Healthcare threat intelligence report — 20–26 June 2026
The dominant collection theme this period is continued aftermath reporting from the June 2026 London hospital ransomware incident, edge-appliance exposure introduced by the 23 June Ubiquiti UniFi OS KEV addition (operationally significant for hospital estates with widespread UniFi deployment)…
- Reference: TI-2026-0626-005 (public edition)
- Sector: Healthcare
- Reporting period: 20–26 June 2026
- Issued: 26 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Healthcare sector during the period 20 Jun 2026 - 26 Jun 2026. It is intended to support NHS Trust IT, private-hospital and primary-care IT functions, medical-device security teams and the senior information risk owner, and is graded TLP:CLEAR. The dominant collection theme this period is continued aftermath reporting from the June 2026 London hospital ransomware incident, edge-appliance exposure introduced by the 23 June Ubiquiti UniFi OS KEV addition (operationally significant for hospital estates with widespread UniFi deployment), and sustained Qilin and Akira leak-site activity against healthcare-adjacent organisations.
Healthcare cyber-resilience reporting continues to highlight the asymmetric impact of attacks: the June 3 London hospital ransomware incident postponed more than 6,000 appointments and procedures, demonstrating the operational fragility of the sector to encryption and data-theft events.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware operators - Qilin, Akira, LockBit 5.0 and the Anubis cluster - will continue to drive the majority of materially-disruptive incidents against UK and EU healthcare organisations through Q3 2026, consistent with sustained 2026 leak-site activity and the June 3 London hospital incident (HIGH confidence).
- It is highly likely that the three Ubiquiti UniFi OS defects added to KEV on 23 June will be exploited against unpatched hospital back-office and clinic-network UniFi deployments within the next 14 days (HIGH confidence).
- It is highly likely that the Lantronix EDS5000 defect (CVE-2025-67038) will be exploited against medical-device serial-to-IP bridges and legacy hospital OT estates within the next two reporting cycles, given the device's prevalence in legacy clinical-engineering environments (MEDIUM-HIGH confidence).
- It is highly likely that BEC and impersonation against hospital finance functions, supplier-payment teams and pharmacy-procurement teams will continue at sustained volume through the summer period (HIGH confidence).
- It is a realistic possibility that the June 3 London hospital incident actor will repeat the targeting pattern against another UK Trust or private-hospital provider within the next two reporting cycles, given the operational-impact reward of healthcare targeting (MEDIUM confidence).
2. Sector threat landscape
The UK and EU healthcare vertical is acutely exposed to cyber risk because of the asymmetric operational and patient-safety consequences of disruption. The June 3 London hospital ransomware incident postponed more than 6,000 appointments and procedures and resulted in publication of 400GB of patient names, dates of birth, NHS numbers and blood-test results. That event continues to anchor sector reporting and informs the threat model for the current period.
The collection picture this period is dominated by the 23 June Ubiquiti UniFi OS KEV addition (operationally significant because UniFi hardware is extensively deployed in hospital back-office, clinic, GP-surgery and dental-practice estates), the Lantronix EDS5000 KEV addition (relevant to legacy medical-device serial-to-IP bridges still in clinical-engineering inventories), and continued ransomware leak-site activity from Qilin and Akira against healthcare-adjacent organisations.
Healthcare-specific ransomware activity continued at elevated levels. Qilin remains the dominant volume leader and has historical healthcare targeting (the 2024 Synnovis pathology-services attack affecting NHS London remains the canonical UK reference). Akira and LockBit 5.0 are both active against healthcare-adjacent professional services. The Anubis cluster's targeting of critical-infrastructure operators - including the 13 June Adriatic Port Authority incident - is structurally similar to healthcare targeting and the threat model should treat the cluster as cross-sector.
