SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Legal services threat intelligence report — 11–17 July 2026

The legal-services vertical continues to be shaped by the NCSC Cyber Threat Report on the UK legal sector and by the accelerated cadence of intrusions against mid-market and boutique firms.

  • Reference: TI-2026-0717-003 (public edition)
  • Sector: Legal services — solicitors, barristers and legal service providers
  • Reporting period: 11–17 July 2026
  • Issued: 17 July 2026 · Lead analyst: EmilyAI · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Legal, Solicitors, Barristers and Legal Services sector during the period 11 Jul 2026 - 17 Jul 2026. It is intended to support security leadership and operational defenders within client organisations operating in the named vertical, and to inform decisions on detection priorities, defensive investment, and risk acceptance.

Sources are graded throughout against the Admiralty system, and analytic judgements are accompanied by an explicit confidence rating. The legal-services vertical continues to be shaped by the NCSC Cyber Threat Report on the UK legal sector and by the accelerated cadence of intrusions against mid-market and boutique firms. This reporting period the collection picture is dominated by four developments: the disclosure and exploitation of SonicWall SMA1000 zero-days CVE-2026-15409 / -15410 with a ransomware objective; the Microsoft AD FS elevation-of-privilege CVE-2026-56155 added to CISA KEV on 14 Jul 2026 with active exploitation confirmed; the 19-agency joint advisory of 13 Jul 2026 attributing systematic router-perimeter compromise to FSB Centre 16 with the paired APT28 "FrostArmada" M365-credential-theft campaign; and the continued dominance of The Gentlemen (121 leak-site postings in June 2026) and Qilin, both of which are actively targeting professional-services firms.

In the absence of a legal-sector ISAC, the vertical's highest-value shared-intelligence source remains the NCSC cyber threat report on the UK legal sector, supplemented by Law Society of Scotland journal analysis and by ad-hoc intra-firm sharing through Legal Sector Alliance / Cyber Law Society channels. The pattern published this July is that ransomware operators (Play, INC Ransom, The Gentlemen and Qilin) are treating mid-market and boutique firms as "low-hanging fruit" — 226 UK law firms suffered data breaches in the past year (Chaucer Group), and the nature of attacks continues to shift toward pure data extortion (11x growth in extortion-only incidents in the year, per Arctic Wolf).

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that Play, INC Ransom, The Gentlemen and Qilin will maintain their cadence against UK mid-market and boutique law firms during the next two reporting cycles; Barnes Solicitors LLP (Play, April 2026) and Weil, Gotshal & Manges (Luna Moth, May 2026) set the operational template (HIGH confidence).
  2. It is highly likely that pure data-extortion (encryption-less) intrusions will account for an increasing share of law-firm incidents through Q3 2026, given the 11x year-on-year growth reported by Arctic Wolf and the model's specific fit to attorney-client privilege leverage (HIGH confidence).
  3. It is likely that AD FS CVE-2026-56155 exploitation will affect at least one UK legal-sector federated-M365 tenant during the next two reporting cycles, given the same-day CISA KEV listing and the concentration of practice-management systems in M365 (MEDIUM-HIGH confidence).
  4. It is likely that SonicWall SMA1000 CVE-2026-15409 / -15410 chained exploitation will affect at least one UK legal-sector remote-access estate; SonicWall is common in mid-market firms (MEDIUM-HIGH confidence).
  5. It is a realistic possibility that a UK law firm will face regulatory action (ICO monetary penalty) for a cyber-related data breach disclosed in this or the next reporting period, in line with the ICO's stated intent and prior precedent (£60,000 April 2025 penalty) (MEDIUM confidence).

2. Sector threat landscape

The legal-services vertical continues to be shaped by the NCSC Cyber Threat Report on the UK legal sector and by the accelerated cadence of intrusions against mid-market and boutique firms. This reporting period the collection picture is dominated by four developments: the disclosure and exploitation of SonicWall SMA1000 zero-days CVE-2026-15409 / -15410 with a ransomware objective; the Microsoft AD FS elevation-of-privilege CVE-2026-56155 added to CISA KEV on 14 Jul 2026 with active exploitation confirmed; the 19-agency joint advisory of 13 Jul 2026 attributing systematic router-perimeter compromise to FSB Centre 16 with the paired APT28 "FrostArmada" M365-credential-theft campaign; and the continued dominance of The Gentlemen (121 leak-site postings in June 2026) and Qilin, both of which are actively targeting professional-services firms.

