SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Healthcare threat intelligence report — 23–29 May 2026

The vertical continues to absorb sustained ransomware and supply-chain pressure: the Synnovis pathology incident's twelve-month follow-on disclosure recorded 122 patient-safety incidents and a patient death assessed as cyber-attack-contributing at King's College Hospital…

  • Reference: TI-2026-0529-005 (public edition)
  • Sector: Healthcare
  • Reporting period: 23–29 May 2026
  • Issued: 29 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Healthcare vertical during the period 23 May 2026 to 29 May 2026. The vertical continues to absorb sustained ransomware and supply-chain pressure: the Synnovis pathology incident's twelve-month follow-on disclosure recorded 122 patient-safety incidents and a patient death assessed as cyber-attack-contributing at King's College Hospital, at total NHS cost of £32.7m. The DXS International (DevMan ransomware) incident from December 2025 remains the most recent publicly-disclosed NHS-supplier event. The collection picture this week is dominated by continued edge-appliance exploitation pressure (Cisco SD-WAN, Ivanti EPMM, Exchange OWA, Apex One, Citrix NetScaler) and by ransomware leak-site cadence from Qilin, Akira, DragonForce and TheGentlemen against healthcare-adjacent victims. Health-ISAC Heartbeat reporting continues to flag a surge in ransomware and VPN-exploit activity. Sources are graded against the Admiralty System.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that ransomware operators — Qilin, Akira, DragonForce and TheGentlemen — will continue to target UK and EU healthcare providers and NHS suppliers over the next reporting cycle, with the Synnovis case study sustaining board-level attention on supplier-concentration risk. (HIGH confidence)
  2. It is likely that the Cisco Catalyst SD-WAN auth-bypass (CVE-2026-20182) will produce at least one publicly-disclosed healthcare-sector exploitation event within the next two reporting cycles, given documented UAT-8616 in-the-wild activity and the prevalence of Cisco SD-WAN deployments across NHS trust and integrated-care-system networks. (MEDIUM confidence)
  3. It is likely that the Microsoft Exchange Server OWA zero-day (CVE-2026-42897) will be weaponised against NHS trusts and healthcare providers still operating on-prem Exchange. (MEDIUM confidence)
  4. It is highly likely that nation-state interest in healthcare data — particularly genomic, clinical-trial and vaccine-pipeline material — will continue, with China-nexus collection the most active. (HIGH confidence)
  5. There is a realistic possibility that DevMan or a similar emerging extortion operator will target another NHS supplier within the next two reporting cycles, following the December 2025 DXS International precedent. (MEDIUM confidence)

2. Sector threat landscape

The UK healthcare vertical continues to operate under the long-tail of the Synnovis pathology incident: the twelve-month follow-on disclosure recorded 122 patient-safety incidents of incorrect, unavailable or delayed pathology results, and a patient death at King's College Hospital NHS Foundation Trust in which the cyber-attack was recorded as a contributing factor. The total cost to the NHS provider was £32.7m. The case study remains the dominant public anchor for healthcare-sector cyber-resilience discussion in the UK, and is shaping supplier-concentration-risk and operational-resilience expectations through 2026.

NHS Barts Health pathology-invoice data exposure via Cl0p in August 2025 sits in the same recent-history bracket. Health-ISAC Heartbeat reporting flagged a surge in ransomware and VPN-exploit activity across healthcare in early 2026, and that trajectory has continued through the reporting period.*

Ransomware leak-site activity remains the dominant single category of disruption. Q1 2026 leak-site postings grew 22% year-on-year, and healthcare-adjacent victims (medical-device manufacturers, clinical-data processors, pharmacy chains and hospital-system suppliers) consistently appear in the population. Qilin, Akira, DragonForce and TheGentlemen have all posted healthcare-adjacent victims in the reporting period, with leak-site activity sustained into the 28 May timestamp.

