MITRE ATT&CK SME Edition ● Live

MITRE-Lite Threat Dashboard

The full MITRE ATT&CK framework covers thousands of attack techniques used by nation-states and sophisticated criminal groups. This dashboard cuts it down to the techniques that are actually being used against UK SMEs and financial services firms — right now — in plain English.

█ Last updated: 28 September 2026  ·  September 2026 Edition

NCSC feed: current CISA KEV: current Actor profiles: monthly review

Updated monthly. Next update: 26 October 2026.

Active Threat Actors Targeting UK Financial Services

7
Active Threat Actor Groups
Confirmed targeting UK fin. services SMEs
14
Techniques in Active Use
From SME-relevant ATT&CK subset
0
New Techniques This Month
No new category — intensified Exploit Public-Facing Application (T1190) activity plus two new Chromium browser zero-days
17
CISA KEV Entries
SME-relevant this month — Citrix NetScaler (×2), WordPress Core, SharePoint, F5 BIG-IP APM, Cisco (×3), Chromium V8 (×2) among them
What is MITRE ATT&CK? It's a publicly-maintained library of every known attack technique used by criminal groups and state-sponsored hackers — think of it as a documented playbook of everything attackers try. This dashboard filters it down to the techniques that realistically threaten businesses like yours: small financial services firms, insurance brokers, and professional services companies in the UK.
Actor / Group Origin Primary Method Active Techniques (ATT&CK IDs) SME Risk
Scattered Spider
aka UNC3944, Octo Tempest
CYBERCRIME SIM-swapping and social engineering to bypass MFA; targets IT helpdesks to gain access. T1078 T1566.001 T1621 HIGH
ALPHV / BlackCat
Ransomware-as-a-Service group
CYBERCRIME Ransomware deployment following stolen credentials and VPN exploitation. Known to target professional services firms. T1486 T1190 T1657 HIGH
APT29 / Cozy Bear
SVR, Russian Foreign Intelligence
RUSSIA / STATE Spearphishing and supply chain compromise. Primarily targets government and finance. Sophisticated, long-dwell operations. T1566.002 T1195 T1071.001 MEDIUM
APT40 / BRONZE MOHAWK
Chinese MSS-linked group
CHINA / STATE Exploitation of internet-facing services and VPNs. Actively targeting financial data and intellectual property. T1190 T1133 T1041 MEDIUM
MuddyWater
STATIC KITTEN, Iranian MOIS
IRAN / STATE Phishing and exploitation of web frameworks (Laravel, Zimbra). Targeting professional services and finance for espionage. NCSC and allies confirmed Iranian state spyware campaigns this month. T1566.001 T1190 T1059 MEDIUM
LockBit 3.0 Affiliates
Ransomware-as-a-Service network
CYBERCRIME Access brokers sell network entry to affiliates who then deploy LockBit ransomware. SMEs frequently targeted as easier entry points. T1486 T1078 T1083 HIGH
TA4903 (BEC Specialists)
Business Email Compromise group
CYBERCRIME Impersonation of senior staff, solicitors, and payment processors to redirect bank transfers. Primary threat vector for insurance brokers. T1566.002 T1534 T1078 HIGH

How Much of This Does GET-IT Cover?

9
Techniques Covered
GET-IT stack addresses these directly
64%
Coverage Rate
Of the 14 active techniques this month — unchanged
5
Uncovered Techniques
Honest gap — not covered by current stack
Partial
Exfiltration Coverage
Monitoring detects data movement; cannot always block it
We show you the gaps honestly. No security provider covers everything. The 5 uncovered techniques below include areas where mitigations depend on human behaviour (staff training) or third-party dependencies (your cloud provider, your line-of-business software vendor). We flag them so you know what to ask about — and so you can factor them into cyber insurance conversations.

Coverage by Tactic

Initial Access
75% 3 of 4 techs
Execution
80% 4 of 5 techs
Persistence
67% 2 of 3 techs
Lateral Movement
50% 1 of 2 techs
Exfiltration
33% 1 of 3 techs
Impact
100% 3 of 3 techs
Exfiltration gap — what this means for your insurance: If an attacker reaches your data and moves it slowly out via legitimate cloud services (Microsoft OneDrive, SharePoint, or email), detection requires behavioural monitoring that goes beyond standard endpoint protection. Many cyber insurance policies include data exfiltration in their coverage — but only where you can demonstrate attempted prevention. Speak to us if this concerns you.

