Maritime and logistics threat intelligence report — 20–26 June 2026
The dominant theme this week is exposure of OT bridge devices following CISA's 23 June addition of CVE-2025-67038 (Lantronix EDS5000 serial-to-IP code injection) to the Known Exploited Vulnerabilities catalogue - this is operationally critical to the maritime vertical because Lantronix devices are…
- Reference: TI-2026-0626-002 (public edition)
- Sector: Maritime and logistics
- Reporting period: 20–26 June 2026
- Issued: 26 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Maritime & Logistics sector during the period 20 Jun 2026 - 26 Jun 2026. It is intended to support operational defenders, vessel IT / OT operators, port authorities and 3PL providers, and is graded TLP:CLEAR. The dominant theme this week is exposure of OT bridge devices following CISA's 23 June addition of CVE-2025-67038 (Lantronix EDS5000 serial-to-IP code injection) to the Known Exploited Vulnerabilities catalogue - this is operationally critical to the maritime vertical because Lantronix devices are widely deployed as PLC / sensor bridges on vessel control networks, container terminals and port-yard automation.
The Anubis ransomware attack on the Adriatic Port Authority disclosed by Resecurity on 13 June continued to attract collection during this period, with sustained intelligence indicating broader EU port-authority targeting. Maritime cyber incident reporting from CYTUR and Smart Maritime Network has 2025 vessel-cyber incidents up 103% year-on-year and the 2026 trajectory remains upward.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that CVE-2025-67038 (Lantronix EDS5000) will be exploited against exposed serial-to-IP bridges on vessel control networks and port-yard estates within the next reporting cycle, given confirmed in-the-wild activity, the device's prevalence in maritime OT, and the operational criticality of the assets behind it (HIGH confidence).
- It is highly likely that ransomware operators - including the Anubis cluster - will continue to target European port authorities and 3PL operators through Q3 2026, consistent with the 13 June Adriatic Port Authority incident and the broader trend of critical-infrastructure extortion (HIGH confidence).
- It is likely that the three Ubiquiti UniFi OS defects added to KEV on 23 June will be exploited against unpatched edge devices at port offices, freight-forwarder branches and shipping-line back-office sites within the next 14 days (HIGH confidence).
- It is likely that AIS spoofing and GNSS jamming incidents will continue to rise alongside cyber-physical maritime activity in conflict-adjacent waters, consistent with CYTUR and IMO secretariat reporting through 2026 (MEDIUM confidence).
- It is a realistic possibility that an Iranian state-aligned actor (Screening Serpens or related) will conduct a credentialed intrusion against a UK or EU shipping line or insurer with Gulf-region exposure within the next two reporting cycles (MEDIUM confidence).
2. Sector threat landscape
*The maritime and logistics vertical sits at a unique cyber-physical intersection: vessel IT, vessel OT, port infrastructure, freight-forwarder enterprise IT, 3PL platforms, customs and trade-finance integrations and the air-cargo overlap each present distinct attack surfaces.
The Lantronix EDS5000 is widely deployed as a serial-to-IP bridge for legacy PLCs, RTUs and sensors on vessel control networks, container terminal yard equipment, port-side fuel and water systems and crane / RTG automation. CVE-2025-67038 chains an unauthenticated HTTP RPC interface to OS command injection running as root - operationally equivalent to a remote control primitive on whatever serial-attached OT lies behind the bridge. Resecurity, SecurityWeek and The Hacker News all confirmed exploitation activity in the period.
Ransomware activity against port authorities and logistics operators remained elevated. Anubis ransomware against the Adriatic Port Authority (disclosed 13 June) is the most operationally significant recent example, with reporting indicating exfiltration of detailed safety plans, staff records and operational communications, and an extortion demand of 10 million dollars. The trend is consistent with CYTUR's broader maritime incident reporting and with the 103% year-on-year rise in vessel-cyber incidents observed across 2025.
