Trade bodies and membership organisations threat intelligence report — 20–26 June 2026
The collection picture this period is dominated by sustained state-aligned interest in trade bodies and policy-influence organisations (Mustang Panda and APT28 both remain active against this vertical), the edge-appliance exposure introduced by the 23 June Ubiquiti UniFi OS KEV addition…
- Reference: TI-2026-0626-007 (public edition)
- Sector: Trade bodies and membership organisations
- Reporting period: 20–26 June 2026
- Issued: 26 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting Trade Bodies and Membership Organisations during the period 20 Jun 2026 - 26 Jun 2026. It is intended to support trade-body IT and membership-services functions, the senior information risk owner and the chief executive, and is graded TLP:CLEAR. The collection picture this period is dominated by sustained state-aligned interest in trade bodies and policy-influence organisations (Mustang Panda and APT28 both remain active against this vertical), the edge-appliance exposure introduced by the 23 June Ubiquiti UniFi OS KEV addition, and continued SaaS-tenant compromise activity from the ShinyHunters / Lynx cluster that is directly relevant to membership-data estates.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that PRC state-aligned actors (Mustang Panda and related clusters) will continue sustained targeting of UK and EU trade bodies, professional associations and policy-influence organisations through Q3 2026, consistent with multi-year tracking and 2026 vendor reporting (HIGH confidence).
- It is highly likely that the three Ubiquiti UniFi OS defects added to KEV on 23 June will be exploited against unpatched trade-body head-office and conference-venue UniFi deployments within the next 14 days (HIGH confidence).
- It is highly likely that ShinyHunters / Lynx-cluster SaaS-tenant compromise tradecraft will continue to affect membership-CRM (Salesforce, MemberClicks, iMIS, YourMembership, Microsoft Dynamics) estates through Q3 2026, given continued 2026 incident pattern (HIGH confidence).
- It is likely that BEC against trade-body finance and membership-renewal functions and impersonation of executive staff in member-engagement communications will continue at sustained volume (MEDIUM-HIGH confidence).
- It is a realistic possibility that Russian state-aligned actors (APT28 / Forest Blizzard) will increase targeting of UK trade bodies with policy positions on Russia, sanctions or Ukraine support within the next two reporting cycles (MEDIUM confidence).
2. Sector threat landscape
Trade bodies and membership organisations occupy a unique threat-model position: they aggregate member data and member-firm correspondence in a single estate, often with limited IT maturity relative to the largest member firms, and they hold policy-influence material that is of sustained interest to state-aligned actors. The collection picture this period is dominated by the 23 June Ubiquiti UniFi OS KEV addition, sustained Mustang Panda and APT28 activity, and continued SaaS-tenant compromise pressure on membership-CRM platforms.
Mustang Panda (PRC) remains the most consistent state-aligned threat to this vertical. Vendor reporting through 2026 continues to document weaponised LNK and ISO container lures, PlugX and ToneShell deployments, and long-dwell-time operations against NGOs, think-tanks, trade bodies and policy-influence organisations. UK trade bodies with international engagement, particularly with Asia-Pacific policy work, should treat the threat as current.
APT28 (GRU) targeting of trade bodies and policy organisations remains a credible threat where the body holds positions on Russia, sanctions or Ukraine. The current NCSC advisory on APT28 router exploitation applies equally to trade-body head-office and remote-worker connectivity, and the GRU's historical interest in democratic-institution and policy-influence targets is well documented.