In the absence of a legal-sector ISAC, the vertical's highest-value shared-intelligence source remains the NCSC cyber threat report on the UK legal sector, supplemented by Law Society of Scotland journal analysis and by ad-hoc intra-firm sharing through Legal Sector Alliance / Cyber Law Society channels. The pattern published this July is that ransomware operators (Play, INC Ransom, The Gentlemen and Qilin) are treating mid-market and boutique firms as "low-hanging fruit" — 226 UK law firms suffered data breaches in the past year (Chaucer Group), and the nature of attacks continues to shift toward pure data extortion (11x growth in extortion-only incidents in the year, per Arctic Wolf).

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

The Gentlemen

  • Aliases: The Gentlemen (single-name RaaS brand); Qilin-affiliate lineage per Halcyon
  • Suspected Origin: Unattributed (Russian-speaking assessed)
  • Suspected Sponsor: Organised criminal RaaS
  • Primary Motivation: Financial (double extortion)
  • Sector Targeting: Broad mid-market; disproportionately professional services, legal, healthcare, manufacturing, retail, trade bodies
  • Geographic Focus: Global; western Europe and North America dominant in June-July 2026 tally; Germany over-represented
  • Signature TTPs: Initial access via brokered credentials and public-facing exploitation (SharePoint CVE-2026-45659 chains this period), LOTL tooling, aggressive leak-site publication cadence, PowerShell + custom Rust payload
  • Tooling / Malware Families: The Gentlemen ransomware (Rust), Rclone, PsExec, Cobalt Strike
  • Recent Activity: 121 leak-site postings in Jun 2026 (revised up from initial 115) - first month above Qilin in over a year; 300 postings across Q2 2026 (Qilin 289); 90% affiliate profit share; sustained cadence into 11-17 Jul 2026
  • Assessed Threat to Vertical: HIGH - fastest-growing RaaS brand
  • Analytic Confidence: HIGH

Qilin (a.k.a. Agenda)

  • Aliases: Agenda, Qilin.B, Water Galura
  • Suspected Origin: Russian-speaking (unattributed)
  • Suspected Sponsor: Organised criminal RaaS
  • Primary Motivation: Financial (double extortion)
  • Sector Targeting: Financial services, healthcare, manufacturing, retail, professional services, legal, logistics
  • Geographic Focus: Global; UK and EU disproportionately represented in H1 2026 leak-site postings; Germany over-represented
  • Signature TTPs: Initial access via brokered credentials, Check Point VPN CVE-2026-50751 exploitation, RMM abuse (AnyDesk, SplashTop), PowerShell + Rust ransomware payload; ESXi Linux variant
  • Tooling / Malware Families: Qilin.B ransomware (Rust), Cobalt Strike, Rclone-to-Mega, Mimikatz, SharpHound
  • Recent Activity: 1,496 leak-site victims across trailing 12 months (dominant RaaS by lifetime volume); 78 postings in June 2026 (overtaken by The Gentlemen); 289 postings across Q2 2026; Max Fordham (UK, 06 Jul 2026) leak-site claim
  • Assessed Threat to Vertical: HIGH - dominant RaaS operator across UK/EU by lifetime volume
  • Analytic Confidence: HIGH

Play

  • Aliases: Play ransomware, PlayCrypt
  • Suspected Origin: Russian-speaking (assessed)
  • Suspected Sponsor: Organised criminal RaaS
  • Primary Motivation: Financial (double extortion)
  • Sector Targeting: Legal, professional services, local government, financial services, healthcare, mid-market
  • Geographic Focus: Global
  • Signature TTPs: Initial access via brokered credentials, ProxyShell and public-facing exploitation; lateral movement; double-extortion follow-through; specific UK legal-sector focus in H1 2026
  • Tooling / Malware Families: Play ransomware, Cobalt Strike, AdFind, Mimikatz, PowerShell
  • Recent Activity: Barnes Solicitors LLP (UK legal firm) leak-site claim (Apr 2026); continued cadence into Q3 2026 with sustained UK legal-sector focus
  • Assessed Threat to Vertical: HIGH for legal sector; MEDIUM elsewhere
  • Analytic Confidence: HIGH