Geopolitical exposure remained relevant. Iranian state-aligned activity (Screening Serpens / MuddyWater overlap) tracked by Unit 42 continues to focus on Gulf-region maritime, energy and insurance targets, and any UK or EU operator with Gulf footprint should treat this as a current threat. AIS spoofing and GNSS jamming incidents in the Gulf and Black Sea attract continued IMO and class-society attention but remain outside the scope of conventional SIEM telemetry.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Anubis ransomware
- Aliases: Anubis (2026 cluster - distinct from earlier Anubis Android banker)
- Suspected Origin: Russian-speaking criminal underground (assessed)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion + leak-site
- Sector Targeting: Maritime port authorities, logistics, healthcare, manufacturing
- Geographic Focus: EU primary, expanding global
- Signature TTPs: Phishing-led initial access; data theft prior to encryption; high-value extortion demands against critical-infrastructure operators
- Tooling / Malware Families: Anubis ransomware, custom .NET loaders, Cobalt Strike
- Recent Activity: 13 Jun attack on Adriatic Port Authority (EU) reported by Resecurity; sustained presence over the reporting period
- Assessed Threat to Vertical: HIGH for maritime / logistics, MEDIUM elsewhere
- Analytic Confidence: MEDIUM
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B, Water Galura
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Manufacturing, energy, financial services, healthcare, professional services, retail
- Geographic Focus: Global; sustained EU and UK targeting through 2026
- Signature TTPs: Initial access via phishing and exposed VPN / RDP; abuse of valid accounts; rapid AD escalation; data exfiltration via Rclone to Mega / Backblaze prior to encryption
- Tooling / Malware Families: Qilin / Agenda ransomware (Rust and Go builders), Cobalt Strike, AnyDesk, Rclone, PsExec
- Recent Activity: 22 Jun leak-site posting of Central Bank of Libya; sustained volume leadership across the reporting period (Insikt / ransomware.live)
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
Akira
- Aliases: Akira, Storm-1567 (some Microsoft attribution overlaps)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Financial services, professional services, manufacturing, education, legal, retail
- Geographic Focus: Global; consistent UK / EU presence
- Signature TTPs: Initial access via Cisco ASA / FTD SSL VPN brute force and exposed admin panels; abuse of valid accounts; rapid network mapping; ChaCha20 ransomware encryption
- Tooling / Malware Families: Akira ransomware (Linux and Windows variants), AnyDesk, RustDesk, WinSCP, Mimikatz
- Recent Activity: 22 Jun NTD Apparel posted to leak site; continued mid-week activity against professional-services sub-verticals
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
Screening Serpens (Iran)
- Aliases: Screening Serpens, MuddyWater overlap, CharmingKitten overlap
- Suspected Origin: Islamic Republic of Iran
- Suspected Sponsor: Nation-state (assessed IRGC-aligned)
- Primary Motivation: Espionage, regional collection, retaliatory positioning
- Sector Targeting: Government contractors, defence, R&D, maritime, energy
- Geographic Focus: Middle East primary; expanding EU / UK
- Signature TTPs: Spear-phishing with credential harvest; deployment of custom RAT families; ongoing positioning against regional adversaries
- Tooling / Malware Families: Two new RAT variants documented by Unit 42 in 2026, MuddyWater-style scripting toolkits
- Recent Activity: Increased operations since February 2026 regional conflict; activity across up to five countries (Unit 42)
- Assessed Threat to Vertical: MEDIUM-HIGH for R&D and government contractor verticals
- Analytic Confidence: MEDIUM
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Anticipated mass-exploitation of Lantronix EDS5000 (CVE-2025-67038) at port-yard and vessel-bridge OT estates and Ubiquiti UniFi OS chain at port-office edge | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | Sustained phishing against vessel-management agents, freight-forwarder operations staff and customs-brokerage personnel with weaponised PDF and Office lures | HIGH |
| Initial Access | T1078 | Valid Accounts | Credential reuse against vessel-VSAT terminal logins and port-authority remote-access portals; observed in EmilyAI brute-force tail this period | MEDIUM |
| Persistence | T1543.002 | Systemd Service | Anticipated implant deployment as systemd unit on Lantronix and Linux-based vessel IT systems following EDS5000 exploitation | MEDIUM |
| Defense Evasion | T1070.004 | File Deletion | Anti-forensic clean-up observed in Anubis ransomware case-work; aligns with Adriatic Port Authority incident reporting | MEDIUM |
| Credential Access | T1110.003 | Password Spraying | Sustained password-spray against OWA / M365 tenants of monitored 3PL and freight-forwarder clients | HIGH |
| Lateral Movement | T1021.002 | SMB / Windows Admin Shares | Cross-segment movement between IT and OT-adjacent vessel networks where segmentation is poor | MEDIUM |
