SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Maritime and logistics threat intelligence report — 20–26 June 2026

The dominant theme this week is exposure of OT bridge devices following CISA's 23 June addition of CVE-2025-67038 (Lantronix EDS5000 serial-to-IP code injection) to the Known Exploited Vulnerabilities catalogue - this is operationally critical to the maritime vertical because Lantronix devices are…

  • Reference: TI-2026-0626-002 (public edition)
  • Sector: Maritime and logistics
  • Reporting period: 20–26 June 2026
  • Issued: 26 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Maritime & Logistics sector during the period 20 Jun 2026 - 26 Jun 2026. It is intended to support operational defenders, vessel IT / OT operators, port authorities and 3PL providers, and is graded TLP:CLEAR. The dominant theme this week is exposure of OT bridge devices following CISA's 23 June addition of CVE-2025-67038 (Lantronix EDS5000 serial-to-IP code injection) to the Known Exploited Vulnerabilities catalogue - this is operationally critical to the maritime vertical because Lantronix devices are widely deployed as PLC / sensor bridges on vessel control networks, container terminals and port-yard automation.

The Anubis ransomware attack on the Adriatic Port Authority disclosed by Resecurity on 13 June continued to attract collection during this period, with sustained intelligence indicating broader EU port-authority targeting. Maritime cyber incident reporting from CYTUR and Smart Maritime Network has 2025 vessel-cyber incidents up 103% year-on-year and the 2026 trajectory remains upward.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that CVE-2025-67038 (Lantronix EDS5000) will be exploited against exposed serial-to-IP bridges on vessel control networks and port-yard estates within the next reporting cycle, given confirmed in-the-wild activity, the device's prevalence in maritime OT, and the operational criticality of the assets behind it (HIGH confidence).
  2. It is highly likely that ransomware operators - including the Anubis cluster - will continue to target European port authorities and 3PL operators through Q3 2026, consistent with the 13 June Adriatic Port Authority incident and the broader trend of critical-infrastructure extortion (HIGH confidence).
  3. It is likely that the three Ubiquiti UniFi OS defects added to KEV on 23 June will be exploited against unpatched edge devices at port offices, freight-forwarder branches and shipping-line back-office sites within the next 14 days (HIGH confidence).
  4. It is likely that AIS spoofing and GNSS jamming incidents will continue to rise alongside cyber-physical maritime activity in conflict-adjacent waters, consistent with CYTUR and IMO secretariat reporting through 2026 (MEDIUM confidence).
  5. It is a realistic possibility that an Iranian state-aligned actor (Screening Serpens or related) will conduct a credentialed intrusion against a UK or EU shipping line or insurer with Gulf-region exposure within the next two reporting cycles (MEDIUM confidence).

2. Sector threat landscape

*The maritime and logistics vertical sits at a unique cyber-physical intersection: vessel IT, vessel OT, port infrastructure, freight-forwarder enterprise IT, 3PL platforms, customs and trade-finance integrations and the air-cargo overlap each present distinct attack surfaces.

The Lantronix EDS5000 is widely deployed as a serial-to-IP bridge for legacy PLCs, RTUs and sensors on vessel control networks, container terminal yard equipment, port-side fuel and water systems and crane / RTG automation. CVE-2025-67038 chains an unauthenticated HTTP RPC interface to OS command injection running as root - operationally equivalent to a remote control primitive on whatever serial-attached OT lies behind the bridge. Resecurity, SecurityWeek and The Hacker News all confirmed exploitation activity in the period.

Ransomware activity against port authorities and logistics operators remained elevated. Anubis ransomware against the Adriatic Port Authority (disclosed 13 June) is the most operationally significant recent example, with reporting indicating exfiltration of detailed safety plans, staff records and operational communications, and an extortion demand of 10 million dollars. The trend is consistent with CYTUR's broader maritime incident reporting and with the 103% year-on-year rise in vessel-cyber incidents observed across 2025.

