Government & Public Sector Threat Intelligence
Nation-state and criminal threats against central government, local councils, MoD supply chains, and the public sector organisations that underpin national services.
Flash Briefings
CVE-2026-46817 is a CVSS 9.8 unauthenticated remote code execution flaw in Oracle E-Business Suite's Payments File Transmission component. CISA added it to the Known Exploited Vulnerabilities catalogue on July 15 with a federal patch deadline of July 18 — 72 hours from disclosure to mandatory remediation.
Two SonicWall SMA1000 zero-days — an unauthenticated SSRF (CVE-2026-15409, CVSS 10.0) chained with post-auth code injection (CVE-2026-15410, CVSS 7.2) — are confirmed exploited in the wild. CISA added both plus two Microsoft zero-days to the KEV catalogue on July 14 with a July 17 federal patch deadline.
Three CVSS 10.0 Flaws Hit CISA KEV in 48 Hours: ColdFusion and Joomla Actively Exploited
Adobe ColdFusion and two Joomla-ecosystem components with CVSS 10.0 ratings were added to the CISA Known Exploited Vulnerabilities catalog between July 7 and 9, with a federal patch deadline of July 10. Langflow also added as the first AI agent platform in the catalog.
Armored Likho Deploys BusySnake Stealer Against Government and Power Sector
Russia-linked threat actor Armored Likho has launched a credential theft campaign targeting government agencies and electric power infrastructure across Russia, Kazakhstan, and Brazil. The Python-based BusySnake infostealer extracts browser credentials, Telegram sessions, and crypto wallet keys while operating in-memory to evade disk-based detection.
Group-IB tracked MuddyWater's Operation Olalampo campaign from January 2026, uncovering four previously undocumented malware families including CHAR — a Rust backdoor using Telegram for C2 with evidence of AI-assisted development. Targets span government, energy, and telecoms across the MENA region.
SharePoint Server RCE Under Active Ransomware Exploitation: CISA Sets July 4 Federal Deadline
CVE-2026-45659, a CVSS 8.8 deserialization remote code execution flaw in on-premises SharePoint Server, is being actively exploited by Storm-2603 ransomware operators. CISA added it to the Known Exploited Vulnerabilities catalogue on July 1 with a federal patch deadline of July 4.
FortiBleed: 73,932 FortiGate Credentials from CVE-2022-40684 Surface Four Years After Exploitation
A dataset of valid VPN credentials harvested from 73,932 FortiGate devices during CVE-2022-40684 exploitation was published on 17 June 2026. The four-year gap between collection and release illustrates a documented threat actor pattern — credential harvesting during a mass exploitation window, then monetising the dataset years later when many organisations have forgotten to rotate.
ShinyHunters (UNC6240) exploited a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft as a zero-day for two weeks before any patch existed, breaching more than 100 organisations — 68% of them universities. CISA added CVE-2026-35273 to its KEV catalog on 12 June 2026.
TA4922 Extends High-Tempo Campaign Operations to UK and Europe With Atlas RAT and Credential Stealer
Proofpoint has published intelligence on TA4922's geographic expansion into the UK, Germany, Italy, and South Africa — deploying two new malware families via tax-themed and HR-themed phishing. The group holds the highest campaign pace of any Proofpoint-tracked threat actor.
APT10 Renews MSP Targeting in UK and Europe -- Cloud Hopper Techniques Persist
China's APT10 has resumed systematic targeting of UK managed service providers and professional services firms, using the same supply chain pivot techniques that characterised the Cloud Hopper campaign -- now adapted for cloud-managed tenants.
APT28 Intensifies Targeting of European Government Networks Ahead of 2026 Election Cycle
Russia's GRU-linked APT28 has escalated spear-phishing and credential-harvesting operations against European government ministries, NATO-adjacent bodies, and political parties in the run-up to elections across the continent.
APT29 Exploiting Trusted Vendor Relationships to Reach UK and European Government Networks
Russia's SVR-linked APT29 is using compromised software vendor and IT service provider accounts to pivot into government targets -- a continuation of the SolarWinds playbook applied to UK and European supply chains.
LockBit Resurgence: Affiliate Network Active Across UK Healthcare and Professional Services
Despite Operation Cronos and the February 2024 infrastructure seizure, LockBit-affiliated actors continue to operate under the LockBit 3.0 and successor infrastructure. UK healthcare and professional services organisations have been among the most recent confirmed victims.
NCSC Warns: Volt Typhoon Reconnaissance Extends to Tier 2 UK Government Suppliers
Intelligence confirms Volt Typhoon pre-positioning activity has moved beyond primary CNI operators into the Tier 2 supplier networks that service UK central government and defence. Smaller suppliers with privileged access to government systems are now directly in scope.
Volt Typhoon Activity Confirmed Across UK Water and Energy OT Networks
NCSC and Five Eyes partners have confirmed Volt Typhoon intrusions at operational technology networks in UK water treatment and regional energy distribution. The group is not causing disruption -- it is waiting.
First Confirmed AI-Built Zero-Day: Google Thwarts Mass Exploitation Campaign
A threat actor used a large language model to write a working 2FA bypass exploit for a widely deployed open-source admin tool. Google's threat intelligence team detected the planned mass exploitation campaign before it launched. The code left distinctive LLM fingerprints.
Deep Analysis
TA427 / Kimsuky: North Korea's Intelligence-Gathering APT
TA427 (Kimsuky, Emerald Sleet) is North Korea's primary intelligence collection arm — an APT operation that has run sustained espionage campaigns against nuclear policy researchers, think tanks, and government officials for over a decade. This deep dive covers their TTPs, evolving malware toolkit, social engineering tradecraft, and what defenders should watch for.
Infoblox and The Hacker News disclosed in July 2026 that Lurking Lizard, a China-based financially motivated threat group, operates an industrial-scale residential proxy business sustained by trojaned installers for legitimate software. The network has processed hundreds of millions of proxy requests and is actively rented to criminal and espionage-linked operators.
Microsoft disclosed Storm-2755 in April 2026 — a financially motivated threat actor conducting adversary-in-the-middle phishing campaigns against Canadian employees to redirect payroll deposits to attacker-controlled bank accounts. The group operates without traditional malware, using stolen session tokens to bypass MFA and modify direct deposit settings in HR portals.
UAT-7810 and LapDogs: Inside China's Malware Factory for Covert Relay Infrastructure
Cisco Talos has published detailed research on UAT-7810's LapDogs campaign: a China-nexus operation building Operational Relay Box networks through compromised SOHO routers. New malware families LONGLEASH, DOGLEASH, and JARLEASH reveal how far this infrastructure-as-a-service model has matured.
Cadet Blizzard: GRU Unit 29155 and the Sabotage Doctrine
Cadet Blizzard — GRU Unit 29155's cyber arm — is the group behind WhisperGate, a wiper that preceded Russia's full-scale Ukraine invasion. Since the September 2024 DOJ indictment publicly named its officers, a clearer picture has emerged of a unit that combines destructive cyber operations with physical sabotage across NATO member states.
Anubis Ransomware: The RaaS Platform Weaponising Healthcare Regulators Against Its Own Victims
Anubis is a Go-based ransomware-as-a-service operation that emerged in late 2024 and has rapidly focused on healthcare organisations, deploying a novel pressure tactic: threatening to notify data protection regulators and HIPAA enforcement bodies unless victims pay. This deep dive covers Anubis's affiliate model, technical profile, targeting patterns, and the regulatory weaponisation that distinguishes its extortion approach.
Qilin emerged in 2022 as Agenda ransomware and has evolved through a complete Rust rewrite, a defining attack on NHS blood supply services in 2024, a novel Chrome browser credential theft technique, and a 2026 VPN exploitation campaign hitting four major vendors simultaneously. This deep dive covers the full operational and technical profile.
RomCom / Storm-0978: Russia's Hybrid Espionage-Criminal Threat Actor
RomCom — tracked by Microsoft as Storm-0978, by Unit 42 as Tropical Scorpius, by Mandiant as UNC2596 — is a Russian threat actor that operates across the line between state-sponsored espionage and organised cybercrime. The group exploited two chained zero-days to target NATO governments in 2023, runs Underground ransomware operations for revenue, and has maintained continuous campaigns against Ukrainian government and European defence targets through 2026.
APT42: Iran's Elite Social Engineering Unit Targeting Western Officials and Research
APT42 is Iran's most operationally sophisticated espionage actor — an IRGC-IO-sponsored group that has compromised US presidential campaigns, nuclear researchers, journalists, and Western diplomats through highly targeted social engineering rather than technical exploitation.
GopherWhisper: China-Aligned APT Using Cloud Messaging C2 Against Mongolian Government
GopherWhisper is a China-aligned threat actor discovered by ESET in January 2025 and publicly disclosed in April 2026. The group operates Go-based implants that use Slack, Discord, Microsoft 365 Outlook, and legitimate file-sharing services as command-and-control channels, almost entirely avoiding traditional C2 infrastructure. Their campaigns have persistently targeted the Mongolian government.
Secret Blizzard: Inside Russia's Most Patient Cyber Espionage Operation
A deep dive into Secret Blizzard (Turla), the FSB-linked APT that has sustained global intelligence collection for over two decades — hijacking criminal infrastructure, deploying ISP-level interception against foreign embassies, and evolving the Kazuar backdoor into a resilient P2P botnet.
APT28: Russia's GRU Hacking Unit and the Twenty-Year Campaign Against Western Democracy
APT28 — Fancy Bear, Forest Blizzard, GRU Unit 26165 — is Russia's Military Intelligence cyber arm and the most prolific nation-state attacker targeting Western governments, militaries, and democratic institutions. This deep dive covers their operational history, tradecraft, tooling, and current targeting priorities.
Cl0p: The Group That Turned File Transfer Vulnerabilities Into a Mass Exploitation Business
Cl0p is a financially motivated cybercriminal group that has systematically identified and mass-exploited zero-day vulnerabilities in enterprise file transfer software, compromising thousands of organisations globally. Their MOVEit campaign in 2023 was the largest data theft operation in the history of ransomware. This deep dive covers their operational model, technical approach, and what comes next.
LockBit: The Ransomware Operation That Survived Its Own Takedown
LockBit is the world's most prolific ransomware-as-a-service operation, responsible for more confirmed attacks than any other RaaS group. Despite Operation Cronos seizing its infrastructure and unmasking its administrator in 2024, the affiliate network remains active. This deep dive covers LockBit's operational model, technical capabilities, and what the post-Cronos resurgence means for defenders.
Midnight Blizzard: A Complete Profile of Russia's SVR Espionage Apparatus
APT29 — Cozy Bear, Midnight Blizzard — is Russia's SVR-aligned intelligence collection machine, responsible for SolarWinds, the 2024 Microsoft corporate email compromise, and ongoing targeting of European governments, diplomatic missions, and defence industrial base organisations. This deep dive covers their full operational history, tradecraft, tooling, and what defenders need to be doing now.
MuddyWater: Iran's MOIS Cyber Arm and the Blurred Line Between Espionage and Disruption
MuddyWater — Seedworm, Static Kitten, Earth Vetala — is Iran's Ministry of Intelligence and Security cyber unit conducting sustained espionage across the Middle East, Europe, and Asia, increasingly deploying ransomware as a false flag to complicate attribution and provide cover for intelligence collection.
Sandworm: Inside Russia's Most Destructive Cyber Weapon
Sandworm -- GRU Unit 74455 -- is responsible for the most destructive cyberattacks in history: the 2015 and 2016 Ukraine power grid attacks, NotPetya, Olympic Destroyer, and continuous destructive campaigns against Ukraine since 2022. This deep-dive covers their history, capabilities, and why they remain the most dangerous threat actor operating today.
AI in the Attack Chain: How Threat Actors Are Using Language Models Operationally
AI-assisted exploitation is no longer theoretical. From automated vulnerability research to AI-generated spear-phishing, the adoption of LLMs across the offensive lifecycle is accelerating. This analysis examines what is confirmed, what is emerging, and what it means for defenders.
Volt Typhoon: The Long Game in Western Critical Infrastructure
A deep analysis of Volt Typhoon's objectives, methods, and targets -- and what the sustained Chinese pre-positioning campaign in Western CNI means for how operators, regulators, and governments need to respond.
Salt Typhoon: How China Compromised the West's Wiretap Infrastructure
The Salt Typhoon campaign against US and European telecommunications carriers was not a data breach in any conventional sense. It was a strategic intelligence operation targeting the systems governments use to conduct lawful surveillance.
Commentary
Twenty-Two Seconds: What M-Trends 2026 Says About Attacker Speed and Defender Reality
Mandiant's M-Trends 2026 report, grounded in over 500,000 hours of incident investigations, contains several findings that should recalibrate how security teams think about detection windows, initial access economics, and the real mechanics of ransomware recovery denial. The headline statistic — 22 seconds from initial access to secondary threat group handoff — isn't the most important one.
A joint advisory from CISA, NCSC, and ten allied nations describes how China-linked threat actors have abandoned dedicated attack infrastructure in favour of networks of compromised home routers and IoT devices. The implication for defenders is worse than it sounds.
The Public Sector Cyber Gap: Why Government's Security Posture Trails the Threat
The structural factors that make the UK public sector a persistently soft target -- fragmented IT estates, procurement cycles that optimise for cost over security, and a talent market that can't compete with private sector pay -- are not going away. Here's what the gap looks like and what's actually being done about it.
Why Ransomware Groups Don't Die When You Arrest Their Leaders
The ransomware-as-a-service model has created a resilient criminal infrastructure that survives law enforcement actions, FBI seizures, and individual prosecutions. Understanding why is the first step to defending against it.
Nation-State Threats: What Business Leaders Get Wrong and Why It Matters
Most executives conflate nation-state cyber activity with the ransomware threat they're more familiar with. They are different in purpose, method, and the defences required. Getting this wrong shapes your entire risk posture.