INC Ransom

  • Aliases: INC Ransomware, INC Ransom Group
  • Suspected Origin: Unattributed (Russian-speaking assessed)
  • Suspected Sponsor: Organised criminal RaaS
  • Primary Motivation: Financial (double extortion)
  • Sector Targeting: Legal, professional services, education, mid-market IT
  • Geographic Focus: Global; UK over-represented in H1 2026 legal-sector postings
  • Signature TTPs: Initial access via brokered credentials; ProxyShell and public-facing exploitation; PowerShell tooling; encryption + data-extortion
  • Tooling / Malware Families: INC ransomware
  • Recent Activity: Rapid campaign against UK law firms flagged by Halcyon; sustained cadence into Q3 2026
  • Assessed Threat to Vertical: HIGH for legal sector
  • Analytic Confidence: MEDIUM-HIGH

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1190Exploit Public-Facing ApplicationThis week the principal exploited public-facing systems observed by ISAC and government feeds are Microsoft SharePoint on-premises (CVE-2026-45659, rolling forward with Storm-2603 / Warlock ransomware use), SonicWall SMA1000 (CVE-2026-15409/-15410 zero-days, active from late June), AD FS (CVE-2026-56155 disclosed and added to KEV on 14 Jul), and three Joomla-family upload flaws added to CISA KEV in the trailing two weeks. All exploited within days of disclosure.HIGH
Initial AccessT1078.004Valid Accounts: Cloud AccountsFSB Centre 16 / APT28 "FrostArmada" activity (13 Jul 2026 joint advisory) hijacked DNS on approximately 18,000 SOHO routers to intercept Microsoft 365 credential and OAuth token flows. Concurrently, sustained password-spray and smart-lockout activity against Entra ID sign-in endpoints across the tenants we monitor (Entra ID password-spray campaign) rotating through five Microsoft app vectors (Azure CLI, AAD PowerShell, One Outlook Web, Teams, OfficeHome).HIGH
Initial AccessT1566.001Spearphishing AttachmentIcedID, Latrodectus and DarkGate loader chains via ISO/IMG/OneNote continued to dominate the phishing tail; volume steady week-on-week per Proofpoint and Sophos public telemetry. Anubis affiliate spear-phish tradecraft (documented in the Adriatic Port Authority intrusion earlier this year) remains active and directly relevant to any organisation with limited external-mail sandboxing.HIGH
Privilege EscalationT1068Exploitation for Privilege EscalationCVE-2026-56155 (AD FS DKM container ACL weakness) provides a low-privileged local user with a route to full administrator on the federation server. Because AD FS bridges on-premises AD to Microsoft 365 / Azure AD, exploitation here confers identity-federation-level control on the joined tenant.HIGH
DiscoveryT1046Network Service DiscoveryAutomated port sweeps from datacentre-hosted infrastructure; IP Insights flagged multiple AS209605 (HOSTBALTIC), dmzhost and Tor-exit sources in the perimeter tail this period.MEDIUM
Command and ControlT1071.001Application Layer Protocol: WebCobalt Strike, Sliver and Havoc HTTPS C2 beaconing observed in incident retrospectives via ISAC channels this period; JARM / JA3 fingerprint hunts remain the primary detection.HIGH
ExfiltrationT1567.002Exfiltration to Cloud StorageRclone-to-Mega and rclone-to-Backblaze exfiltration patterns dominant in Qilin, Akira, DragonForce and The Gentlemen double-extortion intrusions this period.HIGH
ImpactT1486Data Encrypted for ImpactQilin, Akira, DragonForce, The Gentlemen and Interlock ransomware deployment observed against sector-adjacent peers per ransomware.live and ISAC reporting. Warlock (Storm-2603) reported this period on SharePoint CVE-2026-45659 chains.HIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
14 Jul 2026Multiple SonicWall SMA1000 customers (global)Unattributed / assessed ransomware precursorSonicWall SMA1000 CVE-2026-15409/-15410 zero-days confirmed exploited from late June; Rapid7 MDR reports the observed goal is ransomware. Federal BOD 26-04 remediation deadline set to 17 Jul 2026.Rapid7 / SonicWall / CISA KEV
14 Jul 2026AD FS-federated Microsoft 365 tenants (global)UnattributedCVE-2026-56155 AD FS elevation-of-privilege added to CISA KEV on the day of disclosure with confirmation of active exploitation; DKM container ACL weakness allows a low-privileged local user to gain administrator on AD FS and therefore identity-federation control over the joined M365 / Azure AD tenant.Microsoft / CISA KEV / KB5121391
13 Jul 2026Critical national infrastructure and defence sector networks (multiple jurisdictions)FSB Centre 16 / Static Tundra / Berserk Bear (also APT28 "FrostArmada")19-agency joint advisory. Systematic compromise of Cisco, MikroTik and TP-Link routers at the perimeter of CNI and defence networks; separate APT28 "FrostArmada" campaign against ~18,000 SOHO routers hijacking DNS to steal Microsoft 365 credentials and OAuth tokens.NCSC / CISA / 19-agency joint advisory
11 Jul 2026The Gentlemen ransomware brandThe GentlemenThe Gentlemen retained first place among ransomware brands with 121 leak-site postings in June 2026 (vs Qilin 78) and reportedly 300 postings across Q2, edging Qilin at 289. Sustained UK / EU mid-market victim cadence into the reporting period, at a 90% affiliate profit share.Halcyon / SOCRadar / ransomware.live
Retrospective (Apr 2026, ongoing)Barnes Solicitors LLP - UK legal firmPlay ransomwareRetro reference. Play claimed Barnes Solicitors on their leak site and threatened data release; operational template for boutique-firm targeting continues into this reporting period.DeXpose / Halcyon
Retrospective (May 2026)Weil, Gotshal & Manges - US law firmLuna Moth (cyber extortion group)Retro reference. Reported extortion demand $18-20m against a firm holding sensitive client documents; illustrative of the pure-extortion model now favoured against legal-sector targets.Trowers & Hamlins / Solicitors Journal