Geopolitical exposure remained relevant. Iranian state-aligned activity (Screening Serpens / MuddyWater overlap) tracked by Unit 42 continues to focus on Gulf-region maritime, energy and insurance targets, and any UK or EU operator with Gulf footprint should treat this as a current threat. AIS spoofing and GNSS jamming incidents in the Gulf and Black Sea attract continued IMO and class-society attention but remain outside the scope of conventional SIEM telemetry.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Anubis ransomware

  • Aliases: Anubis (2026 cluster - distinct from earlier Anubis Android banker)
  • Suspected Origin: Russian-speaking criminal underground (assessed)
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - extortion + leak-site
  • Sector Targeting: Maritime port authorities, logistics, healthcare, manufacturing
  • Geographic Focus: EU primary, expanding global
  • Signature TTPs: Phishing-led initial access; data theft prior to encryption; high-value extortion demands against critical-infrastructure operators
  • Tooling / Malware Families: Anubis ransomware, custom .NET loaders, Cobalt Strike
  • Recent Activity: 13 Jun attack on Adriatic Port Authority (EU) reported by Resecurity; sustained presence over the reporting period
  • Assessed Threat to Vertical: HIGH for maritime / logistics, MEDIUM elsewhere
  • Analytic Confidence: MEDIUM

Qilin (a.k.a. Agenda)

  • Aliases: Agenda, Qilin.B, Water Galura
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + leak-site extortion
  • Sector Targeting: Manufacturing, energy, financial services, healthcare, professional services, retail
  • Geographic Focus: Global; sustained EU and UK targeting through 2026
  • Signature TTPs: Initial access via phishing and exposed VPN / RDP; abuse of valid accounts; rapid AD escalation; data exfiltration via Rclone to Mega / Backblaze prior to encryption
  • Tooling / Malware Families: Qilin / Agenda ransomware (Rust and Go builders), Cobalt Strike, AnyDesk, Rclone, PsExec
  • Recent Activity: 22 Jun leak-site posting of Central Bank of Libya; sustained volume leadership across the reporting period (Insikt / ransomware.live)
  • Assessed Threat to Vertical: HIGH
  • Analytic Confidence: HIGH

Akira

  • Aliases: Akira, Storm-1567 (some Microsoft attribution overlaps)
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + extortion
  • Sector Targeting: Financial services, professional services, manufacturing, education, legal, retail
  • Geographic Focus: Global; consistent UK / EU presence
  • Signature TTPs: Initial access via Cisco ASA / FTD SSL VPN brute force and exposed admin panels; abuse of valid accounts; rapid network mapping; ChaCha20 ransomware encryption
  • Tooling / Malware Families: Akira ransomware (Linux and Windows variants), AnyDesk, RustDesk, WinSCP, Mimikatz
  • Recent Activity: 22 Jun NTD Apparel posted to leak site; continued mid-week activity against professional-services sub-verticals
  • Assessed Threat to Vertical: HIGH
  • Analytic Confidence: HIGH

Screening Serpens (Iran)

  • Aliases: Screening Serpens, MuddyWater overlap, CharmingKitten overlap
  • Suspected Origin: Islamic Republic of Iran
  • Suspected Sponsor: Nation-state (assessed IRGC-aligned)
  • Primary Motivation: Espionage, regional collection, retaliatory positioning
  • Sector Targeting: Government contractors, defence, R&D, maritime, energy
  • Geographic Focus: Middle East primary; expanding EU / UK
  • Signature TTPs: Spear-phishing with credential harvest; deployment of custom RAT families; ongoing positioning against regional adversaries
  • Tooling / Malware Families: Two new RAT variants documented by Unit 42 in 2026, MuddyWater-style scripting toolkits
  • Recent Activity: Increased operations since February 2026 regional conflict; activity across up to five countries (Unit 42)
  • Assessed Threat to Vertical: MEDIUM-HIGH for R&D and government contractor verticals
  • Analytic Confidence: MEDIUM