Medical-device security remains a structural concern. Legacy clinical-engineering inventories continue to include unpatched Windows XP / Windows 7 imaging modalities, infusion pumps, ventilators and monitoring devices that cannot be patched without vendor re-validation. Serial-to-IP bridges (including Lantronix EDS5000) are commonly used to network these legacy devices, placing the CVE-2025-67038 defect directly in scope for healthcare clients with such inventories.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B, Water Galura
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Manufacturing, energy, financial services, healthcare, professional services, retail
- Geographic Focus: Global; sustained EU and UK targeting through 2026
- Signature TTPs: Initial access via phishing and exposed VPN / RDP; abuse of valid accounts; rapid AD escalation; data exfiltration via Rclone to Mega / Backblaze prior to encryption
- Tooling / Malware Families: Qilin / Agenda ransomware (Rust and Go builders), Cobalt Strike, AnyDesk, Rclone, PsExec
- Recent Activity: 22 Jun leak-site posting of Central Bank of Libya; sustained volume leadership across the reporting period (Insikt / ransomware.live)
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
Akira
- Aliases: Akira, Storm-1567 (some Microsoft attribution overlaps)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Financial services, professional services, manufacturing, education, legal, retail
- Geographic Focus: Global; consistent UK / EU presence
- Signature TTPs: Initial access via Cisco ASA / FTD SSL VPN brute force and exposed admin panels; abuse of valid accounts; rapid network mapping; ChaCha20 ransomware encryption
- Tooling / Malware Families: Akira ransomware (Linux and Windows variants), AnyDesk, RustDesk, WinSCP, Mimikatz
- Recent Activity: 22 Jun NTD Apparel posted to leak site; continued mid-week activity against professional-services sub-verticals
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
LockBit 5.0
- Aliases: LockBit, LockBit Black, LockBit Green, LockBit 5.0 (Aug 2025 relaunch)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Financial services, healthcare, manufacturing, government contractors, legal services
- Geographic Focus: Global; consistent UK / EU / NA volume
- Signature TTPs: Initial access via exposed RDP, public-facing exploits, valid accounts; ESXi-specific encryptor build; double-extortion via leak site
- Tooling / Malware Families: LockBit 5.0 encryptor (Win/Linux/ESXi variants), StealBit exfiltrator, Cobalt Strike, Mimikatz
- Recent Activity: Continuing 2026 leak-site activity post-relaunch; selective targeting of FS, legal and contractor sub-verticals
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: MEDIUM-HIGH
Anubis ransomware
- Aliases: Anubis (2026 cluster - distinct from earlier Anubis Android banker)
- Suspected Origin: Russian-speaking criminal underground (assessed)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion + leak-site
- Sector Targeting: Maritime port authorities, logistics, healthcare, manufacturing
- Geographic Focus: EU primary, expanding global
- Signature TTPs: Phishing-led initial access; data theft prior to encryption; high-value extortion demands against critical-infrastructure operators
- Tooling / Malware Families: Anubis ransomware, custom .NET loaders, Cobalt Strike
- Recent Activity: 13 Jun attack on Adriatic Port Authority (EU) reported by Resecurity; sustained presence over the reporting period
- Assessed Threat to Vertical: HIGH for maritime / logistics, MEDIUM elsewhere
- Analytic Confidence: MEDIUM
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Anticipated mass-exploitation of Ubiquiti UniFi OS chain at hospital back-office and clinic edge; Lantronix EDS5000 at medical-device serial-to-IP bridges | HIGH |
| Initial Access | T1078 | Valid Accounts | Reuse of credentials harvested from NHS-adjacent compromises; password-spray against M365 tenants of monitored Trusts and private-hospital providers | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | Sustained phishing against clinical and administrative staff with patient-themed and supplier-themed lures | HIGH |
| Execution | T1059.001 | Command and Scripting Interpreter: PowerShell | Cobalt Strike beacon execution post-initial-access during Qilin / Akira intrusions | MEDIUM |
| Persistence | T1543.003 | Windows Service | Implant deployment as Windows service on hospital back-office systems; consistent with LockBit 5.0 tradecraft | MEDIUM |
| Defense Evasion | T1562.001 | Disable or Modify Tools | EDR tampering observed in Qilin and Akira intrusions against healthcare victims | MEDIUM |
| Credential Access | T1003.001 | OS Credential Dumping: LSASS Memory | Standard Mimikatz / sekurlsa pattern post-domain-admin during ransomware intrusions | HIGH |
| Lateral Movement | T1021.001 | Remote Services: RDP | RDP-from-anomalous-source patterns; clinic-to-hospital cross-segment movement where segmentation is poor | MEDIUM |
| Collection / Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone to Mega / Backblaze / Wasabi for bulk patient-record exfiltration prior to encryption; pattern matches Qilin tradecraft | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Encryption phase of Qilin, Akira and LockBit 5.0; operational impact on patient-care delivery | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 23 Jun 2026 | Ubiquiti UniFi OS Server (vendor) | Unattributed | Three CVEs added to CISA KEV; hospital back-office, clinic-network, GP-surgery and dental-practice estates with UniFi hardware in scope | CISA KEV / Bishop Fox PoC |