Edge-appliance exploitation pressure is shaping the initial-access landscape across the vertical. NHS trusts and ICS networks frequently run Cisco Catalyst SD-WAN at the WAN tier, Ivanti EPMM for clinical-mobile management, Microsoft Exchange Server on-prem for clinical-and-administrative mail, Trend Micro Apex One for endpoint protection and Citrix NetScaler for remote-clinician access — all four product families have new active-exploitation CVEs in the current reporting period. The patching prioritisation is unambiguous: Cisco SD-WAN CVE-2026-20182 first (CVSS 10.0, UAT-8616), then Exchange OWA CVE-2026-42897, then EPMM CVE-2026-6973 and Apex One CVE-2026-34926, with Citrix NetScaler advisories closing the set.

Nation-state interest in healthcare data continues. China-nexus collection against genomic datasets, clinical-trial material and vaccine-pipeline information has been documented consistently across vendor reporting from Mandiant, Microsoft Threat Intelligence and CrowdStrike. ESET's APT activity report published 28 May reflects sustained pressure across the broader healthcare-and-pharma adjacency. Russian APT28 activity against medical-aid and Ukraine-supply logistics has knock-on relevance for UK healthcare partners operating in that supply chain. The Russian-aligned hacktivist DDoS posture against UK public-facing services carries direct relevance for NHS-trust public-service interfaces.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Qilin (a.k.a. Agenda, Qilin.B)

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russia
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — extortion / data theft
  • Sector Targeting: Cross-sector with sustained Healthcare relevance.
  • Geographic Focus: Global; UK, EU, US, ANZ
  • Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
  • Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)

Akira

  • Aliases:
  • Suspected Origin: Russia-aligned criminal milieu
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — encryption + extortion
  • Sector Targeting: Cross-sector with sustained Healthcare relevance.
  • Geographic Focus: Global; SMB and mid-market heavy
  • Signature TTPs: Cisco VPN account abuse without MFA; rapid AD reconnaissance; ESXi targeting; brand-pressure leak-site
  • Tooling / Malware Families: Akira encryptor (Rust); RustDesk; AnyDesk; rclone; PCHunter; Mimikatz
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH

DevMan

  • Aliases:
  • Suspected Origin: Unattributed
  • Suspected Sponsor: Criminal (ransomware / data-extortion)
  • Primary Motivation: Financial — extortion via data leak
  • Sector Targeting: Cross-sector with sustained Healthcare relevance.
  • Geographic Focus: UK, EU; healthcare supply-chain focus
  • Signature TTPs: Compromise of healthcare technology vendors; leak-site disclosure with short countdown
  • Tooling / Malware Families: Public leak portal; unknown custom encryptor
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. MEDIUM
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty C3.
  • Analytic Confidence: MEDIUM

Cl0p

  • Aliases: TA505 affiliate, FIN11-adjacent
  • Suspected Origin: Russia / CIS
  • Suspected Sponsor: Criminal
  • Primary Motivation: Financial — pure data extortion
  • Sector Targeting: Cross-sector with sustained Healthcare relevance.
  • Geographic Focus: Cross-sector, global
  • Signature TTPs: Mass zero-day exploitation of managed file transfer products (MOVEit, GoAnywhere, Cleo); staged leak-site disclosure; no encryption since 2023
  • Tooling / Malware Families: Custom Cl0p data-extortion toolkit; preference for MFT zero-days
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. MEDIUM-HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: MEDIUM-HIGH

