SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Maritime and logistics threat intelligence report — 23–29 May 2026

The sector remains under elevated pressure: Cydome's May 2026 reporting places 2025 maritime cyber incident growth at 103% year-on-year, with OT-targeted attacks specifically up 150%, and GPS spoofing now affecting some 40,000 vessels per day worldwide.

  • Reference: TI-2026-0529-002 (public edition)
  • Sector: Maritime and logistics
  • Reporting period: 23–29 May 2026
  • Issued: 29 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Maritime and Logistics vertical during the period 23 May 2026 to 29 May 2026. The sector remains under elevated pressure: Cydome's May 2026 reporting places 2025 maritime cyber incident growth at 103% year-on-year, with OT-targeted attacks specifically up 150%, and GPS spoofing now affecting some 40,000 vessels per day worldwide. The collection picture this week is dominated by continued edge-appliance exploitation pressure (Cisco SD-WAN, Ivanti EPMM, Citrix NetScaler) — each of which is materially relevant to ports, freight forwarders and 3PLs whose operational technology increasingly sits behind those tiers — and by continued ransomware leak-site cadence from Qilin, Akira, DragonForce and TheGentlemen against transport-and-logistics victims. Sources are graded against the Admiralty System.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that ransomware operators — particularly Qilin, Akira, DragonForce and TheGentlemen — will continue to target maritime logistics and 3PL operators over the next reporting cycle, with sustained Q1 2026 cadence and the consolidation of leak-site activity into a small number of top-tier operators. (HIGH confidence)
  2. It is likely that nation-state and hacktivist GPS / GNSS spoofing activity will continue to disrupt vessel navigation at strategically-contested chokepoints (Strait of Hormuz, Bab-el-Mandeb, Black Sea), with downstream effects on cargo-tracking and ETA reliability for UK and EU shippers. (HIGH confidence)
  3. It is highly likely that the Cisco Catalyst SD-WAN auth-bypass (CVE-2026-20182) will be exploited against at least one port-operator or 3PL whose WAN architecture depends on the affected Cisco controller / manager pair within the next two reporting cycles, given documented UAT-8616 in-the-wild activity. (MEDIUM confidence)
  4. It is likely that AI-driven sabotage and RaaS-hacktivist alliances will increase OT-targeted pressure on UK and EU ports in H2 2026, per industry forecasting (Cydome, Dryad Global, Industrial Cyber). (MEDIUM confidence)
  5. There is a realistic possibility that Russian or Russian-aligned hacktivists will conduct disruption-grade DDoS against UK port booking and PCS / TOS interfaces over the next reporting cycle, particularly where the port has visible UK-government or Ukrainian-aid throughput. (MEDIUM confidence)

2. Sector threat landscape

Maritime cyber risk in 2026 is now uncontroversially treated as an operational shipping risk rather than a back-office IT concern. Cydome's May 2026 report places 2025 maritime cyber incident growth at 103% year-on-year, with OT-targeted attacks specifically up 150% — a trajectory whose persistence into Q1 2026 has been corroborated by CYTUR's smart-ship reporting and the Hellenic Shipping News systemic-risk treatment. Ransomware, DDoS and malware infections account for the majority of incidents; the remainder is dominated by GPS / GNSS spoofing and a small but consequential set of OT compromise events. Approximately 1,000 GPS disruption incidents are observed every day, affecting more than 40,000 vessels, and 2025 demonstrated that GPS spoofing now constitutes a direct physical safety threat rather than merely a navigational inconvenience.

Port and 3PL infrastructure has emerged as the operationally-meaningful pressure point for the vertical. Container operations halt when cargo-handling systems and logistics-management platforms become unavailable, forcing tankers and cargo ships to idle offshore and producing the cascading economic impact that ransomware operators have learned to monetise. The 2026 outlook from Cydome, Dryad Global and Industrial Cyber is converging on the view that hacktivist groups will increasingly leverage Ransomware-as-a-Service infrastructure against ports and logistics platforms aligned to adversary interest — a pattern already visible in the second half of 2025 against Iranian shipping (the Lab Dookhtegan attacks in March and August 2025 disabled communications for some 180 Iranian vessels).

Edge-appliance exposure has become the second consistent collection theme for the vertical. Cisco Catalyst SD-WAN Controller and Manager are widely deployed in port WAN architectures and in 3PL multi-site networks; CVE-2026-20182 (CVSS 10.0) with confirmed UAT-8616 in-the-wild activity should be treated as the highest-priority patching action of the cycle for any maritime / logistics organisation on the affected versions. Ivanti EPMM (CVE-2026-6973) and Trend Micro Apex One (CVE-2026-34926, KEV 21 May 2026) similarly carry critical risk where the operator deploys those products for mobile-device management or endpoint protection of their fleet-management or port-operations workforce. The Microsoft Exchange OWA zero-day CVE-2026-42897 carries material risk for on-prem mailbox estates of mid-tier shipping and port operators that have not migrated to Exchange Online.

Supply-chain risk in the vertical continues to grow with the diversity of integrated platforms: Port Community Systems, Terminal Operating Systems, fleet-management SaaS and freight-forwarding integrations each represent a credible compromise vector. Hacktivists, nation-state actors and ransomware operators have all demonstrated targeting of these layers, and the Cl0p pattern of MFT-zero-day exploitation continues to be relevant — the 2023 MOVEit / GoAnywhere / Cleo waves disproportionately affected logistics and freight operators, and any fresh MFT zero-day would be expected to follow the same exposure curve.

Geopolitical pressure on maritime trade lanes — particularly the Red Sea / Bab-el-Mandeb axis, the Strait of Hormuz, and the Black Sea — is sustaining nation-state and hacktivist interest in shipping disruption. ESET's APT activity report published 28 May highlighted continued Russian and China-nexus targeting of logistics and oil-shipment infrastructure across the reporting period; the May 2026 CISA, FBI, NSA and partners advisory on Russian state-sponsored cyber-espionage against technology companies and logistics entities remains the primary public anchor for that pressure.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Qilin (a.k.a. Agenda, Qilin.B)

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russia
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — extortion / data theft
  • Sector Targeting: Cross-sector with sustained Maritime & Logistics relevance.
  • Geographic Focus: Global; UK, EU, US, ANZ
  • Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
  • Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)

Akira

  • Aliases:
  • Suspected Origin: Russia-aligned criminal milieu
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — encryption + extortion
  • Sector Targeting: Cross-sector with sustained Maritime & Logistics relevance.
  • Geographic Focus: Global; SMB and mid-market heavy
  • Signature TTPs: Cisco VPN account abuse without MFA; rapid AD reconnaissance; ESXi targeting; brand-pressure leak-site
  • Tooling / Malware Families: Akira encryptor (Rust); RustDesk; AnyDesk; rclone; PCHunter; Mimikatz
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH

APT28 (Fancy Bear / Sednit / Forest Blizzard)

  • Aliases: Sofacy, STRONTIUM, Pawn Storm, Forest Blizzard
  • Suspected Origin: Russia
  • Suspected Sponsor: Nation-state — Russian GRU 26165
  • Primary Motivation: Espionage; geopolitical intelligence
  • Sector Targeting: Cross-sector with sustained Maritime & Logistics relevance.
  • Geographic Focus: NATO member states, Ukraine, MENA defence chain
  • Signature TTPs: Router compromise to hijack DNS; AiTM credential theft; Outlook NTLM relay; HeadLace / OceanMap implants
  • Tooling / Malware Families: X-Agent, X-Tunnel, HeadLace, OceanMap, Zebrocy, GooseEgg
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — NCSC and Five Eyes joint advisories
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty A1.
  • Analytic Confidence: HIGH — NCSC and Five Eyes joint advisories

Russian-aligned hacktivist (NoName057(16) / Killnet successor clusters)

  • Aliases: NoName057(16), Killnet successors, Cyber Army of Russia
  • Suspected Origin: Russian-speaking volunteer milieu
  • Suspected Sponsor: Hacktivist — aligned with Russian strategic interest
  • Primary Motivation: Disruption; brand-damage; ideological
  • Sector Targeting: Cross-sector with sustained Maritime & Logistics relevance.
  • Geographic Focus: UK, EU, NATO members supporting Ukraine
  • Signature TTPs: Volumetric DDoS against public-facing services; defacement; leak claims of dubious provenance
  • Tooling / Malware Families: DDoSia and similar booter ecosystems; Telegram coordination
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
ReconnaissanceT1595Active ScanningInternet-wide scanning for Cisco Catalyst SD-WAN, Ivanti EPMM and exposed Citrix NetScaler instances; mass-Shodan / Censys probing against maritime ASN ranges.HIGH
Initial AccessT1190Exploit Public-Facing ApplicationEdge-appliance exploitation (Cisco SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973, Apex One CVE-2026-34926, Citrix NetScaler CVE-2026-3055/4368).HIGH
Initial AccessT1078Valid AccountsIAB-brokered VPN and RDP credentials sold against UK and EU port-operator / 3PL ASN ranges; passwords harvested from prior breaches.HIGH
Initial AccessT1566PhishingSector-tailored phishing against fleet-management and customs-clearance staff; bill-of-lading and booking-confirmation pretexts.MEDIUM
ExecutionT1059.001Command and Scripting: PowerShellSystemBC / Cobalt Strike loaders post-edge-appliance compromise.MEDIUM
PersistenceT1505.003Server Software Component: Web ShellWeb-shell drops on exploited NetScaler and SD-WAN appliances for re-entry.MEDIUM
Privilege EscalationT1068Exploitation for Privilege EscalationUAT-8616 SD-WAN escalation to root via NETCONF manipulation.HIGH
Defence EvasionT1562.001Impair Defences: Disable Security ToolsApex One CVE-2026-34926 directory-traversal used to disable agents prior to ransomware stage.MEDIUM
ExfiltrationT1567.002Exfiltration to Cloud Storagerclone / MEGA / AzCopy egress to attacker-controlled storage.HIGH
ImpactT1486Data Encrypted for ImpactQilin.B / DragonForce / Akira ESXi-aware encryption of port and 3PL hypervisor estates.HIGH
ImpactT1498Network Denial of ServiceRussian-aligned hacktivist DDoS against port booking, PCS and TOS web interfaces.MEDIUM

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
24 May 2026Global Retool Group (Business Services, supply-chain adjacent)QilinPosted to Qilin leak-site 24 May; ongoing data-extortion.Ransomware.live
Week of 26 May 2026Sunrise Company (real-estate / resort logistics, US)Akira / Qilin (both posted)Cross-posted to both Akira and Qilin leak-sites; illustrates affiliate overlap.Ransomware.live
OngoingRed Sea / Bab-el-Mandeb GPS / GNSS spoofingMultiple (Houthi-aligned and unattributed)Some 40,000 vessels affected daily by signal interference; MSC Antonia grounding (May 2025) remains the canonical case study.Dryad Global / IMO MSC
May 2026Russian state-sponsored cyber-espionage campaign against technology and logistics entities — CISA / FBI / NSA joint advisoryAPT28-adjacent / Russian SVR / GRUSustained collection against logistics-platform operators supporting Ukraine aid throughput.CISA joint advisory
28 May 2026ESET APT Activity Report — oil shipments and drone-maker targetingMultiple — Russian, Chinese, North Korean and Iranian APTsSustained pressure on oil-shipment logistics and dual-use maritime supply chain; methodologically transparent vendor reporting.ESET APT Activity Report

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN Controller / Manager (auth bypass; UAT-8616 in-the-wild)10.0YesYesPatch immediately; rotate SSH keys; review NETCONF logs
CVE-2026-6973Ivanti EPMM (post-CVE-2026-1340 credential reuse chain)7.2YesYesPatch and rotate any admin credential issued before 1 Feb 2026
CVE-2026-34926Trend Micro Apex One (On-Premise) — directory traversal9.4YesYesPatch to build ≥17079; treat as EDR-control-plane exposure until verified
CVE-2026-42897Microsoft Exchange Server (Subscription Edition / 2019 / 2016) — XSS via crafted email8.1YesYesApply 14 May 2026 OOB update; disable OWA externally pending patch
CVE-2025-34291Langflow — origin validation error (added KEV 21 May 2026)9.1YesSuspectedPatch and restrict admin endpoints to trusted networks
CVE-2026-8398 / CVE-2026-45321 / CVE-2026-48027DAEMON Tools Lite / TanStack packages / Nx Console developer extension (supply-chain trio added KEV 27 May)8.0–8.8YesYesAudit developer endpoints; remove compromised package versions
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler ADC and Gateway (NCSC alert week of 24 May)9.0 / 7.5NoSuspectedApply Citrix advisory updates; review session tokens

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]101[.]5ongoingMTOR exit node — Network Attack + tor_exit categories, IP Insights suggestion: block
IP193[.]32[.]162[.]157ongoingMBrute-force / malware family — listed on 6 blacklists per IP Insights
Domainglobal-retool-leaks[.]onion24 May 2026MQilin leak-site post — Global Retool Group disclosure

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Ransomware deployment against port operator or 3PL via IAB front-end → Qilin / Akira / DragonForceHIGHHIGHCRITICAL
Edge-appliance exploitation (Cisco SD-WAN / Ivanti EPMM / NetScaler) against fleet- or port-operator WANHIGHHIGHCRITICAL
GPS / GNSS spoofing at chokepoint affecting UK-relevant vessel navigationHIGHMEDIUMHIGH
Hacktivist DDoS against PCS / TOS / port-booking interfacesMEDIUMMEDIUMMEDIUM
OT-segment compromise via flat-network exposure of TOS / fleet-mgmt platformsMEDIUMHIGHHIGH
Supply-chain compromise via shared logistics SaaS or MFT zero-day (Cl0p pattern)MEDIUMHIGHHIGH

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection engineering should treat the Cisco Catalyst SD-WAN compromise pattern as the highest-priority hunting hypothesis for the next reporting cycle. Cross-walk EPMM admin logins against the documented CVE-2026-1340 / CVE-2026-6973 credential set, rotating any admin token issued before 1 February 2026 as untrusted. For Microsoft Exchange tenants still on-prem, instrument OWA crafted-email telemetry against CVE-2026-42897 — IIS access logs paired with mailbox event 41 should surface the exploitation primitive. Trend Micro Apex One administrators should monitor for directory-traversal probes against the ApexOne web-admin endpoint and treat any EDR-control-plane configuration change without a corresponding change-management record as a P1 trigger. For maritime / logistics tenants specifically, instrument GPS / GNSS-feed integrity at the edge of the bridge-LAN where present, and treat any sustained position-drift from AIS or ECDIS reporting as a P2 hunting hypothesis. Detection of unsigned process-injection sources against TOS / fleet-management Windows hosts should be prioritised, and any new external SSH key on a Cisco SD-WAN Controller / Manager should generate a P1 alert. Hunt for rclone / MEGA / AzCopy execution lineages within the port-operations DMZ and within fleet-management VLANs.

Defend

Preventive priorities follow Section 6 directly: patch Cisco Catalyst SD-WAN Controller and Manager out of band as the single highest-value action of the reporting cycle, treat any pre-patch SD-WAN admin credential as untrusted, and rotate. EPMM tenants should rotate all admin credentials issued before 1 February 2026 and apply the CVE-2026-6973 patch. Trend Micro Apex One should be patched to build 17079 or later; until then, isolate the Apex web-admin interface behind a management VPN. Microsoft Exchange tenants should apply the OOB update for CVE-2026-42897, and restrict OWA external exposure to MFA-protected paths only. Hardening should follow ISO/IEC 27001 Annex A controls A.5.7 (threat intelligence), A.5.23 (information security for cloud services), A.8.8 (management of technical vulnerabilities), A.8.16 (monitoring activities) and A.8.23 (web filtering); under the NIST CSF mapping, the bulk of these controls land under Identify-AM, Protect-AC and Detect-CM. Helpdesk identity-verification scripts should be exercised against an explicit Scattered Spider / DragonForce voice-phishing scenario before the next quarter close. Maritime / logistics clients should map controls onto IMO MSC.428(98), NIS2 Annex I sector obligations where applicable, and the BIMCO Cyber Security Onboard Ships v5 guidance. Port operators in EU jurisdictions should additionally consider the Port Community System and Terminal Operating System segregation requirements emerging under the EU NIS2 implementation. Bridge LAN should be physically segregated from the corporate WAN where feasible, with one-way data diodes for any unavoidable export of AIS / ECDIS / fleet-management telemetry.

Disrupt

Disruption activity within client lawful authority should focus on: (i) participation in the relevant ISAC indicator-exchange channel — FS-ISAC, H-ISAC, RH-ISAC, Aviation-ISAC, MTS-ISAC and the National Council of ISACs aggregator each provide indicator-sharing forums whose value compounds with active participation; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through the registrar-abuse channel and Cloudflare / Microsoft / Google trust-and-safety forms where attribution is sufficient; (iii) deception deployment in the helpdesk-identity-verification path — honey-identities seeded with watch-listed credential signatures will surface IAB front-end activity early; and (iv) tabletop exercise of the Scattered Spider / DragonForce playbook against the inbound helpdesk channel, scoped to a realistic voice-phishing-to-encryption window of 4 to 12 hours. Participation in the Maritime Transportation System ISAC and the Aviation ISAC (for any client with combined cargo / passenger throughput) is the natural indicator-sharing forum; BIMCO and OCIMF have additionally been useful peer-exchange forums for the vertical. NCSC's CiSP maritime trust group provides UK-anchored indicator sharing and is recommended for any UK port operator or 3PL with national CNI throughput exposure.

10. Forward outlook

Looking forward to the next reporting period (30 May – 5 June 2026), it is highly likely that Qilin, Akira, DragonForce and TheGentlemen will continue to post at the current Q1 2026 cadence, with at least one transport-and-logistics victim per week across their combined leak-sites. It is likely that one or more UK / EU port operators or 3PLs will be identified as exposed to CVE-2026-20182 (Cisco SD-WAN) through CiSP or vendor scan-reporting. There is a realistic possibility that Russian-aligned hacktivists will conduct DDoS against UK port-booking interfaces over the next two cycles. GPS / GNSS spoofing at the Strait of Hormuz, Bab-el-Mandeb and Black Sea axes will continue, with sustained operational impact for vessels transiting those chokepoints.

*Trigger conditions that would prompt revision of this outlook include: (a) a publicly-disclosed OT-segment compromise at a UK or major-EU port; (b) the appearance of a UK 3PL or shipping-line victim on a Qilin / Akira / TheGentlemen leak-site, which would warrant an immediate client advisory; (c) a substantive escalation in GPS spoofing geography (e.g. into the English Channel or Eastern Mediterranean); or (d) a Cl0p-style fresh MFT zero-day, which historically has had disproportionate logistics-sector impact.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1CISA KEV Catalog updates — 15, 20, 21, 27 May 2026 — https://www.cisa.gov/known-exploited-vulnerabilities-catalogCISAA1
2Cisco Catalyst SD-WAN Auth Bypass (CVE-2026-20182) — joint advisory CISA / NSA / FBI / NCSC-UK / ACSC / CCCS / NCSC-NZCISA et al.A1
3Talos Intelligence — Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616)Cisco TalosB2
4Trend Micro Apex One CVE-2026-34926 — CISA KEV addition 21 May 2026CISA / Trend MicroA1
5Microsoft Exchange Server CVE-2026-42897 — active exploitation confirmed by MicrosoftMicrosoft / Help Net SecurityB1
6NCSC weekly threat reports and advisory feed (NCSC-UK)NCSCA1
7ESET APT Activity Report — Oct 2025 to Mar 2026ESETB2
8Check Point Research — The State of Ransomware Q1 2026Check Point ResearchB2
9Ransomware.live — leak-site tracker (Qilin / Akira / DragonForce / TheGentlemen postings, week ending 28 May 2026)Ransomware.liveC2
10IP Insights — IP reputation enrichment (https://www.ipinsights.io)UK Cyber Defence LtdB2
11FS-ISAC — sector resilience and AI-fraud advisories (subscription)FS-ISACA2
12NCSC alert — Citrix NetScaler ADC / Gateway CVE-2026-3055 and CVE-2026-4368NCSCA1
13Cydome — 150% surge in maritime OT cyberattacks 2025 retrospectiveCydome / Industrial CyberB2
14CYTUR — smart-ship secure-by-design overhaul advisory 2026CYTUR / SAFETY4SEAB2
15Dryad Global — Channel 16 Maritime Cyber Risk 2026Dryad GlobalB2
16CISA / FBI / NSA joint advisory — Russian state-sponsored campaign against technology and logistics entities (May 2026)CISA / FBI / NSAA1
17Hellenic Shipping News — Port digitisation and systemic cyber riskHellenic Shipping NewsC2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.