Techniques in Use Against UK SMEs This Month

T1566.001 · T1566.002
Phishing — Email & Link-based
Attackers send fake emails pretending to be HMRC, your bank, a solicitor, or a trusted supplier. The email contains a malicious attachment or a link to a fake login page designed to steal your password.
T1190
Exploit Public-Facing Application
Attackers search for unpatched software on your internet-facing systems — VPNs, firewalls, web apps, remote-access appliances — and exploit known security holes to get in. This is the entry point for many ransomware campaigns. This month: two Citrix NetScaler flaws (CVE-2026-88771, CVE-2026-88772), a WordPress Core remote file inclusion bug (CVE-2026-87902), a SharePoint code injection flaw (CVE-2026-65660), and an F5 BIG-IP APM overflow (CVE-2026-94127) all confirmed actively exploited.
T1078
Valid Accounts (Stolen Credentials)
An attacker who has obtained a username and password (from a previous breach, phishing, or the dark web) simply logs in using legitimate credentials. No hacking required — they look like a real user.
T1059
Command-Line Scripting (PowerShell / cmd)
Once inside, attackers use built-in Windows tools (PowerShell, command prompt) to run malicious commands without installing suspicious software. This makes them harder to detect because they're using your own tools against you.
T1621
MFA Fatigue Attack
An attacker who has your password sends dozens of multi-factor authentication (MFA) push notifications to your phone, hoping you'll accidentally approve one — or approve it just to make the alerts stop. This bypasses MFA entirely.
T1598.003
Messaging App Targeting (Spearphishing via Service)
Attackers harvest WhatsApp, Signal, and LinkedIn accounts of senior staff to build social engineering profiles — then impersonate trusted contacts to extract credentials or authorise fraudulent payments.
T1133
External Remote Services (VPN Abuse)
Attackers exploit or abuse your VPN, remote desktop (RDP), or remote access tools to maintain persistent access — often long after the initial breach is discovered. They effectively install a back door.
T1534
Internal Spearphishing
Having compromised one email account, attackers use it to send convincing phishing emails to other staff internally. A message appearing to come from your MD or finance director asking to approve an urgent payment.
T1041 · T1567
Data Exfiltration via Cloud Services
Attackers copy your files out through legitimate cloud services — SharePoint, OneDrive, Dropbox, Google Drive — because this traffic looks normal to most security tools. Data is gone before anyone notices.
T1486
Data Encryption for Ransom
The final step in most ransomware attacks — all your files are encrypted and you're locked out of your own systems. A ransom demand follows. UK SMEs paid an average of £47,000 per incident in 2025, with recovery taking 3–4 weeks.
T1657
Financial Theft (Business Email Compromise)
An attacker with access to a business email account monitors payment conversations and intercepts at the right moment — substituting their own bank account details. The #1 financial loss vector for UK insurance brokers and professional services firms.

Current Risk Status for UK Financial Services SMEs

△
█ THREAT LEVEL: ELEVATED

Elevated Maintained — Edge Devices and Remote-Access Appliances Under Coordinated Pressure, WordPress and SharePoint Both Add Fresh Exploits, Two Browser Zero-Days Confirmed

RAG status remains Elevated/Amber for the September edition. Seventeen SME-relevant vulnerabilities were added to CISA KEV this month — the highest monthly total MITRE-Lite has tracked since moving to a monthly cadence — with a clear pattern across internet-facing and remote-access infrastructure. Citrix NetScaler ADC/Gateway picked up two separate confirmed-exploited flaws in the same week (CVE-2026-88771, an unauthenticated command-execution bug, and CVE-2026-88772, a buffer overflow), while Cisco added three: an authentication bypass in Identity Services Engine (CVE-2026-76460), a root-level SQL injection in Secure Email Gateway (CVE-2026-76461), and an authentication bypass with root access in Firewall Management Center (CVE-2026-20079). F5 BIG-IP APM (CVE-2026-94127) and Fortinet's FortiOS/FortiSwitchManager/FortiSASE stack (CVE-2025-25249) round out the remote-access picture. NCSC's 27 August advisory on the risk from internet-exposed systems and edge devices reads, in hindsight, as a direct preview of this month's KEV additions. Away from the network perimeter, WordPress Core picked up an unauthenticated remote file inclusion vulnerability (CVE-2026-87902) — relevant to a large proportion of UK SME websites — and Microsoft SharePoint added a fifth confirmed-exploited vulnerability of 2026 (CVE-2026-65660, code injection), extending the pattern flagged in previous editions. Google Chromium's V8 engine had two separate zero-days confirmed exploited this month (CVE-2026-87491, CVE-2026-85046), both allowing remote code execution inside the browser sandbox via a crafted web page — relevant to every business regardless of platform, since Chrome, Edge and Opera all share the affected engine. NCSC also published three further pieces on AI-related risk this month (adversary simulation scheme documents, defending against agentic threats, and the risks of unsanctioned "shadow AI" use) and, jointly with allied agencies, confirmed Iranian state-linked spyware campaigns targeting UK-based activists and journalists.