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1190Exploit Public-Facing ApplicationEdge-appliance exploitation across Cisco SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973, Exchange OWA CVE-2026-42897, Apex One CVE-2026-34926, Citrix NetScaler CVE-2026-3055/4368.HIGH
Initial AccessT1078.004Valid Accounts: CloudIAB-purchased clinician M365 credentials; session tokens harvested from AiTM phishing.HIGH
Initial AccessT1566.002Spear-phishing LinkHealthcare-themed phishing (clinical-referral, NHS-mail, supplier-invoice pretexts) against clinician and back-office mailboxes.HIGH
Initial AccessT1199Trusted RelationshipCompromise of NHS-supplier estates (pathology, GP-software, scheduling) as upstream entry into provider networks — Synnovis, DXS International and Barts pathology-invoice pattern.HIGH
ExecutionT1059.001Command and Scripting: PowerShellSystemBC / Cobalt Strike loaders post-edge-appliance compromise.MEDIUM
Credential AccessT1003.001OS Credential Dumping: LSASSMimikatz / comsvcs.dll MiniDump against DCs in NHS trust networks.MEDIUM
Defence EvasionT1562.001Impair Defences: Disable Security ToolsApex One CVE-2026-34926 directory-traversal as fresh primitive for EDR-control-plane tampering.MEDIUM
ExfiltrationT1567.002Exfiltration to Cloud Storagerclone / MEGA / AzCopy egress of clinical / pathology / invoice data prior to ransomware stage.HIGH
ImpactT1486Data Encrypted for ImpactQilin.B / DragonForce / Akira ESXi-aware encryption of NHS trust and supplier hypervisor estates.HIGH
ImpactT1657Financial TheftPathology-invoice data exposure (Cl0p / Barts pattern); follow-on identity-fraud against named patients and staff.MEDIUM

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
January 2026 (cumulative)Synnovis pathology / King's College Hospital NHS Foundation TrustRussian-speaking ransomware operator (Qilin-attributed at time)122 patient-safety incidents recorded; patient death recorded as cyber-attack-contributing; £32.7m total NHS cost.HSJ / NHS Foundation Trust
August 2025NHS Barts Health — pathology invoice dataCl0pInvoice data with patient and staff names and addresses posted to Cl0p leak-portal.Bank InfoSecurity
24 May 2026Global Retool Group (Business Services, healthcare-adjacent)QilinPosted to Qilin leak-site 24 May; data-extortion ongoing.Ransomware.live
15 May 2026Microsoft Exchange Server tenants (on-prem) — NHS-trust exposureMultipleCVE-2026-42897 OWA XSS confirmed in active exploitation; NHS trusts on hybrid Exchange topologies materially exposed.Microsoft / Help Net Security

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN Controller / Manager (auth bypass; UAT-8616 in-the-wild)10.0YesYesPatch immediately; rotate SSH keys; review NETCONF logs
CVE-2026-6973Ivanti EPMM (post-CVE-2026-1340 credential reuse chain)7.2YesYesPatch and rotate any admin credential issued before 1 Feb 2026
CVE-2026-34926Trend Micro Apex One (On-Premise) — directory traversal9.4YesYesPatch to build ≥17079; treat as EDR-control-plane exposure until verified
CVE-2026-42897Microsoft Exchange Server (Subscription Edition / 2019 / 2016) — XSS via crafted email8.1YesYesApply 14 May 2026 OOB update; disable OWA externally pending patch
CVE-2025-34291Langflow — origin validation error (added KEV 21 May 2026)9.1YesSuspectedPatch and restrict admin endpoints to trusted networks
CVE-2026-8398 / CVE-2026-45321 / CVE-2026-48027DAEMON Tools Lite / TanStack packages / Nx Console developer extension (supply-chain trio added KEV 27 May)8.0–8.8YesYesAudit developer endpoints; remove compromised package versions
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler ADC and Gateway (NCSC alert week of 24 May)9.0 / 7.5NoSuspectedApply Citrix advisory updates; review session tokens

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]101[.]5ongoingMTOR exit node — Network Attack + tor_exit categories, IP Insights suggestion: block
IP193[.]32[.]162[.]157ongoingMBrute-force / malware family — listed on 6 blacklists per IP Insights
Domainglobal-retool-leaks[.]onion24 May 2026MQilin leak-site post — Global Retool Group disclosure

