SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Trade bodies and membership organisations threat intelligence report — 23–29 May 2026

Trade bodies and membership organisations sit at the intersection of three distinct threat pressures: criminal cyber operators attracted by the relatively high-value, low-friction donor and member personal-data holdings…

  • Reference: TI-2026-0529-007 (public edition)
  • Sector: Trade bodies and membership organisations
  • Reporting period: 23–29 May 2026
  • Issued: 29 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Trade Bodies and Membership Organisations vertical during the period 23 May 2026 to 29 May 2026. Trade bodies and membership organisations sit at the intersection of three distinct threat pressures: criminal cyber operators attracted by the relatively high-value, low-friction donor and member personal-data holdings; nation-state actors interested in the policy-influence and intelligence-collection opportunities the sector represents; and hacktivist activity tied to the political positions of individual organisations. The week's collection picture is shaped by edge-appliance exploitation pressure, sustained phishing and OAuth consent-phish activity against member-facing M365 tenants, and continued ransomware leak-site cadence from Qilin, Akira, DragonForce and TheGentlemen. The Instructure / Canvas breach affecting approximately 9,000 institutions in May 2026 is the most recent education-and-membership-adjacent supply-chain anchor. Sources are graded against the Admiralty System.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that phishing-driven account compromise against member-facing M365 tenants will continue to drive the highest-frequency category of incident against the vertical over the next reporting cycle, with credential-theft via AiTM phishing the dominant vector. (HIGH confidence)
  2. It is highly likely that ransomware operators — Qilin, Akira, DragonForce and TheGentlemen — will continue to target mid-tier UK and EU trade bodies and membership organisations over the next reporting cycle, with member-database and donor-data exposure the operational consequence. (HIGH confidence)
  3. It is likely that nation-state intelligence interest in trade bodies engaged in policy advocacy on sanctions, defence, technology export or strategic-resource positioning will continue, with China-, Russia- and Iran-nexus collection the most active. (MEDIUM confidence)
  4. It is likely that Russian-aligned hacktivist DDoS or defacement activity will continue to target UK trade bodies and membership organisations taking visible positions on Ukraine, sanctions or geopolitical alignment. (MEDIUM confidence)
  5. There is a realistic possibility that the Instructure / Canvas May 2026 breach pattern will produce additional follow-on supply-chain disclosures across membership-platform SaaS over the next two reporting cycles. (MEDIUM confidence)

2. Sector threat landscape

Trade bodies, professional institutes and membership organisations occupy a distinctive position in the threat landscape: they hold concentrated personal data (member directories, qualification records, donor records, voting and conference data), they frequently operate under-resourced IT functions relative to the value of the data they hold, and they take public positions on policy issues that occasionally attract hacktivist and state-aligned attention. The result is a sustained criminal and nation-state interest in the vertical that is rarely visible in the dominant ransomware-leak-site reporting but is operationally consequential nonetheless.

The phishing and account-compromise category dominates by frequency. ICAEW's May 2026 UK survey confirms phishing remains the most prevalent UK cyber-attack category, with 38% of businesses and 25% of charities reporting phishing attacks in the prior twelve months — and trade bodies and membership organisations typically operate under one or both of those categorisations. The Cybernews Centre 1 May coverage reaffirmed that phishing 'owns the breach economy' in the UK SME-and-charity segment. AiTM phishing pages mimicking M365 sign-in, OAuth consent-phishing against member-services mailboxes, and session-token theft leading to bulk-mailbox Graph-API download are the dominant operational patterns.

Ransomware leak-site activity continues at sustained Q1 2026 cadence. Qilin, Akira, DragonForce and TheGentlemen have each posted new victims in the week of 24 May, including Global Retool Group on the Qilin leak-site (24 May, Business Services) and Sunrise Company cross-posted to Akira and Qilin (week of 26 May). Mid-tier trade bodies sit in the same risk envelope as professional-services firms and small-to-medium businesses generally — the operational profile of member-portal compromise leading to ransomware deployment via IAB front-end is well-established.