| Collection / Exfiltration | T1041 | Exfiltration Over C2 Channel | Anubis cluster exfiltration of safety plans and operational data prior to encryption per Adriatic Port Authority reporting | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Anubis ransomware encryption of port-authority IT estates; theoretical chained impact on connected OT systems if segmentation poor | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 23 Jun 2026 | Lantronix EDS5000 (vendor) | Unattributed | CVE-2025-67038 added to CISA KEV; serial-to-IP bridge with confirmed in-the-wild exploitation; vessel and port OT estates directly in scope | CISA KEV / Lantronix / SecurityWeek |
| 23 Jun 2026 | Ubiquiti UniFi OS Server (vendor) | Unattributed | Three CVEs added to KEV; port offices, freight-forwarder branches and shipping-line back-office sites with UniFi hardware in scope | CISA KEV / Bishop Fox PoC |
| 13 Jun 2026 (continuing) | Adriatic Port Authority (EU) | Anubis ransomware | Sustained reporting in this period; exfiltration of safety plans, staff records and operations comms; 10 million USD extortion demand | Resecurity / Military.africa |
| Through period | AIS spoofing / GNSS jamming Gulf and Black Sea | State-aligned (assessed) | Continued IMO and class-society reporting; not directly observable in client SIEM but operationally relevant to insurer and shipowner clients | IMO / class-society reporting |
| Through period | Screening Serpens (Iran) | Iran-nexus | Continued targeting per Unit 42; Gulf-exposed UK / EU maritime, energy and insurance firms inherit the threat | Palo Alto Unit 42 |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2025-67038 | Lantronix EDS5000 Device Server - HTTP RPC command injection (root) | 9.8 | Yes | Yes | Apply Lantronix firmware update; remove internet exposure; segregate serial-to-IP devices to OT zone |
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8 immediately per CISA BOD 26-04 (due 26 Jun 2026); audit management plane exposure |
| CVE-2026-34909 | Ubiquiti UniFi OS Server < 5.0.8 - path traversal | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; restrict management plane to dedicated VLAN; review for file-system access anomalies |
| CVE-2026-34910 | Ubiquiti UniFi OS Server < 5.0.8 - improper input validation (chains to root RCE) | 10.0 | Yes | Yes | Patch immediately - Bishop Fox PoC chains the three UniFi defects to unauthenticated root RCE |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command injection | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; apply vendor mitigation; monitor for CLI abuse |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager - directory traversal | 8.6 | Yes | Yes | Apply vendor mitigation; restrict management plane to jumpbox-only; monitor file-system access patterns |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply Citrix advisory; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately per NCSC; rotate gateway service accounts; force session reset for all interactive users |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 21 Jun 2026 | HIGH | F3 Netze AS205100 Tor exit (DE); IP Insights threat score 100 / critical; observed in EmilyAI-tagged perimeter brute-force tail this period |
| IP | 92[.]118[.]39[.]95 | 23 Jun 2026 | HIGH | UNMANAGED LTD (AS47890, GB-registered); IP Insights critical / suggest=block; appears in SSH and OWA brute-force tail |
| IP | 80[.]94[.]95[.]115 | 24 Jun 2026 | HIGH | SS-Net (RO) AS204428; IP Insights critical / suggest=block; sustained mass-scan against management plane endpoints |
| IP | 134[.]122[.]114[.]42 | 23 Jun 2026 | MEDIUM | DigitalOcean droplet IP; IP Insights critical / suggest=block; pattern-matches NetScaler probe traffic |
| IP | 198[.]235[.]24[.]31 | 20 Jun 2026 | MEDIUM | Google Cloud Platform US (AS396982); IP Insights critical / suggest=block; aggressive web-scan against client portals |
| IP | 162[.]142[.]125[.]34 | 25 Jun 2026 | LOW | Censys research scanner; benign but high-volume - exclude from alerting via known-scanner allow-list to reduce noise |
| IP | 64[.]227[.]107[.]117 | 24 Jun 2026 | MEDIUM | DigitalOcean droplet; IP Insights suggest=block; new this period - submitted to ipinsights.io reciprocal feed via EmilyAI |
| IP | 152[.]32[.]143[.]49 | 22 Jun 2026 | MEDIUM | UCloud HK (AS135377) hosting / datacenter, NG geolocation; observed in SaaS-tenant credential-stuffing tail |
| IP | 146[.]70[.]180[.]13 | 21 Jun 2026 | MEDIUM | M247 (RO) hosting; persistent credential-stuffing pattern against public-facing portals across multiple verticals |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Lantronix EDS5000 exploitation enabling cyber-physical disruption of vessel OT or port-yard equipment | H | H | CRITICAL |
| Anubis-style ransomware extortion of EU port authority | H | H | CRITICAL |
| Ubiquiti UniFi OS exploitation at port office / freight-forwarder branch as ransomware initial-access vector | H | M | HIGH |
| Iranian state-aligned credentialed intrusion against Gulf-exposed shipping or insurance firm | M | H | HIGH |
| AIS spoofing / GNSS jamming impacting marine-insurance underwriting decisions in conflict-adjacent waters | M | M | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat the Lantronix EDS5000 HTTP RPC interface and Ubiquiti UniFi OS management plane as the principal hunting hypotheses for this period. For vessel IT clients, hunt for new outbound connections from VSAT-attached IT subnets to non-traditional destinations and for password-spray patterns against M365 tenants serving shipboard crew accounts. Tune existing SOC rules to suppress benign Censys / Shodan scanner traffic (162.142.125.34) from alerting whilst retaining it in IP Insights enrichment.