Criminal SaaS-tenant compromise via the ShinyHunters / Lynx cluster is directly relevant. Membership-CRM platforms (Salesforce, MemberClicks, iMIS, YourMembership, Microsoft Dynamics) typically hold the entire member-firm contact graph, member-firm financial relationships and historical correspondence - precisely the bulk-export target the cluster's 2026 incidents (Crunchbase, Charter, Foxconn) demonstrate. The Klue breach (19 June, claimed by Icarus) is a recent reminder that mid-market SaaS-tenant compromise is a current threat.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Mustang Panda (PRC)
- Aliases: Mustang Panda, Bronze President, RedDelta, TA416, HoneyMyte
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation-state (MSS-aligned)
- Primary Motivation: Espionage, influence collection on diaspora and NGO targets
- Sector Targeting: Government, NGOs, think-tanks, trade bodies, defence contractors, R&D
- Geographic Focus: Global, with sustained EU and SEA operations
- Signature TTPs: Spear-phishing with weaponised LNK / ISO containers; PlugX deployment; long-dwell-time operations against policy-influence targets
- Tooling / Malware Families: PlugX, ToneShell, Korplug, ClaimLoader
- Recent Activity: Sustained 2026 operations against trade bodies and NGOs documented in vendor reporting
- Assessed Threat to Vertical: HIGH for trade bodies and R&D
- Analytic Confidence: HIGH
APT28 / Fancy Bear (GRU)
- Aliases: APT28, Fancy Bear, Sofacy, Strontium, Forest Blizzard, GRU Unit 26165
- Suspected Origin: Russian Federation
- Suspected Sponsor: Nation-state (GRU)
- Primary Motivation: Espionage, influence operations, strategic intelligence collection
- Sector Targeting: Government, defence contractors, R&D, NGOs, trade bodies, legal services with state-adjacent work
- Geographic Focus: NATO and partner states primary
- Signature TTPs: Router and edge-appliance exploitation for DNS hijack; spear-phishing of credentialed staff; AiTM token theft; ongoing exploitation of Outlook / Exchange
- Tooling / Malware Families: X-Agent, X-Tunnel, GooseEgg, Headlace, JaguarTooth
- Recent Activity: NCSC advisory on continued APT28 router exploitation and DNS hijack tradecraft remains current
- Assessed Threat to Vertical: HIGH for R&D, gov contractor, trade-body verticals
- Analytic Confidence: HIGH
ShinyHunters / Lynx cluster
- Aliases: ShinyHunters, Lynx, WorldLeaks overlap, ScatteredLapsus overlap
- Suspected Origin: English-speaking criminal cluster with intermittent Russian-speaking operator overlap
- Suspected Sponsor: Criminal
- Primary Motivation: Data theft, extortion, dark-market resale
- Sector Targeting: Retail, fintech, technology, BPO, professional services, trade bodies
- Geographic Focus: UK, US, EU, APAC
- Signature TTPs: Compromise of SaaS tenant via stolen credentials or vishing; bulk export of customer / member records; sale or leak via dark-market
- Tooling / Malware Families: Salesforce / Snowflake credential abuse, custom data-exfiltration scripts, Tor-fronted leak sites
- Recent Activity: Continued 2026 SaaS-tenant compromise activity following Charter / Foxconn / Crunchbase / Klue incidents
- Assessed Threat to Vertical: HIGH for SaaS-heavy verticals
- Analytic Confidence: MEDIUM-HIGH
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B, Water Galura
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Manufacturing, energy, financial services, healthcare, professional services, retail
- Geographic Focus: Global; sustained EU and UK targeting through 2026
- Signature TTPs: Initial access via phishing and exposed VPN / RDP; abuse of valid accounts; rapid AD escalation; data exfiltration via Rclone to Mega / Backblaze prior to encryption
- Tooling / Malware Families: Qilin / Agenda ransomware (Rust and Go builders), Cobalt Strike, AnyDesk, Rclone, PsExec
- Recent Activity: 22 Jun leak-site posting of Central Bank of Libya; sustained volume leadership across the reporting period (Insikt / ransomware.live)
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1566.001 | Spearphishing Attachment | Mustang Panda PlugX deployment via weaponised LNK / ISO containers; policy-themed lures to senior trade-body staff | HIGH |
| Initial Access | T1190 | Exploit Public-Facing Application | Anticipated mass-exploitation of Ubiquiti UniFi OS chain at trade-body head-office and conference-venue edge | HIGH |
| Initial Access | T1078 | Valid Accounts | ShinyHunters-style stolen-credential abuse against membership-CRM SaaS tenants; APT28 valid-account abuse post-router-compromise | HIGH |
| Initial Access | T1110.003 | Password Spraying | Sustained password-spray against M365 tenants and member-portal logins; observed in IP Insights enrichment | HIGH |
| Persistence | T1098.001 | Account Manipulation: Additional Cloud Credentials | Attacker-controlled federation in Entra ID / membership-CRM tenants of compromised trade bodies | MEDIUM |
| Defense Evasion | T1070.004 | File Deletion | Anti-forensic clean-up consistent with sustained state-aligned tradecraft | MEDIUM |
| Credential Access | T1539 | Steal Web Session Cookie | Okta / Entra session hijack via AiTM phishing kits against senior staff | HIGH |
| Collection | T1213 | Data from Information Repositories | Bulk export of membership records, member-firm correspondence and policy-position documents from SaaS tenants | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone to Mega / Backblaze / Wasabi during criminal intrusions; alternative low-and-slow exfiltration during state-aligned intrusions | HIGH |
| Impact | T1531 | Account Access Removal | Theoretical follow-on impact of disrupting member-services through account lockout; not observed against this vertical in current period | LOW |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 23 Jun 2026 | Ubiquiti UniFi OS Server (vendor) | Unattributed | Three CVEs added to CISA KEV; trade-body head-office, conference-venue and branch-office estates with UniFi hardware in scope | CISA KEV / Bishop Fox PoC |
| 19 Jun 2026 | Klue (competitive-intelligence SaaS, member-firm-adjacent) | Icarus extortion cluster | Breach claimed publicly; trade bodies and member firms using Klue inherit data-exposure risk via competitive-intelligence pipelines | Infosecurity Magazine |
| Continuing | Mustang Panda NGO and trade-body targeting | Mustang Panda (PRC) | Multi-year sustained activity against policy-influence targets; UK and EU trade bodies with Asia-Pacific engagement in scope | Microsoft / Mandiant |
| Continuing | APT28 router exploitation campaign | APT28 / GRU Unit 26165 | Current NCSC advisory remains valid; remote-worker CPE and SOHO routers under sustained DNS-hijack and credential-theft targeting; trade-body remote-worker exposure | NCSC |
| Continuing | 2026 SaaS-tenant compromise pattern (Charter, Foxconn, Crunchbase, Nike, Klue) | ShinyHunters / Lynx cluster | Continued documented pattern of SaaS-tenant compromise via stolen credentials and vishing; UK trade bodies using Salesforce / MemberClicks / iMIS / Dynamics inherit risk | Industry reporting |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8 immediately per CISA BOD 26-04 (due 26 Jun 2026); audit management plane exposure |
| CVE-2026-34909 | Ubiquiti UniFi OS Server < 5.0.8 - path traversal | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; restrict management plane to dedicated VLAN; review for file-system access anomalies |
| CVE-2026-34910 | Ubiquiti UniFi OS Server < 5.0.8 - improper input validation (chains to root RCE) | 10.0 | Yes | Yes | Patch immediately - Bishop Fox PoC chains the three UniFi defects to unauthenticated root RCE |
| CVE-2026-48907 | Joomla Widget Factory / JCE editor - improper access control | 8.6 | Yes | Yes | Patch JCE editor on customer-facing micro-sites; remove unused Joomla deployments |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read / write | 8.8 | Yes | Yes | Force Chrome / Edge update across workstation estate via Intune / SCCM; verify against KEV due-date |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command injection | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; apply vendor mitigation; monitor for CLI abuse |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply Citrix advisory; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately per NCSC; rotate gateway service accounts; force session reset for all interactive users |
| CVE-2026-54420 | LiteSpeed cPanel plugin - symlink following | 7.5 | Yes | Yes | Patch per LiteSpeed; confirm with hosting providers; relevant under outsourced-ICT regulatory regimes |
| CVE-2025-48595 | Android Framework - integer overflow leading to local privilege escalation | 7.8 | Yes | Yes | Push June 2026 Android security patch via MDM; require minimum patch level on BYOD enrolments |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 21 Jun 2026 | HIGH | F3 Netze AS205100 Tor exit (DE); IP Insights threat score 100 / critical; observed in EmilyAI-tagged perimeter brute-force tail this period |
| IP | 92[.]118[.]39[.]95 | 23 Jun 2026 | HIGH | UNMANAGED LTD (AS47890, GB-registered); IP Insights critical / suggest=block; appears in SSH and OWA brute-force tail |
| IP | 80[.]94[.]95[.]115 | 24 Jun 2026 | HIGH | SS-Net (RO) AS204428; IP Insights critical / suggest=block; sustained mass-scan against management plane endpoints |
| IP | 134[.]122[.]114[.]42 | 23 Jun 2026 | MEDIUM | DigitalOcean droplet IP; IP Insights critical / suggest=block; pattern-matches NetScaler probe traffic |
| IP | 198[.]235[.]24[.]31 | 20 Jun 2026 | MEDIUM | Google Cloud Platform US (AS396982); IP Insights critical / suggest=block; aggressive web-scan against client portals |
| IP | 162[.]142[.]125[.]34 | 25 Jun 2026 | LOW | Censys research scanner; benign but high-volume - exclude from alerting via known-scanner allow-list to reduce noise |
| IP | 64[.]227[.]107[.]117 | 24 Jun 2026 | MEDIUM | DigitalOcean droplet; IP Insights suggest=block; new this period - submitted to ipinsights.io reciprocal feed via EmilyAI |
| IP | 152[.]32[.]143[.]49 | 22 Jun 2026 | MEDIUM | UCloud HK (AS135377) hosting / datacenter, NG geolocation; observed in SaaS-tenant credential-stuffing tail |
| IP | 146[.]70[.]180[.]13 | 21 Jun 2026 | MEDIUM | M247 (RO) hosting; persistent credential-stuffing pattern against public-facing portals across multiple verticals |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Mustang Panda long-dwell-time intrusion against UK trade body with policy data exfiltration | M | H | HIGH |
| ShinyHunters / Lynx SaaS-tenant compromise with bulk membership-record exfiltration | H | H | CRITICAL |
| Ubiquiti UniFi OS chain exploitation at trade-body head-office as criminal ransomware initial-access vector | H | H | CRITICAL |
| APT28 router exploitation against remote-worker CPE leading to credential theft and tenant access | M | H | HIGH |
| BEC / impersonation of executive staff in member-renewal or member-fee correspondence | H | M | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat the Ubiquiti UniFi OS chain, the Mustang Panda LNK / ISO tradecraft, the ShinyHunters / Lynx SaaS-tenant compromise pattern, and the APT28 router-exploitation pattern as the principal hunting hypotheses for this period. Hunt for AiTM phishing session-cookie indicators against senior staff and for outbound DNS anomalies from remote-worker CPE consistent with APT28 hijack tradecraft.
Defend
Preventive priorities follow Section 6 directly. Ubiquiti UniFi OS 5.0.8 patch must be applied across the trade-body estate by 26 June to meet CISA BOD 26-04. Apply Joomla and JCE editor patches across any micro-site or member-facing portal estate. Force-update Chrome / Edge across the workstation estate. For identity hardening, enforce number-matching MFA on all M365 / Okta / membership-CRM tenants, block legacy authentication, and ensure executive-staff accounts use phishing-resistant authentication (FIDO2 / WebAuthn) given their value as Mustang Panda and APT28 targets. For SaaS-tenant hardening across Salesforce / MemberClicks / iMIS / Dynamics, enforce IP-restricted login for admin roles, audit OAuth-connected app grants, require step-up MFA on bulk-export and data-loader use, and audit federation trust relationships for unrecognised cloud directories. For state-aligned threat exposure, trade bodies with policy positions on Russia, China or Iran should adopt elevated identity hardening per NCSC's high-threat individual guidance for senior staff.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the NCSC CiSP trade-body / sectoral community, the Information Society Alliance and the relevant national-authority indicator exchange, with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) coordination with NCSC on the APT28 router-exploitation campaign and the Mustang Panda activity pattern; (iii) takedown coordination via NCSC ACD for trade-body-brand-themed phishing infrastructure; (iv) coordination with membership-CRM platform vendors on tenant-hardening posture; (v) submission of observed BEC sender infrastructure to ipinsights.io for community blocklisting.
10. Forward outlook
Looking forward to the next reporting period (27 Jun - 03 Jul 2026), it is likely that at least one UK or EU trade body will privately disclose (via CiSP trust-group channels) an incident traceable to one of the Ubiquiti UniFi OS chain, the Mustang Panda LNK / ISO tradecraft or the ShinyHunters / Lynx SaaS-tenant compromise pattern in Section 6. Sustained Mustang Panda and APT28 activity is highly likely to continue. SaaS-tenant compromise via ShinyHunters / Lynx remains an open and current threat.
Trigger conditions that would prompt revision of this outlook include: (a) NCSC, FBI or partner attribution of a fresh PRC or GRU campaign specifically targeting UK trade bodies, which would warrant immediate out-of-cycle reporting; (b) public disclosure of a ShinyHunters / Lynx SaaS-tenant compromise affecting a UK trade body, which would trigger an emergency advisory across all monitored membership-CRM tenants on the same platform; (c) emergence of evidence linking APT28 to a successful UK trade-body intrusion, which would warrant an immediate executive-staff identity-hardening engagement; (d) a sector-impacting BEC incident exceeding GBP 250,000 against a monitored trade-body finance function, which would trigger an immediate Action Fraud notification and a sector-wide finance-process advisory. The principal intelligence gap remains the limited transparency of trade-body peer-incident data outside CiSP trust-group disclosures.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | CISA Alert: Three Ubiquiti UniFi OS Flaws Added to KEV (23 Jun 2026) | CISA | A1 |
| 4 | CISA Alert: CVE-2025-67038 Lantronix EDS5000 added to KEV (23 Jun 2026) | CISA | A1 |
| 5 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 6 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 7 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 8 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 9 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 10 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 11 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 12 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 13 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 14 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 15 | IP Insights (ipinsights.io) IP enrichment, blocklists and STIX 2.1 feed | UK Cyber Defence Ltd | A1 |
| 17 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 18 | NCSC CiSP trade-body / sectoral community indicator and incident summaries (Week 26, 2026) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 19 | Microsoft Threat Intelligence Mustang Panda tracking (2026) | Microsoft Corporation | B2 |
| 20 | Mandiant / Google Threat Intelligence on PRC NGO and trade-body targeting (2026) | Google / Mandiant | B2 |
| 21 | Infosecurity Magazine: Klue breach (19 Jun 2026) | Infosecurity Magazine | C2 |
| 22 | Bishop Fox UniFi OS root RCE chain technical write-up (Jun 2026) | Bishop Fox | B1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Trade bodies and membership organisations threat intelligence report — 11–17 July 2026
The trade body and membership organisation vertical continues to be shaped by three structural characteristics that shape the threat picture: (i) the sector holds sensitive membership registers, financial information (dues, event bookings…
Trade bodies and membership organisations threat intelligence report — 27 April – 3 May 2026
The trade-body and membership-organisation threat picture for the reporting period is dominated by phishing and ransomware against organisations holding member-PII at scale, augmented by Russian state-aligned hacktivist activity targeting representative bodies for political signalling.
Trade bodies and membership organisations threat intelligence report — 4–8 May 2026
The trade-body and membership-organisation threat picture for the reporting period continues to be dominated by phishing and ransomware against organisations holding member-PII at scale, augmented by Russian state-aligned hacktivist activity targeting representative bodies for political signalling.