| 23 Jun 2026 | Lantronix EDS5000 (vendor) | Unattributed | CVE-2025-67038 added to KEV; legacy medical-device serial-to-IP bridges in clinical-engineering inventories in scope | CISA KEV / Lantronix |
| 22 Jun 2026 | Healthcare-adjacent professional services | Akira | NTD Apparel posted to Akira leak-site 22 June; supply-chain exposure into hospital merchandise / uniform channels | ransomware.live |
| 22 Jun 2026 | Central Bank of Libya (Qilin posting) | Qilin | Not directly healthcare-relevant but illustrates Qilin's continued operational tempo and willingness to target high-profile victims | ransomware.live / Insikt Group |
| Continuing | June 3 2026 London hospital ransomware incident | Unattributed (criminal) | Continued aftermath reporting; 6,000+ appointments postponed; 400GB patient data published; sector risk profile anchor | The Record / industry reporting |
| Continuing | 2026 University of Mississippi Medical Center ransomware | Unattributed | 35 outpatient clinics closed during system restoration; appointment cancellations and procedure delays; sector reference for impact | Industry reporting |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8 immediately per CISA BOD 26-04 (due 26 Jun 2026); audit management plane exposure |
| CVE-2026-34909 | Ubiquiti UniFi OS Server < 5.0.8 - path traversal | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; restrict management plane to dedicated VLAN; review for file-system access anomalies |
| CVE-2026-34910 | Ubiquiti UniFi OS Server < 5.0.8 - improper input validation (chains to root RCE) | 10.0 | Yes | Yes | Patch immediately - Bishop Fox PoC chains the three UniFi defects to unauthenticated root RCE |
| CVE-2025-67038 | Lantronix EDS5000 Device Server - HTTP RPC command injection (root) | 9.8 | Yes | Yes | Apply Lantronix firmware update; remove internet exposure; segregate serial-to-IP devices to OT zone |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read / write | 8.8 | Yes | Yes | Force Chrome / Edge update across workstation estate via Intune / SCCM; verify against KEV due-date |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command injection | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; apply vendor mitigation; monitor for CLI abuse |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply Citrix advisory; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately per NCSC; rotate gateway service accounts; force session reset for all interactive users |
| CVE-2025-48595 | Android Framework - integer overflow leading to local privilege escalation | 7.8 | Yes | Yes | Push June 2026 Android security patch via MDM; require minimum patch level on BYOD enrolments |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 21 Jun 2026 | HIGH | F3 Netze AS205100 Tor exit (DE); IP Insights threat score 100 / critical; observed in EmilyAI-tagged perimeter brute-force tail this period |
| IP | 92[.]118[.]39[.]95 | 23 Jun 2026 | HIGH | UNMANAGED LTD (AS47890, GB-registered); IP Insights critical / suggest=block; appears in SSH and OWA brute-force tail |
| IP | 80[.]94[.]95[.]115 | 24 Jun 2026 | HIGH | SS-Net (RO) AS204428; IP Insights critical / suggest=block; sustained mass-scan against management plane endpoints |
| IP | 134[.]122[.]114[.]42 | 23 Jun 2026 | MEDIUM | DigitalOcean droplet IP; IP Insights critical / suggest=block; pattern-matches NetScaler probe traffic |
| IP | 198[.]235[.]24[.]31 | 20 Jun 2026 | MEDIUM | Google Cloud Platform US (AS396982); IP Insights critical / suggest=block; aggressive web-scan against client portals |
| IP | 162[.]142[.]125[.]34 | 25 Jun 2026 | LOW | Censys research scanner; benign but high-volume - exclude from alerting via known-scanner allow-list to reduce noise |
| IP | 64[.]227[.]107[.]117 | 24 Jun 2026 | MEDIUM | DigitalOcean droplet; IP Insights suggest=block; new this period - submitted to ipinsights.io reciprocal feed via EmilyAI |
| IP | 152[.]32[.]143[.]49 | 22 Jun 2026 | MEDIUM | UCloud HK (AS135377) hosting / datacenter, NG geolocation; observed in SaaS-tenant credential-stuffing tail |
| IP | 146[.]70[.]180[.]13 | 21 Jun 2026 | MEDIUM | M247 (RO) hosting; persistent credential-stuffing pattern against public-facing portals across multiple verticals |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via Ubiquiti UniFi OS chain at hospital / clinic edge with patient-care disruption | H | H | CRITICAL |
| Lantronix EDS5000 exploitation at medical-device serial-to-IP bridge with cyber-physical patient-safety exposure | M | H | HIGH |
| Bulk patient-record exfiltration to leak site via Qilin / Akira tradecraft | H | H | CRITICAL |
| BEC / payment-redirection against hospital finance / pharmacy-procurement function | H | M | HIGH |
| Repeat targeting of UK Trust or private-hospital provider in the June 3 London incident pattern | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
*Detection engineering should treat the Ubiquiti UniFi OS chain, the Lantronix EDS5000 HTTP RPC interface and the Qilin / Akira tradecraft set as the principal hunting hypotheses for this period. For healthcare-specific patterns, hunt for bulk-export activity against EPR systems (Epic, Cerner, Lorenzo, EMIS), against PACS / RIS imaging archives and against pharmacy systems.