Defend
Preventive priorities for the maritime vertical follow Section 6 directly. Segregate serial-to-IP bridges to a dedicated OT VLAN with restrictive ACLs and no outbound internet other than to vendor-update destinations. Apply Ubiquiti UniFi OS 5.0.8 to port-office and back-office estates by 26 June to meet CISA BOD 26-04. For vessel IT, enforce MFA on all VSAT terminal logins, separate crew-personal-use networks from vessel-operational networks, and ensure shipboard backup procedures meet IMO MSC.428(98) cyber-risk management code requirements. Audit Lantronix and OT-adjacent device inventories against MTS-ISAC sector guidance and confirm patch coverage to port-authority compliance functions where applicable.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the Maritime Transportation System ISAC (MTS-ISAC) and the Maritime ISAO with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) honeypot deployment fronting Lantronix EDS5000 device profiles to capture exploit attempt variants and report to CISA and the vendor; (iii) coordination with NCSC and CISP on the Anubis ransomware cluster's TTPs and IOCs; (iv) takedown coordination via NCSC ACD for maritime-themed phishing infrastructure flagged in client tenant inbox cohorts during the period; (v) submission of observed OT-targeted scanning to ipinsights.io for community blocklisting.
10. Forward outlook
Looking forward to the next reporting period (27 Jun - 03 Jul 2026), it is highly likely that exploitation of CVE-2025-67038 will become broadly documented, with at least one publicly attributed maritime or port-authority incident expected within the next two reporting cycles. Anubis ransomware activity is likely to continue at the current cadence with one further EU port-authority or major 3PL victim plausible by end of Q2. The 2026 trajectory of vessel-cyber incidents remains upward and shipowner and marine-insurer clients should expect continued growth in incident frequency.
Trigger conditions that would prompt revision of this outlook include: (a) public attribution of a Lantronix EDS5000 exploitation incident to a state-aligned actor, which would shift the Section 8 risk rating from CRITICAL to systemic and trigger out-of-cycle reporting; (b) a vessel-OT incident causing physical disruption (engine, steering, navigation), which would warrant immediate IMO and class-society engagement; (c) any expansion of Anubis ransomware activity beyond EU into UK port authorities, which would escalate the immediacy of MTS-ISAC indicator exchange. The principal intelligence gap remains direct visibility into vessel-IT telemetry for client shipowners not yet integrated with shore-side SIEM.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | CISA Alert: Three Ubiquiti UniFi OS Flaws Added to KEV (23 Jun 2026) | CISA | A1 |
| 4 | CISA Alert: CVE-2025-67038 Lantronix EDS5000 added to KEV (23 Jun 2026) | CISA | A1 |
| 5 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 6 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 7 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 8 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 9 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 10 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 11 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 12 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 13 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 14 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 15 | IP Insights (ipinsights.io) IP enrichment, blocklists and STIX 2.1 feed | UK Cyber Defence Ltd | A1 |
| 17 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 18 | MTS-ISAC sector advisories and indicator exchange (Week 26, 2026) | Maritime Transportation System ISAC | A1 |
| 19 | Resecurity / Military.africa report on Anubis Adriatic Port Authority attack (13 Jun 2026) | Resecurity | B2 |
| 20 | CYTUR 2026 Maritime Cyber Incident Report (Jun 2026) | CYTUR / Industrial Cyber | B2 |
| 21 | Palo Alto Unit 42 Screening Serpens tracking (Jun 2026) | Palo Alto Networks Unit 42 | B2 |
| 22 | IMO MSC.428(98) Maritime Cyber Risk Management resolution | International Maritime Organization | A1 |
| 23 | Lantronix EDS5000 vendor advisory (Jun 2026) | Lantronix, Inc. | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Maritime and logistics threat intelligence report — 4–8 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents…
Maritime and logistics threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the maritime and logistics threat picture remained dominated by ransomware and supply-chain compromise against vendor and TOS platforms.
Maritime and logistics threat intelligence report — 27 April – 3 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents…