributed (Russian-speaking assessed)
  • Suspected Sponsor: Organised criminal RaaS
  • Primary Motivation: Financial (double extortion)
  • Sector Targeting: Broad mid-market; disproportionately professional services, retail, healthcare, manufacturing
  • Geographic Focus: Global; western Europe and North America dominant in June-July 2026 tally
  • Signature TTPs: Initial access via brokered credentials, LOTL tooling, aggressive leak-site publication cadence, PowerShell + custom Rust payload
  • Tooling / Malware Families: The Gentlemen ransomware (Rust), Rclone, PsExec, Cobalt Strike
  • Recent Activity: 115 leak-site postings in Jun 2026 - highest of any single brand and first month above Qilin in over a year; sustained cadence into 04-10 Jul 2026
  • Assessed Threat to Vertical: HIGH - fastest-growing RaaS brand
  • Analytic Confidence: MEDIUM-HIGH

BlueNoroff / Sapphire Sleet (DPRK)

  • Aliases: APT38, BlueNoroff, Sapphire Sleet, Dangerous Password, CryptoCore
  • Suspected Origin: Democratic People's Republic of Korea (Lazarus umbrella)
  • Suspected Sponsor: Nation state (DPRK Reconnaissance General Bureau)
  • Primary Motivation: Financial (regime revenue generation, especially cryptocurrency theft)
  • Sector Targeting: Cryptocurrency exchanges, Web3, DeFi, fintech, cross-border payments, VC / investment firms
  • Geographic Focus: Global with heavy Anglophone and Japanese targeting
  • Signature TTPs: Social engineering via LinkedIn / Telegram / X, fake job offers, fake investment approaches, macOS-focused implants, signed installer chains
  • Tooling / Malware Families: RustBucket, KANDYKORN, ObjCShellz, TodoSwift, DPRK signed installer chains
  • Recent Activity: Ongoing campaigns against cross-border payments and crypto-adjacent FS firms; NCSC / CISA joint reporting continues to flag active LinkedIn recruitment
  • Assessed Threat to Vertical: MEDIUM-HIGH - moderate volume but very high per-incident impact where successful
  • Analytic Confidence: MEDIUM

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1190Exploit Public-Facing ApplicationContinued exploitation of CitrixBleed 3 follow-on (CVE-2026-8451, exploited within 24h of disclosure), SharePoint deserialisation (CVE-2026-45659, remediation deadline 04 Jul passed) and Ivanti Sentry (CVE-2026-10520). FS-ISAC daily indicator exchange during the period surfaces a consistent set of Tor and bulletproof-hosting source ranges probing OWA, NetScaler Gateway and Entra ID sign-in endpoints across peer FS estates.HIGH
Initial AccessT1078.004Valid Accounts: Cloud AccountsSustained OAuth / refresh-token replay against Microsoft 365 tenants sourced from UAB Host Baltic (141.98.10.0/24, 141.98.11.0/24) and rotating Tor egress; consistent with NCSC Anubis-affiliate tradecraft advisory this periodHIGH
Initial AccessT1566.001Spearphishing AttachmentIcedID, Latrodectus and DarkGate loader chains via ISO/IMG/OneNote continued to dominate the phishing tail; volume steady week-on-week per Proofpoint and Sophos public telemetryHIGH
PersistenceT1219Remote Access SoftwareAnubis-affiliate abuse of ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC and Total Software Deployment noted in NCSC advisory; RMM install-signal hunts remain the primary early-warning telemetryHIGH
DiscoveryT1046Network Service DiscoveryAutomated port sweeps from datacentre-hosted infrastructure - IP Insights flagged multiple AS209605 (HOSTBALTIC) and dmzhost sources in the perimeter tail this periodMEDIUM
Command and ControlT1071.001Application Layer Protocol: WebCobalt Strike, Sliver and Havoc HTTPS C2 beaconing observed in incident retrospectives via ISAC channels this period; JARM / JA3 fingerprint hunts remain the primary detectionHIGH
ExfiltrationT1567.002Exfiltration to Cloud StorageRclone-to-Mega and rclone-to-Backblaze exfiltration patterns dominant in Qilin, Akira, DragonForce and The Gentlemen double-extortion intrusions this periodHIGH
ImpactT1486Data Encrypted for ImpactQilin, Akira, DragonForce and the newly-dominant The Gentlemen ransomware deployment observed against sector-adjacent peers per ransomware.live and ISAC reportingHIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
07 Jul 2026Joomla-based FS partner and comparison sites (multiple)UnattributedCISA KEV additions for CVE-2026-48908 (JoomShaper SP Page Builder) and CVE-2026-56290 (Joomlack Page Builder) - webshell deployment risk against partner-facing marketing estates and open-banking comparison portals commonly deployed on JoomlaCISA KEV / vendor advisories
06 Jul 2026UK / EU FS peers (anonymised, ISAC-derived)Qilin (assessed)Sustained double-extortion targeting; Qilin affiliates exploiting CVE-2026-50751 (Check Point VPN) reported this period as an initial-access vector; two peer FS firms confirmed via FS-ISAC channelFS-ISAC daily indicator exchange (TLP:CLEAR)
OngoingMultiple US FS firms (sector-adjacent)BlueNoroff sub-clusterContinuing LinkedIn-lure recruitment campaigns targeting FS technology and blockchain engineering staff; unchanged tradecraftMandiant, CrowdStrike, ESET APT reporting
OngoingMultiple UK insurance firmsN/AContinued voice-based deepfake authorisation attempts against claims-adjuster and treasury workflows; consistent with FS-ISAC AI Cybersecurity Hardening working group outputFS-ISAC member exchange
04-10 Jul 2026Multiple UK / EU fintech and payments firmsThe GentlemenLeak-site postings continue at record cadence following June's overtake of Qilin; FS-adjacent mid-market victims noted in ransomware.live trackerransomware.live
10 Jul 2026UK retail cluster (M&S / Co-op / Harrods long-tail)DragonForce / Scattered Spider (allegedly)Further four NCA arrests announced this period; FS relevance is via payments-fraud and vendor-payment redirect vectors that transfer from retail social-engineering methodologyNCA / Cybersecurity Dive

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-8451Citrix NetScaler ADC / Gateway - memory overread (CitrixBleed 3 follow-on)9.3YesYesApply fixed builds 14.1-66.59 / 13.1-62.23 / 13.1-37.262 FIPS/NDcPP; must run 'kill icaconnection -all', 'kill pcoipConnection -all', 'kill aaa session -all' post-patch; exploited within 24h of 30 Jun disclosure
CVE-2026-45659Microsoft SharePoint Server SubEd / 2019 / 2016 - deserialisation RCE (rolling exposure from prior week)8.8YesYesContinue enforcement of 04 Jul CISA KEV deadline; audit Site Member permissions; hunt w3wp.exe children (cmd.exe / powershell.exe / rundll32.exe) under the SharePoint app pool; restrict /_layouts/15 uploader paths at the WAF
CVE-2026-10520Ivanti Sentry (formerly MobileIron Sentry) - unauthenticated OS command injection on admin interface9.8YesYesApply Ivanti hotfix immediately; restrict admin interface to management VLAN; Shadowserver confirms exposed instances actively backdoored during the reporting period
CVE-2026-25089Fortinet FortiSandbox - unauthenticated command injection (FortiBleed activity cluster)9.8YesYesUpgrade to fixed FortiSandbox release train; segment FortiSandbox management interface; hunt for FortiBleed indicators including 74,000 stolen credential set referenced by NCSC and vendor reporting
CVE-2026-26083Fortinet FortiSandbox - additional unauthenticated command injection (paired with -25089)9.8YesYesAs per CVE-2026-25089; both must be remediated together; unauthenticated pre-condition removes any residual doubt about exposure
CVE-2026-6973Ivanti Endpoint Manager Mobile - unauthenticated RCE (limited targeted exploitation)9.2YesYesApply Ivanti EPMM hotfix; restrict admin interface; enable audit logging on device-registration workflows
CVE-2026-48908JoomShaper SP Page Builder (Joomla) - unrestricted file upload of dangerous type9.8YesYesUpdate SP Page Builder / Joomla installations; audit uploads directory for webshells; added to CISA KEV 07 Jul 2026
CVE-2026-55255Langflow - authorisation bypass through user-controlled key9.1YesYesUpgrade Langflow to patched release; restrict LLM-tooling admin interfaces to internal networks; added to CISA KEV 07 Jul 2026
CVE-2026-56290Joomlack Page Builder (Joomla) - improper access control on administration endpoints9.1YesYesUpdate the extension immediately; restrict administrator paths at the WAF; added to CISA KEV 07 Jul 2026
CVE-2026-50751Check Point Security Gateway - improper authentication (Qilin-affiliate exploitation reported)9.8YesYesApply Check Point R81.20 / R81.10 / R80.40 hotfixes; hunt admin sessions from non-management source addresses; Qilin affiliates observed leveraging as initial-access