Supply-chain exposure across membership-platform SaaS continues to be a significant theme. The Instructure / Canvas breach affecting approximately 9,000 institutions across the US, Canada, Australia and the UK in early May 2026 is the most recent education-and-membership-adjacent supply-chain anchor; trade bodies running educational or qualification-platform exposure to Canvas should have completed an impact-assessment and member-notification by the reporting date. Other membership-platform SaaS, donor-management and conference-platform tools should be reviewed against the same supply-chain pattern over the next reporting cycle.

Edge-appliance exploitation pressure applies acutely to the vertical because mid-tier membership organisations frequently operate small but materially-exposed on-prem estates with limited patching cadence. Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973, Microsoft Exchange OWA CVE-2026-42897, Trend Micro Apex One CVE-2026-34926 and Citrix NetScaler CVE-2026-3055/4368 all carry critical or high-impact risk in this segment. Exchange OWA is particularly relevant because trade bodies have historically been slow to migrate fully to Exchange Online and frequently retain OWA exposure for member-services and board correspondence.

Nation-state intelligence collection against the vertical is harder to characterise precisely but persists. Trade bodies engaged in policy advocacy on sanctions, defence, technology export controls, strategic-resource positioning, or membership-aligned international campaigns frequently surface in vendor reporting as collection targets. The CISA / FBI / NSA May 2026 advisory on Russian state-sponsored campaigns against technology and logistics entities, ESET's 28 May APT activity report, and the persistent China-nexus reporting from Mandiant, Microsoft and CrowdStrike collectively place a sustained collection-effort baseline against the vertical that would be imprudent to discount.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Qilin (a.k.a. Agenda, Qilin.B)

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russia
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — extortion / data theft
  • Sector Targeting: Cross-sector with sustained Trade Bodies, Membership Organisations relevance.
  • Geographic Focus: Global; UK, EU, US, ANZ
  • Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
  • Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)

Akira

  • Aliases:
  • Suspected Origin: Russia-aligned criminal milieu
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — encryption + extortion
  • Sector Targeting: Cross-sector with sustained Trade Bodies, Membership Organisations relevance.
  • Geographic Focus: Global; SMB and mid-market heavy
  • Signature TTPs: Cisco VPN account abuse without MFA; rapid AD reconnaissance; ESXi targeting; brand-pressure leak-site
  • Tooling / Malware Families: Akira encryptor (Rust); RustDesk; AnyDesk; rclone; PCHunter; Mimikatz
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH

Russian-aligned hacktivist (NoName057(16) / Killnet successor clusters)

  • Aliases: NoName057(16), Killnet successors, Cyber Army of Russia
  • Suspected Origin: Russian-speaking volunteer milieu
  • Suspected Sponsor: Hacktivist — aligned with Russian strategic interest
  • Primary Motivation: Disruption; brand-damage; ideological
  • Sector Targeting: Cross-sector with sustained Trade Bodies, Membership Organisations relevance.
  • Geographic Focus: UK, EU, NATO members supporting Ukraine
  • Signature TTPs: Volumetric DDoS against public-facing services; defacement; leak claims of dubious provenance
  • Tooling / Malware Families: DDoSia and similar booter ecosystems; Telegram coordination
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH

TheGentlemen

  • Aliases:
  • Suspected Origin: Unattributed (likely Russian-speaking criminal milieu)
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — extortion
  • Sector Targeting: Cross-sector with sustained Trade Bodies, Membership Organisations relevance.
  • Geographic Focus: Cross-sector, global
  • Signature TTPs: Rapid affiliate onboarding; multi-platform encryptor (Windows/Linux/BSD/NAS); SystemBC C2
  • Tooling / Malware Families: Go-based encryptor; SystemBC; partner-supplied IAB access
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. MEDIUM-HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: MEDIUM-HIGH

