Maritime and logistics threat intelligence report — 6–12 June 2026
The maritime-and-logistics collection picture this week has been dominated by the convergence of the new no-patch network-edge defects (Cisco Catalyst SD-WAN Manager CVE-2026-20245 and Arista EOS CVE-2026-7473) with the still-current US Coast Guard MTSA Cyber Regulations compliance window.
- Reference: TI-2026-0612-002 (public edition)
- Sector: Maritime and logistics
- Reporting period: 6–12 June 2026
- Issued: 12 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Maritime and Logistics sector during the period 06 Jun 2026 - 12 Jun 2026. It is intended to support security leadership and operational defenders within the vertical and is issued under TLP:CLEAR.
The maritime-and-logistics collection picture this week has been dominated by the convergence of the new no-patch network-edge defects (Cisco Catalyst SD-WAN Manager CVE-2026-20245 and Arista EOS CVE-2026-7473) with the still-current US Coast Guard MTSA Cyber Regulations compliance window. Both defects sit squarely against the SD-WAN / data-centre fabric in use across global liner operators, port community systems, freight-forwarder hubs and 3PL / 4PL platforms. The Citrix NetScaler advisories from NCSC compound exposure on the operational-technology / IT-OT bridge that regulated maritime entities increasingly depend on for remote vessel and terminal management.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that the no-patch Cisco SD-WAN Manager (CVE-2026-20245) and Arista EOS (CVE-2026-7473) defects will be exploited against at least one global maritime or freight-forwarding operator within the next two reporting cycles, given the prevalence of both vendors in liner / port / 3PL data-centre fabrics and the absence of a vendor patch. (MEDIUM-HIGH confidence)
- It is highly likely that organised ransomware crews - Qilin, TheGentlemen, Akira and DragonForce - will continue to treat liner shipping, port community systems and 3PL / 4PL platforms as high-value targets, with mass-encryption of ESXi clusters supporting cargo-management and terminal-operating systems remaining the principal disruption modality. (HIGH confidence)
- It is likely that nation-state targeting of maritime and logistics infrastructure will continue in line with the broader pattern of China-, Russia- and DPRK-linked operator focus on critical-national-infrastructure adjacents, with port community systems and ship-to-shore communications as the highest-value access vectors. (MEDIUM confidence)
- It is a realistic possibility that the convergence of the US Coast Guard MTSA Cyber Regulations and the EU NIS2 Directive will surface previously-undisclosed incidents at smaller operators within the next reporting cycle as compliance-driven reporting matures. (MEDIUM confidence)
- It is highly likely that GPS / AIS spoofing and tampering will continue to be observed in the Black Sea, Eastern Mediterranean and Strait of Hormuz, with knock-on effects for shipping insurers and route-planning platforms used by UK-flagged operators. (HIGH confidence)
2. Sector threat landscape
The maritime-and-logistics vertical sits at the intersection of regulated critical national infrastructure, complex IT-OT integration and a sustained high-value criminal target set. The US Coast Guard's MTSA Cyber Regulations entered into force during 2026 with multiple compliance milestones falling through 2026 and 2027, formalising obligations around cyber risk assessment, incident reporting, account management and incident response for US-port-touching vessels and facilities. The EU NIS2 Directive and its UK equivalent CAF / ESF framework continue to mature, with the Department for Transport publishing supplementary maritime cyber guidance during the period.
Edge-appliance exposure continues to define the operational threat picture for the vertical. The Cisco Catalyst SD-WAN Manager defect CVE-2026-20245 (added to CISA KEV 09 June, no patch available) is the seventh SD-WAN zero-day Cisco has acknowledged in 2026; the prevalence of Cisco SD-WAN in liner data-centre, port community system and 3PL hub fabrics elevates this defect to the top of the maritime-and-logistics risk list for the reporting period. The Arista EOS tunnel-decap defect CVE-2026-7473 (no patch planned) is acutely relevant to inter-DC fabrics on which global cargo-management and terminal-operating systems depend. The Citrix NetScaler advisories from NCSC (CVE-2026-3055 / -4368) sit against the VPN concentrators commonly used to reach onboard vessel networks and remote-management consoles for cranes and gantries.
