Menu

Monthly Cyber Threats Report - June 2026

Issue 18: June 2026

Monthly Cyber Threats Report - June 2026

Editor's note

Francisco Sanches
Francisco Sanches

June 2026 has been a demanding month for cyber security teams. Across the five articles in this edition, our analysts begin with Anthropic's first year of AI threat intelligence - which reveal that malicious actors are systematically using AI to raise the technical ceiling of their attacks - before turning to a zero-day vulnerability actively exploited in Android devices, a critical authentication bypass in widely deployed Check Point VPN gateways, the continued - and escalating - threat posed by the Silent Ransom Group to law firms and professional services organisations, and a high-priority remote code execution vulnerability in Windows Netlogon.

A consistent theme runs through all five articles: the attack surface continues to expand across every layer of the stack - now encompassing the AI tooling organisations are only beginning to deploy, as well as the mobile operating system, the network perimeter, human trust, and enterprise identity infrastructure. Organisations that rely on reactive or manual patch processes, or that have not yet updated their threat models to account for AI-enabled adversaries, are disproportionately exposed.

News
a person typing on a laptop
Anthropic's first year of AI Threat Intelligence rewrites the attacker risk model

Anthropic has published a threat intelligence report, analysing 832 accounts banned for malicious cyber activity between March 2025 and March 2026 and mapping their behaviour against known attacker tactics, techniques, and procedures. In short, malicious actors are using AI in ways that make them more dangerous and cyberattacks are becoming more autonomous.

News
Person looking at screen of code
Android framework under fire from latest zero-day (CVE-2025-48595)

Google has confirmed active exploitation of CVE-2025-48595, a zero-day integer overflow vulnerability (CWE-190) in the Android Framework - the core system layer that mediates between applications and the operating system. The flaw allows a local attacker to escalate privileges on affected devices without requiring user interaction and carries a CVSS score of 8.4 (High). Android versions 14, 15, 16, and 16-QPR2 are all affected.

News
a laptop with green lights
Silent Ransom, social engineering and cyber extortion

The FBI published an alert on 26 May advising that the Silent Ransom Group (SRG) - also tracked as UNC3753, Luna Moth, and Chatty Spider - is actively targeting law firms using social engineering and impersonation techniques. Mandiant reports that the group targeted multiple organisations across the legal, financial, and professional services sectors between January and May 2026.

Subscribe

Never miss a publication by signing up to our mailing list

Monthly Cyber Threats Report - June 2026 Issues

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else