[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1190Exploit Public-Facing ApplicationAnticipated mass-exploitation of Lantronix EDS5000 (CVE-2025-67038) at port-yard and vessel-bridge OT estates and Ubiquiti UniFi OS chain at port-office edgeHIGH
Initial AccessT1566.001Spearphishing AttachmentSustained phishing against vessel-management agents, freight-forwarder operations staff and customs-brokerage personnel with weaponised PDF and Office luresHIGH
Initial AccessT1078Valid AccountsCredential reuse against vessel-VSAT terminal logins and port-authority remote-access portals; observed in EmilyAI brute-force tail this periodMEDIUM
PersistenceT1543.002Systemd ServiceAnticipated implant deployment as systemd unit on Lantronix and Linux-based vessel IT systems following EDS5000 exploitationMEDIUM
Defense EvasionT1070.004File DeletionAnti-forensic clean-up observed in Anubis ransomware case-work; aligns with Adriatic Port Authority incident reportingMEDIUM
Credential AccessT1110.003Password SprayingSustained password-spray against OWA / M365 tenants of monitored 3PL and freight-forwarder clientsHIGH
Lateral MovementT1021.002SMB / Windows Admin SharesCross-segment movement between IT and OT-adjacent vessel networks where segmentation is poorMEDIUM
Collection / ExfiltrationT1041Exfiltration Over C2 ChannelAnubis cluster exfiltration of safety plans and operational data prior to encryption per Adriatic Port Authority reportingHIGH
ImpactT1486Data Encrypted for ImpactAnubis ransomware encryption of port-authority IT estates; theoretical chained impact on connected OT systems if segmentation poorHIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
23 Jun 2026Lantronix EDS5000 (vendor)UnattributedCVE-2025-67038 added to CISA KEV; serial-to-IP bridge with confirmed in-the-wild exploitation; vessel and port OT estates directly in scopeCISA KEV / Lantronix / SecurityWeek
23 Jun 2026Ubiquiti UniFi OS Server (vendor)UnattributedThree CVEs added to KEV; port offices, freight-forwarder branches and shipping-line back-office sites with UniFi hardware in scopeCISA KEV / Bishop Fox PoC
13 Jun 2026 (continuing)Adriatic Port Authority (EU)Anubis ransomwareSustained reporting in this period; exfiltration of safety plans, staff records and operations comms; 10 million USD extortion demandResecurity / Military.africa
Through periodAIS spoofing / GNSS jamming Gulf and Black SeaState-aligned (assessed)Continued IMO and class-society reporting; not directly observable in client SIEM but operationally relevant to insurer and shipowner clientsIMO / class-society reporting
Through periodScreening Serpens (Iran)Iran-nexusContinued targeting per Unit 42; Gulf-exposed UK / EU maritime, energy and insurance firms inherit the threatPalo Alto Unit 42

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2025-67038Lantronix EDS5000 Device Server - HTTP RPC command injection (root)9.8YesYesApply Lantronix firmware update; remove internet exposure; segregate serial-to-IP devices to OT zone
CVE-2026-34908Ubiquiti UniFi OS Server < 5.0.8 - improper access control10.0YesYesPatch to UniFi OS Server 5.0.8 immediately per CISA BOD 26-04 (due 26 Jun 2026); audit management plane exposure
CVE-2026-34909Ubiquiti UniFi OS Server < 5.0.8 - path traversal10.0YesYesPatch to UniFi OS Server 5.0.8; restrict management plane to dedicated VLAN; review for file-system access anomalies
CVE-2026-34910Ubiquiti UniFi OS Server < 5.0.8 - improper input validation (chains to root RCE)10.0YesYesPatch immediately - Bishop Fox PoC chains the three UniFi defects to unauthenticated root RCE
CVE-2026-20245Cisco Catalyst SD-WAN Manager - CLI command injection7.8YesYesRestrict netadmin role; rotate netadmin credentials; apply vendor mitigation; monitor for CLI abuse
CVE-2026-20262Cisco Catalyst SD-WAN Manager - directory traversal8.6YesYesApply vendor mitigation; restrict management plane to jumpbox-only; monitor file-system access patterns
CVE-2026-3055Citrix NetScaler ADC / Gateway - memory disclosure7.4No (NCSC advisory)SuspectedApply Citrix advisory; rotate session secrets; monitor for anomalous gateway sessions
CVE-2026-4368Citrix NetScaler ADC / Gateway - authentication bypass9.1No (NCSC advisory)SuspectedPatch immediately per NCSC; rotate gateway service accounts; force session reset for all interactive users