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]101[.]3405 Jul 2026HIGHfor-privacy.net Tor exit (185.220.101.0/24); IP Insights score 100 / critical; 8 blacklists; observed in credential-spray tail against Entra ID sign-in endpoints
IP45[.]148[.]10[.]24006 Jul 2026HIGHdmzhost bulletproof (45.148.10.0/24); IP Insights score 100 / critical; 5 active blacklists including SSH/Telnet Brute Force honeypot capture; SSH / RDWeb brute-force tail
IP92[.]118[.]39[.]20307 Jul 2026HIGHdmzhost / PPTECHNOLOGY LIMITED (UK/NL, 92.118.39.0/24); IP Insights score 85 / critical; 4 blacklists; Exchange OWA credential-spray tail
IP194[.]180[.]48[.]1808 Jul 2026MEDIUMserverion (NL, 194.180.48.0/24); IP Insights score 85 / critical; ThreatFox and malicious-outgoing-ip listings; SSH brute-force tail against perimeter jump hosts
IP141[.]98[.]10[.]14009 Jul 2026MEDIUMUAB Host Baltic AS209605 (LT, hostname pivotsudo-leang.outreachratio.com); IP Insights score 95 / critical; AbuseIPDB s100 30d listing; datacentre-hosted scripted attack traffic
IP141[.]98[.]11[.]9010 Jul 2026LOWUAB Host Baltic AS209605 (LT); IP Insights score 10 / low but datacentre-flagged; observed as source of scripted OAuth token replay against Microsoft 365 tenants

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Ransomware deployment via CitrixBleed 3 follow-on (CVE-2026-8451) session-token theftHHCRITICAL
Business email compromise / vendor payment redirect targeting finance functionHHCRITICAL
Qilin / Anubis intrusion via Check Point VPN CVE-2026-50751 exploitationMHHIGH
Rolling SharePoint (CVE-2026-45659) exploitation against document-management estateMHHIGH
Supply-chain compromise via shared SaaS (SharePoint, M365, Salesforce)MHHIGH
Deepfake voice / video authorisation of payments (fraud-adjacent)MHHIGH
DPRK BlueNoroff social-engineering of technical staff at crypto-adjacent FS firmsMHHIGH

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection engineering should treat CVE-2026-8451 CitrixBleed 3 follow-on session-token replay as the principal hunting hypothesis for the next reporting cycle. Retain SharePoint w3wp.exe / cmd.exe / powershell.exe / rundll32.exe process-tree hunts under the SharePoint app pool identity. Deploy hunts around the Anubis-affiliate RMM tooling (ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment) - the NCSC advisory this week provides a clean baseline. Continue Qilin / Akira / DragonForce / The Gentlemen initial-access playbook hunts (RMM install, PsExec / SMBExec, DCSync, Rclone-to-Mega). Deploy IP Insights critical-tail block / alert lists to WAF and Entra ID Conditional Access.

Defend

Preventive priorities follow Section 6 directly. Complete Citrix NetScaler patching for CVE-2026-8451 and re-run the session-invalidation commands ('kill icaconnection -all', 'kill pcoipConnection -all', 'kill aaa session -all') on every patched appliance. Verify CVE-2026-45659 SharePoint patching has been applied and Site Member permissions audited. Apply Check Point R81.20 / R81.10 / R80.40 hotfixes to address CVE-2026-50751 given the Qilin-affiliate exploitation report. Complete Ivanti Sentry patching against CVE-2026-10520 and restrict admin interfaces to a management VLAN. Address FortiSandbox exposure (CVE-2026-25089 / -26083) as part of the wider FortiBleed remediation. Enforce phishing-resistant MFA on all privileged FS accounts including finance-function payment approvers.

Disrupt

Disruption activity within client lawful authority should focus on: (i) sustained participation in the FS-ISAC daily indicator exchange, with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) honeypot deployment fronting NetScaler Gateway and Check Point management paths, with capture routed to the disruption workflow and shared with FS-ISAC and NCSC CiSP; (iii) coordinated take-down requests to bulletproof-hosting providers (dmzhost, serverion, PPTECHNOLOGY, UAB Host Baltic) for the IP Insights critical tail, submitted via the NCSC Takedown Service where the tail intersects with UK-hosted infrastructure; (iv) continued participation in the FS-ISAC AI Cybersecurity Hardening working group covering deepfake payments-fraud detection.

10. Forward outlook

Looking forward to the next reporting period (11 Jul - 17 Jul 2026), it is likely that at least one UK FS firm will publicly disclose a CitrixBleed 3 follow-on (CVE-2026-8451) intrusion, given the 24-hour exploitation cadence observed on disclosure and the residual population of appliances that have been patched but not fully session-invalidated. It is likely that Qilin-affiliate exploitation of CVE-2026-50751 will extend to at least one UK FS victim within the next two cycles. Ransomware leak-site cadence from Qilin, Akira, DragonForce and The Gentlemen is expected to remain steady week-on-week; the 10 Jul NCA arrests are unlikely to materially reduce the operational threat given the alliance-affiliate model.

Trigger conditions that would prompt revision of this outlook include: (a) a UK FS firm publicly attributing a breach to CVE-2026-8451 or CVE-2026-50751, which would warrant immediate out-of-cycle reporting; (b) emergence of an unauthenticated variant of any current SharePoint or Ivanti Sentry chain; (c) further CISA KEV additions materially affecting FS infrastructure (particularly Fortinet, Ivanti or SonicWall gateways); (d) any confirmed intrusion against a monitored FS client attributable to the actors profiled in Section 3, which would warrant a case-linked addendum to this product.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC-UK weekly threat reports and reports/advisories portalNational Cyber Security CentreA1
2CISA Known Exploited Vulnerabilities catalogue (daily updates)CISAA1
3CISA KEV addition of CVE-2026-48908, -55255, -56290 (07 Jul 2026)CISAA1
4CISA KEV entry rolling forward for CVE-2026-45659 (SharePoint deserialisation)CISA / MicrosoftA1
5Citrix Security Bulletin - CVE-2026-8451 (CitrixBleed follow-on) memory overreadCitrix / Cloud Software GroupA2
6Ivanti Security Advisory - CVE-2026-10520 (Sentry unauthenticated command injection)IvantiA2
7Shadowserver Foundation - Ivanti Sentry active-backdoor reportingShadowserver FoundationA1
8Fortinet PSIRT - CVE-2026-25089 and CVE-2026-26083 (FortiSandbox unauthenticated command injection)FortinetA2
9FortiBleed campaign reporting - 74,000 stolen credentials, 12 confirmed ransomware infectionsCyprus Shipping News / vendor reportingB2
10Ivanti EPMM CVE-2026-6973 limited targeted exploitation advisoryIvanti / The Hacker NewsB2
11NCSC Anubis ransomware advisory (VPN credential abuse and RMM tradecraft)National Cyber Security CentreA1
12NCSC advisory - action following Middle East conflict escalationNational Cyber Security CentreA1
13SonicWall - 10x surge in IPS events across UK hospitals Jan-May 2026 (264k events)SonicWall / Enterprise TimesB2
14ransomware.live daily leak-site tracker (Qilin, Akira, DragonForce, The Gentlemen)ransomware.liveB2
15Qilin ransomware 2026 profile - 1,496 leak-site victims trailing 12 months; CVE-2026-50751 exploitationMOXFIVE / Infosecurity MagazineB2
16Akira ransomware profile - 1,205 leak-site victims trailing 12 monthsSOCRadar / Infosecurity MagazineB2
17DragonForce ransomware - 7 victims in a 24h period; Real Estate / Manufacturing / Construction focusPurple OpsB2
18The Gentlemen ransomware overtakes Qilin in Jun 2026 (115 vs 78 victims)Cybereason / Infosecurity MagazineB2
19NCA arrests four further UK nationals connected to M&S / Co-op / Harrods cluster (10 Jul 2026)National Crime Agency / Cybersecurity DiveA1
20Google Cloud - Threats to the Defense Industrial Base (2026 update)Google Cloud / MandiantA2
21NCSC Cyber Threat Report - UK Legal SectorNational Cyber Security CentreA1
22NCSC Cyber Threat Report - UK Charity SectorNational Cyber Security CentreA1
23Adriatic Port Authority - Anubis ransomware intrusion ($10m demand)Industrial Cyber / ResecurityB2
24Maritime cyber incidents 2025 - 103% year-on-year increase (retro reference)SAFETY4SEA / CYTURB2
25Cybersecurity Breaches Survey 2025/2026 - UK statutory datasetDSIT / GOV.UKA1
26FS-ISAC daily indicator exchange (member portal - TLP:CLEAR)FS-ISACA1
27H-ISAC daily bulletin (member portal - TLP:CLEAR)H-ISACA1
28MTS-ISAC daily bulletin and Cyware indicator exchange (TLP:CLEAR)MTS-ISACA1
29RH-ISAC member exchange (TLP:CLEAR)Retail and Hospitality ISACA1
30Space ISAC / National Council of ISACs bulletins (TLP:CLEAR)NCI / Space ISACA1
31IP Insights REST API enrichment (multiple lookups during the reporting period, week ending 10 Jul 2026)IP Insights / UK Cyber Defence LtdA1
33FS-ISAC April 2026 AI Cybersecurity Hardening Advisory (rolling reference)FS-ISACA1
34Verizon Data Breach Investigations Report 2026 - FS chapter (retro reference)VerizonB2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.