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-15410SonicWall SMA1000 Appliance Management Console - post-authentication OS command injection7.2YesYesApplied by the same 12.4.3-02962 patch; observed chained with CVE-2026-15409 to gain unauthenticated code execution. Restrict management console to management VLAN and enable MFA on admin logins. Added to CISA KEV 14 Jul 2026.
CVE-2026-45659Microsoft SharePoint Server SubEd / 2019 / 2016 - deserialisation RCE (Site Member+ authenticated)8.8YesYesRolling forward from prior weeks. Microsoft May 2026 patch. Storm-2603 / Warlock ransomware operators observed exploiting during this period. Audit Site Member permissions; hunt w3wp.exe child processes (cmd.exe, powershell.exe, rundll32.exe) under the SharePoint application pool; restrict /_layouts/15 uploader paths at the WAF.
CVE-2026-48939Joomla iCagenda extension - unrestricted upload of file with dangerous type9.8YesYesUpdate iCagenda immediately; audit uploads directories for webshells; added to CISA KEV 10 Jul 2026.
CVE-2026-56291Joomla Balbooa Forms extension - unrestricted upload of file with dangerous type9.8YesYesUpdate Balbooa Forms immediately; audit uploads directories; added to CISA KEV 10 Jul 2026. Third Joomla-family upload flaw added to KEV in the trailing two weeks.
CVE-2026-48908JoomShaper SP Page Builder (Joomla) - unrestricted file upload of dangerous type9.8YesYesRolling forward from prior week. Update SP Page Builder; audit uploads directories for webshells. Added to CISA KEV 07 Jul 2026.
CVE-2026-56290Joomlack Page Builder (Joomla) - improper access control on administration endpoints9.1YesYesRolling forward from prior week. Update the extension; restrict administrator paths at the WAF. Added to CISA KEV 07 Jul 2026.
CVE-2026-55255Langflow - authorisation bypass through user-controlled key9.1YesYesRolling forward from prior week. Restrict LLM-tooling admin interfaces to internal networks. Added to CISA KEV 07 Jul 2026.
CVE-2026-8451Citrix NetScaler ADC / Gateway - memory overread (CitrixBleed 3 follow-on)9.3YesYesRolling forward. Apply fixed builds 14.1-66.59 / 13.1-62.23 / 13.1-37.262 FIPS/NDcPP; MUST run "kill icaconnection -all", "kill pcoipConnection -all", "kill aaa session -all" post-patch to invalidate stolen sessions. Exploited within 24h of 30 Jun 2026 disclosure.
CVE-2026-50751Check Point Security Gateway - improper authentication (Qilin-affiliate exploitation)9.8YesYesRolling forward. Apply Check Point R81.20 / R81.10 / R80.40 hotfixes; hunt admin sessions from non-management source addresses; Qilin affiliates observed leveraging as initial-access vector.

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IPv6 prefix2a06:b440::/3216 Jul 2026HIGHNinth documented family in the Entra ID password-spray campaign, first IPv6-only family; 40 events/7d against 9 named targets; observed across Microsoft Azure CLI, Azure Active Directory PowerShell, One Outlook Web and Microsoft Teams applications.
IP185[.]220[.]100[.]24011 Jul 2026HIGHF3 Netze e.V. AS205100 Tor exit (DE, tor-exit-13.zbau.f3netze.de). IP Insights threat score 100/critical, 7 active blacklists (IPInsights Honeypot, AbuseIPDB, ipsum, Dan.me.uk, Checkpoint TOR, malicious-ip); sustained perimeter tail against multiple estates during the reporting period.
IP45[.]148[.]10[.]24012 Jul 2026HIGHdmzhost bulletproof (NL). IP Insights threat score 100/critical, 5 blacklists including IPInsights Honeypot capture categorised "SSH/Telnet Brute Force"; SSH / RDWeb brute-force tail against monitored estates.

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Ransomware / data-extortion deployment against practice-management systems via SharePoint CVE-2026-45659 chainHHCRITICAL
SonicWall SMA1000 CVE-2026-15409/-15410 chained exploitation of legal-sector remote-access estateMHHIGH
AD FS CVE-2026-56155 exploitation against federated-M365 legal-sector tenantsMHHIGH
Pure data-extortion (Luna Moth-model) against attorney-client privileged materialHHCRITICAL
Business email compromise / vendor payment redirect against completions moniesHHCRITICAL
Client-side spear-phish leading to case-file access, particularly around high-value transactional or reputational mattersHMHIGH
Insider risk during mid-transaction or lateral-move periodsLHMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Implement SonicWall SMA1000 outbound-request hunts (T1190 → T1071.001). Add rclone / MEGA / Backblaze upload heuristics from finance and case-management endpoints — pure-data-extortion tradecraft leans heavily on cloud-storage exfiltration. Add explicit "large SharePoint / OneDrive download" hunts around the completions calendar for transactional practices. Maintain the standard SharePoint w3wp.exe child-process hunt for CVE-2026-45659 chains.

Defend

Preventive priorities: apply the SonicWall SMA1000 12.4.3-02962 patch immediately if in use; apply the July 2026 Patch Tuesday (KB5121391) on AD FS servers; apply SharePoint CVE-2026-45659 patching and audit Site Member permissions. Lift Microsoft 365 conditional access to require MFA on all administrative sign-ins and block legacy authentication. Given the router-perimeter advisory, audit firmware currency on any premises router that has not been replaced in the past 24 months.

Review privileged-access-workstation posture for partners handling large transactional matters. Verify DLP coverage on legal-sector-relevant document classes (case files, deal room content, wills / trusts, personal-injury bundles). Ensure incident-response retainer covers the specific regulatory notification obligations under the SRA / SRA-equivalent regime and the ICO.

Disrupt

Disruption activity within client lawful authority should focus on: (i) intra-firm sharing through Legal Sector Alliance / Law Society channels of any observed spear-phish tradecraft targeting completions monies or client-onboarding workflows; (ii) tabletop exercise of the Barnes Solicitors / Weil scenario, sequenced from initial spear-phish through case-file exfiltration and privileged-material extortion; (iii) coordinated takedown submissions against any AS200373 DREI-K-TECH-GMBH IP identified as attacker infrastructure against firm accounts; (iv) sector-level engagement with the ICO on breach-notification expectations for pure-data-extortion scenarios where encryption has not occurred.

10. Forward outlook

Looking forward to the next reporting period (18 Jul - 24 Jul 2026), it is likely that at least one UK boutique or mid-market law firm will surface on a leak site (Play, INC Ransom, The Gentlemen or Qilin), given the sustained cadence documented across Q2 2026. It is a realistic possibility that CVE-2026-56155 or CVE-2026-15409/-15410 exploitation will feature in a UK legal-sector public disclosure within this window. It is a realistic possibility that a Luna Moth-style pure-extortion intrusion will be publicly claimed against a UK firm within the next two reporting cycles.

Trigger conditions that would prompt revision of this outlook include: (a) any UK law firm publicly disclosing a breach linked to CVE-2026-56155, CVE-2026-15409/-15410 or CVE-2026-45659, which would warrant immediate out-of-cycle reporting; (b) ICO announcement of a monetary penalty against a law firm in this reporting period; (c) any Legal Sector Alliance TLP-shared indicator batch attributable to actors profiled in Section 3; (d) shift in Luna Moth-model activity from US to UK-terminated victims.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC-UK weekly threat reports and reports/advisories portalNational Cyber Security CentreA1
2CISA Known Exploited Vulnerabilities catalogue (daily updates)CISAA1
3CISA KEV additions 14 Jul 2026 (SonicWall SMA1000 CVE-2026-15409, CVE-2026-15410; Microsoft AD FS CVE-2026-56155; Cisco IOS CVE-2008-4128 re-listing)CISAA1
4CISA KEV additions 10 Jul 2026 (Joomla iCagenda CVE-2026-48939; Balbooa Forms CVE-2026-56291)CISAA1
5CISA KEV additions 07 Jul 2026 (JoomShaper SP Page Builder CVE-2026-48908; Langflow CVE-2026-55255; Joomlack Page Builder CVE-2026-56290)CISAA1
6Microsoft July 2026 Patch Tuesday - 622 CVEs including two actively-exploited zero-days (AD FS CVE-2026-56155, SharePoint CVE-2026-45659 rolling forward)Microsoft MSRC / Zero Day InitiativeA1
7SonicWall product notice - SMA1000 series multiple vulnerabilities and 12.4.3-02962 patch guidanceSonicWallA2
8Rapid7 MDR blog - SonicWall SMA1000 zero-day exploitation with ransomware objective (CVE-2026-15409, CVE-2026-15410)Rapid7A2
9Sophos X-Ops blog - SonicWall SMA1000 vulnerabilities in active exploitationSophosA2
1019-agency joint advisory - FSB Centre 16 (Static Tundra / Berserk Bear) systematic router compromise; APT28 "FrostArmada" 18,000-router DNS hijackNCSC / CISA / 17 partner agenciesA1
11Google Cloud Mandiant - Threats to the Defense Industrial Base (2026 update, China-nexus dominance)Google Cloud / MandiantA2
12The Hacker News / bytevanguard - CVE-2026-56155 AD FS DKM ACL hardening, active exploitation confirmedThird-party technical mediaB2
13ransomware.live daily leak-site tracker (Qilin, The Gentlemen, DragonForce, Akira, Interlock, Warlock)ransomware.liveB2
14Halcyon / SOCRadar - The Gentlemen 483 lifetime victims; 121 in June 2026, first month above QilinHalcyon / SOCRadarB2
15MOXFIVE / Infosecurity Magazine - Qilin ransomware 2026 profile (1,496 leak-site victims trailing 12 months)MOXFIVE / Infosecurity MagazineB2
16NCSC Anubis ransomware advisory (VPN credential abuse and RMM tradecraft)National Cyber Security CentreA1
17Bitdefender July 2026 Threat DebriefBitdefenderB2
18Check Point Q1 2026 State of Ransomware / ReliaQuest Q2 2026 Ransomware & Cyber ExtortionCheck Point Research / ReliaQuestB2
19CISA KEV entry rolling forward for CVE-2026-45659 (SharePoint deserialisation) - Storm-2603 / Warlock ransomware useCISA / Microsoft / hard2bitA1
20IP Insights REST API enrichment (multiple lookups during the reporting period - AS200373 DREI-K-TECH-GMBH pivot on the Entra ID password-spray campaign)IP Insights / UK Cyber Defence LtdA1
22Cybersecurity Breaches Survey 2025/2026 - UK statutory dataset (rolling reference)DSIT / GOV.UKA1
23Verizon Data Breach Investigations Report 2026 - sector chapters (rolling reference)VerizonB2
24NCSC Cyber Threat Report - UK Legal SectorNational Cyber Security CentreA1
25Law Society of Scotland journal - "Law in the crosshairs: ransomware gangs targeting low-hanging fruit firms" (July 2026)Law Society of ScotlandB2
26Chaucer Group press release - 226 UK law firms suffered data breaches in the past yearChaucer GroupB2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.