Defend
Preventive priorities follow Section 6 directly. Ubiquiti UniFi OS 5.0.8 patch must be applied across the healthcare estate by 26 June to meet CISA BOD 26-04 - prioritise hospital back-office, clinic and surgery edge estates. Lantronix EDS5000 firmware update applies similarly to legacy clinical-engineering inventories; where firmware update is not viable without device re-validation, immediately remove from internet exposure and segregate to dedicated OT VLAN with restrictive ACLs. For identity hardening across hospital M365 tenants, enforce number-matching MFA, block legacy authentication, and ensure clinical-staff account-recovery procedures cannot be triggered without out-of-band identity verification. Ensure immutable, off-premises backups exist for EPR, PACS and pharmacy systems and that recovery time objectives are tested against the June 3 London incident impact baseline. Audit pharmacy-procurement payment-authorisation procedures for BEC resilience.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the Health Information Sharing and Analysis Centre (H-ISAC), the NHS Cyber Associates Network and the NCSC CiSP healthcare community, with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) coordination with NHS England Cyber Operations on the Ubiquiti UniFi OS chain and the Lantronix EDS5000 defect across NHS supplier estates; (iii) takedown coordination via NCSC ACD for hospital-themed phishing infrastructure; (iv) submission of observed bulk-EPR-exfiltration indicators to H-ISAC and to ipinsights.io; (v) coordination with clinical-engineering teams to inventory Lantronix-attached medical devices and to engage device vendors on patch availability.
10. Forward outlook
Looking forward to the next reporting period (27 Jun - 03 Jul 2026), it is likely that at least one UK or EU healthcare organisation will publicly disclose a ransomware or data-theft incident traceable to one of the Ubiquiti UniFi OS chain, the Lantronix EDS5000 defect or the Citrix NetScaler defects in Section 6. Qilin and Akira leak-site activity against healthcare-adjacent organisations is highly likely to continue at the current cadence with at least one further healthcare-adjacent posting expected.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | CISA Alert: Three Ubiquiti UniFi OS Flaws Added to KEV (23 Jun 2026) | CISA | A1 |
| 4 | CISA Alert: CVE-2025-67038 Lantronix EDS5000 added to KEV (23 Jun 2026) | CISA | A1 |
| 5 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 6 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 7 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 8 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 9 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 10 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 11 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 12 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 13 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 14 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 15 | IP Insights (ipinsights.io) IP enrichment, blocklists and STIX 2.1 feed | UK Cyber Defence Ltd | A1 |
| 17 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 18 | NHS England Cyber Operations advisories (June 2026) | NHS England | A1 |
| 19 | Health-ISAC sector advisories and indicator exchange (Week 26, 2026) | Health Information Sharing and Analysis Center | A1 |
| 20 | The Record: London hospital ransomware aftermath reporting | Recorded Future News | B2 |
| 21 | HIPAA Journal / industry reporting on healthcare ransomware impact (2026) | HIPAA Journal | C2 |
| 22 | MHRA medical-device cyber-safety guidance (current) | Medicines and Healthcare products Regulatory Agency | A1 |
| 23 | Bishop Fox UniFi OS root RCE chain technical write-up (Jun 2026) | Bishop Fox | B1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Healthcare Threat Intelligence Briefing
Healthcare Sector Ransomware Threat Analysis, May 2025
Healthcare threat intelligence report — 27 April – 3 May 2026
The healthcare threat picture for the reporting period continues to escalate. Health-ISAC reporting flags a 55% surge in cyber incidents in 2025 with continued escalation expected in 2026.
Healthcare threat intelligence report — 4–8 May 2026
The healthcare threat picture for the reporting period continues to escalate.