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1566.002Spear-phishing LinkAiTM phishing pages mimicking M365 sign-in against member-services mailboxes; OAuth consent-phishing.HIGH
Initial AccessT1566.001Spear-phishing AttachmentDonor-, membership- and conference-themed phishing with weaponised PDF / DOCX attachments.HIGH
Initial AccessT1190Exploit Public-Facing ApplicationCisco SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973, Exchange OWA CVE-2026-42897, Apex One CVE-2026-34926, Citrix NetScaler CVE-2026-3055/4368 against unpatched internet-facing tiers.HIGH
Initial AccessT1199Trusted RelationshipMembership-platform SaaS supplier compromise (Canvas / member-management SaaS pattern).MEDIUM
Credential AccessT1539Steal Web Session CookieSession-token theft from AiTM phishing; reuse against M365 / SharePoint / OneDrive.HIGH
PersistenceT1098.002Account Manipulation: Additional Email Delegate PermissionsAttacker-controlled mailbox-delegate grants to maintain access in member-services mailbox.HIGH
CollectionT1114.002Email Collection: Remote Email CollectionBulk-download of member correspondence and donor data via Graph API.MEDIUM
ExfiltrationT1567.002Exfiltration to Cloud Storagerclone / MEGA / AzCopy egress of member and donor data prior to ransomware stage.HIGH
ImpactT1486Data Encrypted for ImpactQilin.B / Akira / DragonForce ESXi-aware encryption of small-to-mid-tier hypervisor estates.HIGH
ImpactT1498Network Denial of ServiceRussian-aligned hacktivist DDoS against UK trade-body and membership-organisation public-facing services taking visible positions on Ukraine or sanctions.MEDIUM

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
Early May 2026Instructure / Canvas — supply-chain breach affecting ~9,000 institutionsUnattributedApproximately 9,000 educational and membership institutions affected across US, Canada, Australia and UK; supply-chain anchor for the vertical.ANY.RUN / Hackmageddon
24 May 2026Global Retool Group (Business Services, trade-body-adjacent)QilinPosted to Qilin leak-site 24 May; data-extortion ongoing.Ransomware.live
Week of 26 May 2026Sunrise / Toscana / Andalusia Country Club (membership organisations, US)QilinMultiple membership-club victims posted to Qilin leak-site week of 26 May; operational case study.Ransomware.live
OngoingICAEW May 2026 UK phishing surveyMultiple criminal38% of UK businesses and 25% of charities reported phishing attacks in prior twelve months; sector baseline.ICAEW
28 May 2026ESET APT Activity ReportMultiple — Russian, Chinese, North Korean and Iranian APTsSustained policy- and influence-targeted intrusions where the underlying organisation has political or advocacy exposure.ESET / Help Net Security

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN Controller / Manager (auth bypass; UAT-8616 in-the-wild)10.0YesYesPatch immediately; rotate SSH keys; review NETCONF logs
CVE-2026-6973Ivanti EPMM (post-CVE-2026-1340 credential reuse chain)7.2YesYesPatch and rotate any admin credential issued before 1 Feb 2026
CVE-2026-34926Trend Micro Apex One (On-Premise) — directory traversal9.4YesYesPatch to build ≥17079; treat as EDR-control-plane exposure until verified
CVE-2026-42897Microsoft Exchange Server (Subscription Edition / 2019 / 2016) — XSS via crafted email8.1YesYesApply 14 May 2026 OOB update; disable OWA externally pending patch
CVE-2025-34291Langflow — origin validation error (added KEV 21 May 2026)9.1YesSuspectedPatch and restrict admin endpoints to trusted networks
CVE-2026-8398 / CVE-2026-45321 / CVE-2026-48027DAEMON Tools Lite / TanStack packages / Nx Console developer extension (supply-chain trio added KEV 27 May)8.0–8.8YesYesAudit developer endpoints; remove compromised package versions
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler ADC and Gateway (NCSC alert week of 24 May)9.0 / 7.5NoSuspectedApply Citrix advisory updates; review session tokens