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Ransomware deployment against NHS trust or supplier estate via IAB front-endHIGHHIGHCRITICAL
Supplier-concentration compromise via shared pathology / GP-software / scheduling vendor (Synnovis / DXS / Barts pattern)MEDIUMHIGHHIGH
Edge-appliance exploitation (Cisco SD-WAN / Ivanti EPMM / NetScaler / Exchange OWA / Apex One) against trust networkHIGHHIGHCRITICAL
Nation-state collection against genomic / clinical-trial / vaccine-pipeline dataMEDIUMHIGHHIGH
Russian-aligned hacktivist DDoS against NHS public-facing servicesMEDIUMMEDIUMMEDIUM
Phishing-driven clinician-mailbox compromise leading to PHI exposureHIGHMEDIUMHIGH

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection engineering should treat the Cisco Catalyst SD-WAN compromise pattern as the highest-priority hunting hypothesis for the next reporting cycle. Cross-walk EPMM admin logins against the documented CVE-2026-1340 / CVE-2026-6973 credential set, rotating any admin token issued before 1 February 2026 as untrusted. For Microsoft Exchange tenants still on-prem, instrument OWA crafted-email telemetry against CVE-2026-42897 — IIS access logs paired with mailbox event 41 should surface the exploitation primitive. Trend Micro Apex One administrators should monitor for directory-traversal probes against the ApexOne web-admin endpoint and treat any EDR-control-plane configuration change without a corresponding change-management record as a P1 trigger. For healthcare tenants specifically, instrument Graph-API bulk-mailbox download patterns against the clinician-mailbox baseline, and treat any cross-trust SharePoint sharing-grant of pathology / clinical / patient-data folders to external tenants as a P1 trigger. Watch for new external SSH keys on Cisco SD-WAN Controllers / Managers and treat as P1. Instrument any pathology-LIMS / RIS / PACS authentication anomaly as a P2 hunting hypothesis given the Synnovis precedent.

Defend

Preventive priorities follow Section 6 directly: patch Cisco Catalyst SD-WAN Controller and Manager out of band as the single highest-value action of the reporting cycle, treat any pre-patch SD-WAN admin credential as untrusted, and rotate. EPMM tenants should rotate all admin credentials issued before 1 February 2026 and apply the CVE-2026-6973 patch. Trend Micro Apex One should be patched to build 17079 or later; until then, isolate the Apex web-admin interface behind a management VPN. Microsoft Exchange tenants should apply the OOB update for CVE-2026-42897, and restrict OWA external exposure to MFA-protected paths only. Hardening should follow ISO/IEC 27001 Annex A controls A.5.7 (threat intelligence), A.5.23 (information security for cloud services), A.8.8 (management of technical vulnerabilities), A.8.16 (monitoring activities) and A.8.23 (web filtering); under the NIST CSF mapping, the bulk of these controls land under Identify-AM, Protect-AC and Detect-CM. Helpdesk identity-verification scripts should be exercised against an explicit Scattered Spider / DragonForce voice-phishing scenario before the next quarter close. Healthcare clients should map controls onto the Data Security and Protection Toolkit (DSPT) requirements, NHS Digital Cyber Assurance Framework, and the Cyber Essentials Plus baseline. Supplier-concentration risk should be explicitly modelled — the Synnovis case study made concentration-risk a board-level governance concern, and the DXS December 2025 incident extended the pattern to GP-software suppliers. Pathology and GP-software supplier contracts should require demonstrated CAF level 2 at minimum.