Organised criminal ransomware activity continues to treat the vertical as high-value. BreachSense's May 2026 retrospective places Qilin at 97-101 victims (fifth consecutive month at #1), TheGentlemen at 70, Akira at 64 and DragonForce at 32; cross-sector statistics indicate logistics and transportation as the third-most-targeted vertical behind manufacturing and healthcare. The ESXi-aware encryptor families used by Qilin and DragonForce specifically threaten the hypervisor estates that underpin cargo-management, dangerous-goods systems, electronic-bill-of-lading platforms and customs-broker integrations.
GPS / AIS spoofing and tampering remains a persistent operational concern in the Black Sea, Eastern Mediterranean and Strait of Hormuz; MTS-ISAC and equivalent maritime cyber sharing communities continue to circulate observed-position-deviation indicators.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda, Qilin.B)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russia (Russian-speaking)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion / data theft
- Sector Targeting: Cross-sector with sustained Maritime and Logistics relevance; demonstrated targeting of liner shipping and 3PL hubs.
- Geographic Focus: Global; UK, EU, US, ANZ
- Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
- Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
- Recent Activity: 97-101 victims posted in May 2026 - fifth consecutive month at top of leak-site postings (BreachSense / Check Point).
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: HIGH - multiply sourced (Check Point Research, BreachSense, Ransomware.live)
TheGentlemen
- Aliases: -
- Suspected Origin: Unattributed (likely Russian-speaking)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion
- Sector Targeting: Cross-sector with sustained Maritime and Logistics relevance.
- Geographic Focus: Cross-sector, global
- Signature TTPs: Rapid affiliate onboarding; multi-platform encryptor (Windows / Linux / BSD / NAS); SystemBC C2
- Tooling / Malware Families: Go-based encryptor; SystemBC; partner-supplied IAB access
- Recent Activity: 70 victims posted in May 2026 - second only to Qilin (BreachSense).
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: MEDIUM-HIGH
Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine
- Suspected Origin: UK / US / English-speaking community
- Suspected Sponsor: Criminal (IAB into DragonForce / LockBit / Qilin)
- Primary Motivation: Financial - extortion via partner ransomware
- Sector Targeting: Cross-sector with sustained Maritime and Logistics relevance, particularly BPO and outsourced IT helpdesks supporting freight / 3PL operators.
- Geographic Focus: UK, US, increasing EU and outsourced helpdesks abroad
- Signature TTPs: Voice-phishing of IT helpdesks, SIM-swap, MFA fatigue, OAuth consent-phish, RMM abuse (AnyDesk / ScreenConnect)
- Tooling / Malware Families: DragonForce / LockBit / Qilin partner encryptors; ESXi mass-encryption
- Recent Activity: DragonForce 32 victims in May 2026 (down from 41 in April per BreachSense); BPO / outsourced-helpdesk pattern continues.
- Assessed Threat to Vertical: HIGH - Admiralty A2.
- Analytic Confidence: HIGH - NCSC-UK, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced
UNC2891 / FIN13-adjacent transportation cluster
- Aliases: Unattributed in the open-source picture
- Suspected Origin: Mixed
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - cargo-theft enablement and freight-forwarding-fraud
- Sector Targeting: Maritime and Logistics primary
- Geographic Focus: Global
- Signature TTPs: EDI / EDIFACT manipulation; BEC against freight-forwarder and customs-broker finance teams; targeted phish against bill-of-lading platforms
- Tooling / Malware Families: Commodity loaders, password-stealer families, web-shell sets against Magento and similar storefronts
- Recent Activity: Continued reporting via INTERPOL / NCA logistics-fraud channels; no specific public attribution this reporting period.
- Assessed Threat to Vertical: MEDIUM-HIGH - direct logistics relevance; Admiralty C3.