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]101[.]5ongoingMTOR exit node — Network Attack + tor_exit categories, IP Insights suggestion: block
IP193[.]32[.]162[.]157ongoingMBrute-force / malware family — listed on 6 blacklists per IP Insights
Domainglobal-retool-leaks[.]onion24 May 2026MQilin leak-site post — Global Retool Group disclosure

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Phishing / OAuth-consent-phish against member-services mailbox → bulk member-data exposureHIGHHIGHCRITICAL
Ransomware deployment via IAB front-end against small-to-mid-tier hypervisor estateHIGHHIGHCRITICAL
Edge-appliance exploitation against on-prem estate (Cisco SD-WAN / EPMM / NetScaler / Exchange / Apex One)MEDIUMHIGHHIGH
Supply-chain compromise via membership-platform SaaS (Canvas pattern)MEDIUMHIGHHIGH
Russian-aligned hacktivist DDoS / defacement against politically-exposed trade bodyMEDIUMMEDIUMMEDIUM
Nation-state collection against policy-advocacy trade body engaged in sanctions / defence / technology-export workLOWHIGHMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection engineering should treat the Cisco Catalyst SD-WAN compromise pattern as the highest-priority hunting hypothesis for the next reporting cycle. Cross-walk EPMM admin logins against the documented CVE-2026-1340 / CVE-2026-6973 credential set, rotating any admin token issued before 1 February 2026 as untrusted. For Microsoft Exchange tenants still on-prem, instrument OWA crafted-email telemetry against CVE-2026-42897 — IIS access logs paired with mailbox event 41 should surface the exploitation primitive. Trend Micro Apex One administrators should monitor for directory-traversal probes against the ApexOne web-admin endpoint and treat any EDR-control-plane configuration change without a corresponding change-management record as a P1 trigger. For trade-body / membership tenants specifically, instrument M365 OAuth consent grants against the organisation-allow-listed enterprise application set; any consent grant outside the allow-list should generate a P2. Hunt for Graph-API bulk-mailbox or bulk-SharePoint download following session-token theft, and treat any cross-tenant sharing-grant of member-data folders to external tenants as a P1 trigger. Watch for spike patterns on public-facing interfaces correlating with public-policy announcements from the organisation.

Defend

Preventive priorities follow Section 6 directly: patch Cisco Catalyst SD-WAN Controller and Manager out of band as the single highest-value action of the reporting cycle, treat any pre-patch SD-WAN admin credential as untrusted, and rotate. EPMM tenants should rotate all admin credentials issued before 1 February 2026 and apply the CVE-2026-6973 patch. Trend Micro Apex One should be patched to build 17079 or later; until then, isolate the Apex web-admin interface behind a management VPN. Microsoft Exchange tenants should apply the OOB update for CVE-2026-42897, and restrict OWA external exposure to MFA-protected paths only. Hardening should follow ISO/IEC 27001 Annex A controls A.5.7 (threat intelligence), A.5.23 (information security for cloud services), A.8.8 (management of technical vulnerabilities), A.8.16 (monitoring activities) and A.8.23 (web filtering); under the NIST CSF mapping, the bulk of these controls land under Identify-AM, Protect-AC and Detect-CM. Helpdesk identity-verification scripts should be exercised against an explicit Scattered Spider / DragonForce voice-phishing scenario before the next quarter close. Trade-body / membership clients should map controls onto the Charity Commission cyber guidance (where applicable), the NCSC Small Charity Guide and Small Organisation Guide, Cyber Essentials Plus, and ICO data-protection guidance for membership data. Where the organisation accepts charitable donations or processes payment data, PCI-DSS v4.0 controls apply. Conditional-access policies should enforce phishing-resistant MFA across member-services and finance mailboxes.