Disrupt

Disruption activity within client lawful authority should focus on: (i) participation in the relevant ISAC indicator-exchange channel — FS-ISAC, H-ISAC, RH-ISAC, Aviation-ISAC, MTS-ISAC and the National Council of ISACs aggregator each provide indicator-sharing forums whose value compounds with active participation; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through the registrar-abuse channel and Cloudflare / Microsoft / Google trust-and-safety forms where attribution is sufficient; (iii) deception deployment in the helpdesk-identity-verification path — honey-identities seeded with watch-listed credential signatures will surface IAB front-end activity early; and (iv) tabletop exercise of the Scattered Spider / DragonForce playbook against the inbound helpdesk channel, scoped to a realistic voice-phishing-to-encryption window of 4 to 12 hours. The Health-ISAC is the natural indicator-sharing forum for the vertical, with sector-tailored Heartbeat reporting and a TLP:CLEAR trust group whose value compounds with active participation. NHS Digital's Cyber Security Operations Centre and CARE-CERT provide UK-anchored indicator sharing through the integrated NHS-trust network. NCSC's CiSP healthcare trust group offers complementary peer-exchange.

10. Forward outlook

Looking forward to the next reporting period (30 May – 5 June 2026), it is highly likely that Qilin, Akira, DragonForce and TheGentlemen will continue at the current leak-site cadence with healthcare-adjacent victims appearing each week. It is likely that one or more NHS trusts or healthcare suppliers will be identified through CiSP or vendor scan-reporting as exposed to CVE-2026-20182 (Cisco SD-WAN) or CVE-2026-42897 (Exchange OWA). There is a realistic possibility that DevMan or a similar emerging extortion operator will target another NHS supplier within the next two cycles.

*Trigger conditions that would prompt revision of this outlook include: (a) any UK NHS trust or supplier publicly disclosing a cyber-incident traceable to the edge-appliance CVEs flagged in Section 6; (b) the appearance of a UK healthcare victim on a Qilin / Akira / TheGentlemen leak-site, which would warrant an immediate client advisory; (c) a Health-ISAC TLP:CLEAR advisory pointing to a sector-wide credential-stuffing or supplier-compromise campaign; or (d) a fresh NHS-supplier ransomware claim by DevMan or successor.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1CISA KEV Catalog updates — 15, 20, 21, 27 May 2026 — https://www.cisa.gov/known-exploited-vulnerabilities-catalogCISAA1
2Cisco Catalyst SD-WAN Auth Bypass (CVE-2026-20182) — joint advisory CISA / NSA / FBI / NCSC-UK / ACSC / CCCS / NCSC-NZCISA et al.A1
3Talos Intelligence — Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616)Cisco TalosB2
4Trend Micro Apex One CVE-2026-34926 — CISA KEV addition 21 May 2026CISA / Trend MicroA1
5Microsoft Exchange Server CVE-2026-42897 — active exploitation confirmed by MicrosoftMicrosoft / Help Net SecurityB1
6NCSC weekly threat reports and advisory feed (NCSC-UK)NCSCA1
7ESET APT Activity Report — Oct 2025 to Mar 2026ESETB2
8Check Point Research — The State of Ransomware Q1 2026Check Point ResearchB2
9Ransomware.live — leak-site tracker (Qilin / Akira / DragonForce / TheGentlemen postings, week ending 28 May 2026)Ransomware.liveC2
10IP Insights — IP reputation enrichment (https://www.ipinsights.io)UK Cyber Defence LtdB2
11FS-ISAC — sector resilience and AI-fraud advisories (subscription)FS-ISACA2
12NCSC alert — Citrix NetScaler ADC / Gateway CVE-2026-3055 and CVE-2026-4368NCSCA1
13HSJ — £33m cost of Synnovis cyber attack revealedHealth Service JournalB2
14Digital Health — NHS GP software supplier DXS International hit by cyber attackDigital HealthB2
15Health-ISAC Heartbeat — surge in ransomware and VPN exploits across healthcareHealth-ISACA2
16Bank InfoSecurity — UK hospital asks court to stymie ransomware data leakBank InfoSecurityB2
17The Record — ransomware attack continues to disrupt London healthcare nearly two years laterRecorded Future NewsB2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.