- Analytic Confidence: MEDIUM
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Mass exploitation of Cisco Catalyst SD-WAN Manager (CVE-2026-20245), Arista EOS (CVE-2026-7473), Fortinet FortiClient EMS (CVE-2026-35616), Citrix NetScaler (CVE-2026-3055 / -4368) and Mirasvit Magento (CVE-2026-45247) against maritime / 3PL perimeters and storefronts. | HIGH |
| Initial Access | T1566.002 | Spear-phishing Link | Voice-phishing of outsourced IT helpdesks supporting freight / 3PL operators; OAuth consent-phishing of M365 tenants. | HIGH |
| Initial Access | T1078 | Valid Accounts | Reuse of IAB-purchased VPN credentials and NetScaler session tokens against maritime customer-portal estates. | HIGH |
| Execution | T1059.001 | Command and Scripting: PowerShell | Encoded PowerShell loaders staging SystemBC and Cobalt Strike Beacon. | MEDIUM |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Cisco SD-WAN Manager CLI command-injection (CVE-2026-20245) and Microsoft Defender BlueHammer chain (CVE-2026-33825). | HIGH |
| Defence Evasion | T1562.001 | Impair Defences: Disable Security Tools | EDR control-plane targeting via BlueHammer LPE. | MEDIUM |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGAcmd / AzCopy push prior to encryption. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | ESXi-aware Qilin.B and DragonForce encryptors continue mass-encryption of hypervisor estates. | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | CVE-2026-20245 added to CISA KEV; SD-WAN fabric supporting liner / 3PL hubs directly relevant. | CISA / Cisco PSIRT |
| 09 Jun 2026 | Arista EOS (vendor) | Unattributed | CVE-2026-7473 added to CISA KEV; tunnel-decap conflation; no patch. | CISA / Arista |
| 09 Jun 2026 | Google Chromium V8 | Unattributed | CVE-2026-11645 added to KEV; freight-platform admin-console relevance. | CISA / Google |
| 03 Jun 2026 | Mirasvit Magento | Unattributed | CVE-2026-45247 deserialisation; freight-quotation / cargo storefront relevance. | CISA |
| 02 Jun 2026 | Fortinet FortiClient EMS | Unattributed | CVE-2026-35616 ITW confirmed; carry. | watchTowr Labs |
| Ongoing | Qilin / TheGentlemen / Akira / DragonForce | Multiple | May 2026 leak-site volumes (97-101 / 70 / 64 / 32); logistics in top three target verticals. | BreachSense |
| Continuing | Black Sea / E. Med / Strait of Hormuz | Mixed state-linked | GPS / AIS spoofing and tampering continues; insurance and route-planning effects. | Open-source maritime tracking |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command-injection (authenticated, netadmin) | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; ACL Manager to management VLAN; monitor for crafted file uploads. No vendor patch at issue. |
| CVE-2026-7473 | Arista EOS - tunnel-protocol type not validated on decap interface (no patch planned) | 6.9 | Yes | Yes | Apply Arista mitigation: explicit per-protocol decap-group configuration; ACL the tunnel-endpoint IP; consider removal of decap on edge. |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read/write, browser-side RCE | 8.8 | Yes | Yes | Force-update Chrome and Chromium-derived browsers (Edge, Brave) across the fleet; enforce Site Isolation; verify SmartScreen / SafeBrowsing telemetry. |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer for Magento - deserialisation of untrusted data | 9.8 | Yes | Yes | Patch Mirasvit extension to vendor-supplied build; restrict admin/cache endpoints to internal IP space; rotate any captured admin tokens. |
| CVE-2025-48595 | Android Framework - integer overflow, limited targeted exploitation | 7.8 | Yes | Yes | Enforce June 2026 Android security patch level on managed devices via MDM; deprovision devices unable to receive the update. |
| CVE-2022-0492 | Linux Kernel cgroup release_agent - container escape (revived for cloud workloads) | 7.8 | Yes | Yes | Enforce seccomp / AppArmor / SELinux on container hosts; verify kernel >= 5.16.4 or backported patches; restrict unprivileged user namespaces. |