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]100[.]24021 Jun 2026HIGHF3 Netze AS205100 Tor exit (DE); IP Insights threat score 100 / critical; observed in EmilyAI-tagged perimeter brute-force tail this period
IP92[.]118[.]39[.]9523 Jun 2026HIGHUNMANAGED LTD (AS47890, GB-registered); IP Insights critical / suggest=block; appears in SSH and OWA brute-force tail
IP80[.]94[.]95[.]11524 Jun 2026HIGHSS-Net (RO) AS204428; IP Insights critical / suggest=block; sustained mass-scan against management plane endpoints
IP134[.]122[.]114[.]4223 Jun 2026MEDIUMDigitalOcean droplet IP; IP Insights critical / suggest=block; pattern-matches NetScaler probe traffic
IP198[.]235[.]24[.]3120 Jun 2026MEDIUMGoogle Cloud Platform US (AS396982); IP Insights critical / suggest=block; aggressive web-scan against client portals
IP162[.]142[.]125[.]3425 Jun 2026LOWCensys research scanner; benign but high-volume - exclude from alerting via known-scanner allow-list to reduce noise
IP64[.]227[.]107[.]11724 Jun 2026MEDIUMDigitalOcean droplet; IP Insights suggest=block; new this period - submitted to ipinsights.io reciprocal feed via EmilyAI
IP152[.]32[.]143[.]4922 Jun 2026MEDIUMUCloud HK (AS135377) hosting / datacenter, NG geolocation; observed in SaaS-tenant credential-stuffing tail
IP146[.]70[.]180[.]1321 Jun 2026MEDIUMM247 (RO) hosting; persistent credential-stuffing pattern against public-facing portals across multiple verticals

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Lantronix EDS5000 exploitation enabling cyber-physical disruption of vessel OT or port-yard equipmentHHCRITICAL
Anubis-style ransomware extortion of EU port authorityHHCRITICAL
Ubiquiti UniFi OS exploitation at port office / freight-forwarder branch as ransomware initial-access vectorHMHIGH
Iranian state-aligned credentialed intrusion against Gulf-exposed shipping or insurance firmMHHIGH
AIS spoofing / GNSS jamming impacting marine-insurance underwriting decisions in conflict-adjacent watersMMMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection engineering should treat the Lantronix EDS5000 HTTP RPC interface and Ubiquiti UniFi OS management plane as the principal hunting hypotheses for this period. For vessel IT clients, hunt for new outbound connections from VSAT-attached IT subnets to non-traditional destinations and for password-spray patterns against M365 tenants serving shipboard crew accounts. Tune existing SOC rules to suppress benign Censys / Shodan scanner traffic (162.142.125.34) from alerting whilst retaining it in IP Insights enrichment.

Defend

Preventive priorities for the maritime vertical follow Section 6 directly. Segregate serial-to-IP bridges to a dedicated OT VLAN with restrictive ACLs and no outbound internet other than to vendor-update destinations. Apply Ubiquiti UniFi OS 5.0.8 to port-office and back-office estates by 26 June to meet CISA BOD 26-04. For vessel IT, enforce MFA on all VSAT terminal logins, separate crew-personal-use networks from vessel-operational networks, and ensure shipboard backup procedures meet IMO MSC.428(98) cyber-risk management code requirements. Audit Lantronix and OT-adjacent device inventories against MTS-ISAC sector guidance and confirm patch coverage to port-authority compliance functions where applicable.