Disrupt

Disruption activity within client lawful authority should focus on: (i) participation in the relevant ISAC indicator-exchange channel — FS-ISAC, H-ISAC, RH-ISAC, Aviation-ISAC, MTS-ISAC and the National Council of ISACs aggregator each provide indicator-sharing forums whose value compounds with active participation; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through the registrar-abuse channel and Cloudflare / Microsoft / Google trust-and-safety forms where attribution is sufficient; (iii) deception deployment in the helpdesk-identity-verification path — honey-identities seeded with watch-listed credential signatures will surface IAB front-end activity early; and (iv) tabletop exercise of the Scattered Spider / DragonForce playbook against the inbound helpdesk channel, scoped to a realistic voice-phishing-to-encryption window of 4 to 12 hours. The vertical lacks a dedicated ISAC, but NCSC's CiSP small-organisation trust groups, the Charity Sector Cyber Resilience Forum and the Association of British Insurers / Confederation of British Industry-aligned trust groups provide UK-anchored indicator sharing. International trade-body and association management peer-exchanges via the American Society of Association Executives (ASAE) Cyber Working Group provide complementary fora.

10. Forward outlook

Looking forward to the next reporting period (30 May – 5 June 2026), it is highly likely that phishing-driven account compromise will remain the highest-frequency category of incident against the vertical, and that Qilin, Akira, DragonForce and TheGentlemen will continue at the current leak-site cadence with mid-tier membership-organisation victims appearing each week. It is likely that one or more UK trade bodies with on-prem Exchange will be identified as exposed to CVE-2026-42897 through CiSP or ICO MROS reporting. There is a realistic possibility that the Instructure / Canvas supply-chain pattern will produce additional follow-on disclosures across membership-platform SaaS over the next two cycles.

*Trigger conditions that would prompt revision of this outlook include: (a) a UK trade body or membership organisation publicly disclosing a ransomware incident or data-breach, which would warrant an immediate client advisory; (b) any NCSC TLP:CLEAR advisory pointing to a sector-wide credential-stuffing or OAuth-consent-phishing campaign; (c) a fresh membership-platform SaaS supply-chain breach; or (d) a publicly-attributed hacktivist campaign against a UK trade body.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1CISA KEV Catalog updates — 15, 20, 21, 27 May 2026 — https://www.cisa.gov/known-exploited-vulnerabilities-catalogCISAA1
2Cisco Catalyst SD-WAN Auth Bypass (CVE-2026-20182) — joint advisory CISA / NSA / FBI / NCSC-UK / ACSC / CCCS / NCSC-NZCISA et al.A1
3Talos Intelligence — Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616)Cisco TalosB2
4Trend Micro Apex One CVE-2026-34926 — CISA KEV addition 21 May 2026CISA / Trend MicroA1
5Microsoft Exchange Server CVE-2026-42897 — active exploitation confirmed by MicrosoftMicrosoft / Help Net SecurityB1
6NCSC weekly threat reports and advisory feed (NCSC-UK)NCSCA1
7ESET APT Activity Report — Oct 2025 to Mar 2026ESETB2
8Check Point Research — The State of Ransomware Q1 2026Check Point ResearchB2
9Ransomware.live — leak-site tracker (Qilin / Akira / DragonForce / TheGentlemen postings, week ending 28 May 2026)Ransomware.liveC2
10IP Insights — IP reputation enrichment (https://www.ipinsights.io)UK Cyber Defence LtdB2
11FS-ISAC — sector resilience and AI-fraud advisories (subscription)FS-ISACA2
12NCSC alert — Citrix NetScaler ADC / Gateway CVE-2026-3055 and CVE-2026-4368NCSCA1
13ICAEW — Phishing most prevalent cyber attack confirms UK survey (May 2026)ICAEWB2
14Cybernews Centre — UK survey shows phishing still owns the breach economy (1 May 2026)Cybernews CentreC2
15ANY.RUN — Major Cyber Attacks in May 2026 (incident timeline)ANY.RUNC2
16Hackmageddon — 1-15 May 2026 Cyber Attacks TimelineHackmageddonC2
17NCSC — Small Charity Guide and Small Organisation GuideNCSCA1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.