| CVE-2026-35616 | Fortinet FortiClient EMS - pre-auth RCE; watchTowr confirmed ITW exploitation 02 Jun (carry) | 9.8 | Yes | Yes | Patch to 7.4.2 or later; restrict EMS admin interface to management VLAN; hunt for new local accounts and outbound HTTP from EMS hosts. |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform - BlueHammer LPE / defence-evasion (carry) | 8.4 | Yes | Yes | Force MoCAMP rollout to 4.18.26040.1011 or later; hunt for FortiGate SSL-VPN sessions terminating from RU/SG/CH source IPs. |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - NCSC take-action notice (carry) | 9.1 | No | Suspected | Apply Citrix firmware; rotate NetScaler session tokens; force re-authentication across Gateway tenants; review for AAA-vserver tampering. |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - companion NCSC advisory (carry) | 8.8 | No | Suspected | Apply Citrix firmware bundle; baseline configuration drift; monitor for new admin or read-only accounts. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 85[.]137[.]228[.]167 | 24 May 2026 | HIGH | ServeTheWorld AS (NO, AS34989) - perimeter SSH/CMS brute-force; IP Insights threat=critical, 9 blacklists. |
| IP | 79[.]143[.]178[.]79 | 24 May 2026 | HIGH | Contabo (DE) - perimeter brute-force; IP Insights threat=critical, 8 blacklists. |
| IP | 51[.]68[.]226[.]87 | 02 Jun 2026 | HIGH | OVH SAS (FR, AS16276) - datacentre IP; carry-IOC sweep; IP Insights threat=critical, 6 blacklists. |
| IP | 136[.]232[.]11[.]10 | 02 Jun 2026 | HIGH | Reliance Jio (IN, AS55836) - carry-IOC; IP Insights threat=critical, 7 blacklists. |
| IP | 165[.]154[.]105[.]128 | 02 Jun 2026 | HIGH | UCLOUD HK (VN, AS135377) - datacentre; carry-IOC; IP Insights threat=critical, 7 blacklists. |
| ASN | AS135377 (UCLOUD HK) | 12 Jun 2026 | HIGH | IP Insights ASN risk=critical (81); 807/1000 sampled IPs blacklisted; recommend AS-level edge denial for low-business-need ASNs. |
| ASN | AS60729 (TorServers / Stiftung Erneuerbare Freiheit) | 12 Jun 2026 | HIGH | 190/191 sampled IPs blacklisted; treat Tor egress as inherently suspect for client estates. |
| ASN | AS51167 (Contabo) | 12 Jun 2026 | MEDIUM | IP Insights risk=high (52); 553/1000 sampled IPs blacklisted; common scanner / brute-force source. |
| Domain | sd-wan-vmanage-portal[.]net | 10 Jun 2026 | MEDIUM | Suspected Cisco SD-WAN Manager credential-phish landing. |
| URL | hxxps://maersk-customs-update[.]com/login | 08 Jun 2026 | MEDIUM | Generic logistics-themed phish lure. |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via SD-WAN / NetScaler initial-access against liner / TOS estates | H | H | CRITICAL |
| BEC and freight-forwarding fraud via finance-team phishing | H | H | HIGH |
| OT / IT-OT compromise of port community systems, cranes or gantries via NetScaler / VPN | M | H | HIGH |
| GPS / AIS spoofing affecting fleet operations and cargo insurance | H | M | MEDIUM-HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should prioritise (a) Cisco SD-WAN Manager netadmin role activity, config-push events from non-management VLANs, and crafted file uploads; (b) Arista EOS decap-protocol-conflation via gNMI / syslog; (c) NetScaler AAA-vserver tampering and session-token reuse outside expected geographies; (d) Fortinet FortiClient EMS admin-endpoint anomaly patterns from the watchTowr PoC; (e) anomalous EDI / EDIFACT changes against cargo-management and customs-broker integration points; and (f) anomalous OAuth-consent grants against M365 tenants supporting freight-management workflows. Maintain MTS-ISAC indicator ingestion where membership is held.
Defend
Preventive priorities follow Section 6 directly: enforce mitigation-only postures for CVE-2026-20245 and CVE-2026-7473 in the absence of vendor patches - restrict netadmin role membership, ACL the SD-WAN Manager and Arista tunnel-endpoint IP, and apply Arista's per-protocol decap-group configuration; patch Fortinet FortiClient EMS to 7.4.2; apply Citrix NetScaler firmware and rotate session tokens; force Microsoft Defender MoCAMP roll-up; force Chromium update. Verify segmentation between IT and OT networks supporting TOS, dangerous-goods, electronic-bill-of-lading and gantry / crane control planes.