► Highest Severity Active Technique — September 2026 Edition

Exploit Public-Facing Application (T1190) — Citrix, Cisco and F5 Remote-Access Appliances Confirmed Exploited Alongside WordPress and SharePoint

Seven confirmed-exploited vulnerabilities this month share the same underlying technique: an attacker exploiting a flaw in software your business exposes to the internet, without needing valid credentials first. Citrix NetScaler ADC and Gateway — used by many UK SMEs for VPN and remote access — picked up two separate confirmed-exploited flaws in the same week (CVE-2026-88771, added 27 September 2026, which allows an unauthenticated attacker to execute arbitrary commands, and CVE-2026-88772, a buffer overflow enabling code execution or denial of service). Cisco contributed three: an authentication bypass in Identity Services Engine allowing unauthorised access to the management interface (CVE-2026-76460), a SQL injection in Secure Email Gateway that gives an unauthenticated attacker root access (CVE-2026-76461), and an authentication bypass in Firewall Management Center that also yields root access (CVE-2026-20079). F5 BIG-IP APM (CVE-2026-94127, unauthenticated remote code execution via a heap overflow) and Fortinet's FortiOS/FortiSwitchManager/FortiSASE line (CVE-2025-25249, unauthorised code execution via crafted packets) extend the same pattern across the remote-access and VPN layer. NCSC's 27 August advisory on the risk from internet-exposed systems and edge devices now reads as an accurate preview of this month's KEV additions. Outside the network perimeter, WordPress Core — the platform behind a very large share of UK SME websites — added an unauthenticated remote file inclusion vulnerability that can lead to full remote code execution (CVE-2026-87902, added 25 September 2026), and Microsoft SharePoint picked up its fifth confirmed-exploited vulnerability of 2026 (CVE-2026-65660, code injection via an authorised network attacker), continuing the most persistent single-platform pattern in this year's SME-relevant CISA KEV data. Separately, Google Chromium's V8 engine had two zero-days confirmed exploited within the same month (CVE-2026-87491 and CVE-2026-85046), both allowing sandbox escape via a crafted web page — relevant to Chrome, Edge and Opera users alike, which in practice means almost every employee's browser.

🔒
█ Ransomware Activity Indicator

ACTIVE — LockBit 3.0 Affiliates and ALPHV/BlackCat Successors Operational

Both ransomware-as-a-service ecosystems remain active with affiliate networks continuing to acquire access from initial access brokers. UK professional services firms make up approximately 18% of confirmed UK ransomware victims in Q1 2026 (NCSC data). Offline backups, patching cadence, and tested recovery plans are the three most effective mitigations at this level.

Live Source Summary

■ NCSC UK Alerts
8
Eight NCSC advisories this month. Headline: "Disruptive cyber activity highlights risk from internet-exposed systems and edge devices" — a direct preview of this month's Citrix, Cisco and F5 KEV wave. NCSC also published on agentic AI defence, shadow AI risk, and — jointly with allies — confirmed Iranian state spyware targeting UK activists and journalists.
Latest: 21 September 2026  →  NCSC: Defending Agentically →
■ CISA KEV Entries (SME-Relevant)
17
Citrix NetScaler ADC/Gateway (×2); Cisco ISE, Secure Email Gateway and Firewall Management Center (×3); F5 BIG-IP APM; Fortinet FortiOS/FortiSwitchManager/FortiSASE; WordPress Core RFI; SharePoint code injection — fifth SharePoint KEV entry in 2026; Chromium V8 (×2). Awareness: Adobe Commerce/Magento (×2), Windows (×2), Google Pixel.
Latest: 27 September 2026  →  View CISA KEV →
■ Top Sector Affected This Month
Financial Crime & Fraud
A UK man has pleaded guilty to fraud and forgery after fabricating a fake takeover approach for a listed company — a reminder that impersonation fraud extends well beyond email. Separately, the FCA reports firms are shutting down record numbers of suspected money mule accounts but says more is needed. For brokers and advisers: fraud awareness is a live client conversation this quarter, not a compliance afterthought.
FCA update: September 2026  →  FCA →
Full Advisory Detail
For full advisory detail, vulnerability write-ups, and CISA KEV entries see the Threat Advisory page →
Has Your Email Been Breached?
Check whether your business email appears in known breach databases — Free check →

Does Your Security Stack Cover These Techniques?

64% coverage of active techniques is a starting point. If you'd like to understand exactly where your gaps are — and what it would cost to close them — book a resilience scan.

Book a Resilience Scan →

Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, FCA ScamSmart, and the MITRE ATT&CK framework (licensed under CC BY 4.0). Technique descriptions are plain-English interpretations for SME audiences and are not verbatim reproductions of MITRE documentation. Coverage assessments reflect the GET-IT stack as configured for a typical SME client — actual coverage depends on your specific environment. This dashboard is updated monthly; data may not reflect events in the days immediately prior to the last refresh date. GET-IT Solutions Ltd is not responsible for inaccuracies in third-party source data.