Disrupt

Disruption activity within client lawful authority should focus on: (i) participation in the Maritime Transportation System ISAC (MTS-ISAC) and the Maritime ISAO with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) honeypot deployment fronting Lantronix EDS5000 device profiles to capture exploit attempt variants and report to CISA and the vendor; (iii) coordination with NCSC and CISP on the Anubis ransomware cluster's TTPs and IOCs; (iv) takedown coordination via NCSC ACD for maritime-themed phishing infrastructure flagged in client tenant inbox cohorts during the period; (v) submission of observed OT-targeted scanning to ipinsights.io for community blocklisting.

10. Forward outlook

Looking forward to the next reporting period (27 Jun - 03 Jul 2026), it is highly likely that exploitation of CVE-2025-67038 will become broadly documented, with at least one publicly attributed maritime or port-authority incident expected within the next two reporting cycles. Anubis ransomware activity is likely to continue at the current cadence with one further EU port-authority or major 3PL victim plausible by end of Q2. The 2026 trajectory of vessel-cyber incidents remains upward and shipowner and marine-insurer clients should expect continued growth in incident frequency.

Trigger conditions that would prompt revision of this outlook include: (a) public attribution of a Lantronix EDS5000 exploitation incident to a state-aligned actor, which would shift the Section 8 risk rating from CRITICAL to systemic and trigger out-of-cycle reporting; (b) a vessel-OT incident causing physical disruption (engine, steering, navigation), which would warrant immediate IMO and class-society engagement; (c) any expansion of Anubis ransomware activity beyond EU into UK port authorities, which would escalate the immediacy of MTS-ISAC indicator exchange. The principal intelligence gap remains direct visibility into vessel-IT telemetry for client shipowners not yet integrated with shore-side SIEM.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC-UK weekly threat reports and reports/advisories portalNational Cyber Security CentreA1
2CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feedCybersecurity & Infrastructure Security AgencyA1
3CISA Alert: Three Ubiquiti UniFi OS Flaws Added to KEV (23 Jun 2026)CISAA1
4CISA Alert: CVE-2025-67038 Lantronix EDS5000 added to KEV (23 Jun 2026)CISAA1
5MITRE ATT&CK Enterprise v15.1 framework and technique catalogueMITRE CorporationA1
6Mandiant M-Trends 2026 and Threat Intelligence advisoriesGoogle / MandiantB2
7Microsoft Threat Intelligence operational reports and Tempest namingMicrosoft CorporationB2
8CrowdStrike Global Threat Report 2026 and Adversary Universe updatesCrowdStrike HoldingsB2
9Cisco Talos research and weekly threat round-upCisco Talos Intelligence GroupB2
10Sophos X-Ops research blog and quarterly threat reportsSophos LtdB2
11Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo TrackerSpamhaus / abuse.chB2
12Ransomware.live aggregated leak-site monitoringransomware.liveC2
13Recorded Future Insikt Group operational reportsRecorded Future, Inc.B2
14GreyNoise scanning intelligence and tag observationsGreyNoise Intelligence, Inc.B2
15IP Insights (ipinsights.io) IP enrichment, blocklists and STIX 2.1 feedUK Cyber Defence LtdA1
17CISP indicator and incident summaries (peer-shared, trust-group)NCSC Cyber Security Information Sharing PartnershipA2
18MTS-ISAC sector advisories and indicator exchange (Week 26, 2026)Maritime Transportation System ISACA1
19Resecurity / Military.africa report on Anubis Adriatic Port Authority attack (13 Jun 2026)ResecurityB2
20CYTUR 2026 Maritime Cyber Incident Report (Jun 2026)CYTUR / Industrial CyberB2
21Palo Alto Unit 42 Screening Serpens tracking (Jun 2026)Palo Alto Networks Unit 42B2
22IMO MSC.428(98) Maritime Cyber Risk Management resolutionInternational Maritime OrganizationA1
23Lantronix EDS5000 vendor advisory (Jun 2026)Lantronix, Inc.A1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.