Disrupt
Disruption activity within client lawful authority should focus on: (i) MTS-ISAC indicator sharing with this week's IP Insights critical tail as the highest-value contribution; (ii) takedown of Magento / Mirasvit storefront credential-phish destinations through registrar-abuse channels; (iii) sector-level coordination through MTS-ISAC of any UK-attributed Scattered Spider helpdesk-phish indicators; (iv) deception deployment on logistics-themed honeypot domains modelling NetScaler VPN portals and SD-WAN Manager landing pages.
10. Forward outlook
Looking forward to the next reporting period (13-19 Jun 2026), it is likely that at least one logistics or freight-forwarding operator will publicly disclose an incident traceable to one of the Cisco SD-WAN Manager, Arista EOS, Fortinet FortiClient EMS or Citrix NetScaler vulnerabilities flagged in Section 6 (MEDIUM-HIGH confidence). Qilin and TheGentlemen are highly likely to retain their leak-site dominance. GPS / AIS spoofing is highly likely to persist in current hotspots.
Trigger conditions that would prompt revision of this outlook include: (a) public disclosure by a UK-flagged operator or UK-port-touching liner of an incident traceable to one of the flagged CVEs; (b) appearance of a Qilin, Akira or DragonForce leak-site post naming a UK port community system, 3PL hub or 4PL platform; (c) MTS-ISAC TLP:CLEAR notification of a sector-wide TOS or EDI campaign; (d) USCG Marine Safety Information Bulletin escalating beyond current MTSA Cyber Regulations guidance. The principal intelligence gap to be closed is direct visibility into MTS-ISAC TLP:CLEAR traffic for the 06-12 Jun period.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports & advisories index, https://www.ncsc.gov.uk/section/keep-up-to-date/reports-advisories | A1 | |
| 2 | CISA Known Exploited Vulnerabilities Catalogue, additions of 02 / 03 / 09 Jun 2026, https://www.cisa.gov/known-exploited-vulnerabilities-catalog | A1 | |
| 3 | CISA Adds Three KEV (Arista EOS, Chromium V8, Cisco SD-WAN Manager), 09 Jun 2026, https://www.cisa.gov/news-events/alerts/2026/06/09/cisa-adds-three-known-exploited-vulnerabilities-catalog | A1 | |
| 4 | 'Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited - No Patch Available', Jun 2026 | The Hacker News | B2 |
| 5 | 'No Patch Planned for Exploited Arista EOS Vulnerability (CVE-2026-7473)', Jun 2026 | SecurityWeek | B2 |
| 6 | Fortinet FortiClient EMS CVE-2026-35616 in-the-wild exploitation confirmation, 02 Jun 2026 | watchTowr Labs | B2 |
| 7 | May 2026 ransomware retrospective (Qilin 97-101, TheGentlemen 70, Akira 64, DragonForce 32; 115 TB stolen) | BreachSense | B2 |
| 8 | 'The State of Ransomware - Q1 2026', https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/ | Check Point Research | B2 |
| 10 | IP Insights threat-assessment lookups (X-API-Key authenticated), https://www.ipinsights.io | A2 | |
| 11 | MITRE ATT&CK Enterprise framework v15, https://attack.mitre.org | A1 | |
| 12 | Cisco Security Advisory cisco-sa-sdwan-privesc-4uxFrdzx, Jun 2026 | A1 | |
| 13 | EOS tunnel decap protocol-type validation | Arista Security Advisory 0137 | A1 |
| 14 | MTS-ISAC bulletins and member sharing, https://www.mtsisac.org | B2 | |
| 15 | US Coast Guard MTSA Cyber Regulations in force 2026, https://www.uscg.mil/MaritimeCyber/ | A1 | |
| 16 | ENISA Threat Landscape for Maritime, latest update | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Maritime and logistics threat intelligence report — 4–8 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents…
Maritime and logistics threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the maritime and logistics threat picture remained dominated by ransomware and supply-chain compromise against vendor and TOS platforms.
Maritime and logistics threat intelligence report — 27 April – 3 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents…