In this week's report:
A brand new flaw in Microsoft SharePoint is already being attacked, just days after test code for breaking into it was published online.
A separate flaw in N-central, a tool IT support companies use to manage other people's computers, has let attackers take over servers even after an earlier fix failed to work properly.
A cancer diagnostics company has confirmed that hackers stole health information belonging to millions of patients after tricking staff over the phone, and the same extortion group has now published customer data taken from business communications platform RingCentral too.
And the UK's criminal records office has been formally reprimanded after failing to patch its website for years.
Read on to find out what happened, why it matters, and what you can do about it...
Microsoft has released fixes for two new flaws in SharePoint Server, tracked as CVE-2026-55040 and CVE-2026-63520. On their own, each flaw is serious, but chained together they let an attacker with no account at all take full control of a SharePoint server over the internet. Security researchers published a detailed technical write-up and working test code for the first flaw this month, and NHS England says attacks are now highly likely. The Hacker News reports that real attacks began within days of the test code appearing, making this the fifth SharePoint flaw to be attacked this year alone. To make things harder, support for the older SharePoint Server 2016 and 2019 has now ended, so those versions will not get this fix, or any future ones.
SharePoint is used across many NHS trusts and suppliers to store documents, policies, and patient-related records. NHS England has already warned that further attacks are likely, and this is now the fifth SharePoint flaw exploited this year, showing attackers are watching this software closely. Organisations that applied the fix for an earlier SharePoint alert (CC-4818, issued 22 July) are already protected against this new flaw too, so this is a good moment to check that earlier patch actually went in.
Recommendations:
N-central is a tool that IT support companies and managed service providers use to remotely monitor and control their customers' computers from one central place. N-able, the company behind it, found that an earlier fix for a login-bypass flaw did not fully work. Attackers have been using the gap, tracked as CVE-2026-18577, to log in as an administrator without a password and take full control of N-central servers. Once inside, attackers reportedly set up hidden tunnels to keep their access even if the server is restarted, and used the platform's own remote-control features to reach the computers it manages.
Tools like N-central are exactly the kind of software that IT providers and managed service companies use to support their clients, including smaller NHS suppliers and digital health firms who rely on an outside company to manage their IT. If a criminal takes over the management platform itself, they can potentially reach every computer that platform controls in one go, not just a single victim. Because the first fix for this problem did not work, any organisation that patched earlier still needs to check it is running the very latest version.
Recommendations:
Exact Sciences, a cancer diagnostics company owned by healthcare giant Abbott, has confirmed that hackers broke into some of its systems and stole a large amount of patient and staff data. The attackers, a group called ShinyHunters, got in by phoning staff and tricking them into handing over access, a technique known as vishing, or voice phishing. After Abbott reportedly refused to pay a ransom, the hackers published the stolen data online, including more than 10.9 million email addresses along with names, dates of birth, and other personal and health information. The group also claims to have taken confidential notes from doctor-patient conversations and millions of medical order records, though Abbott says it is still investigating exactly what was taken.
This case shows that even large, well-resourced healthcare companies can be beaten by a simple phone call rather than clever computer code. Anyone in digital health or an NHS-supplier role who handles patient data should treat this as a warning that staff, not just systems, need to be ready to spot and stop this kind of trick. Health information is especially sensitive because, unlike a password, it cannot be changed once it has been stolen, and can be used for years afterwards in scams or identity theft.
Recommendations:
ACRO, the UK's criminal records office, has been formally reprimanded by the Information Commissioner's Office after an investigation found major security failings. Attackers had quiet, ongoing access to ACRO's website and its content management system for more than seven months in 2022 and 2023, and had prepared sensitive data, including police certificates, passport details, and biometric data, ready to steal. ACRO had not applied years of patches and hotfixes to the software running its website, largely because nobody was clear on whether ACRO or its IT supplier was responsible for doing so. Antivirus software raised alerts about the problem, but the investigation found no one was checking them.
This is a clear lesson for any UK organisation, including NHS suppliers and digital health companies, that outsources IT support to another company. A gap in who is responsible for patching, or who checks security alerts, can leave known weaknesses unfixed for years without anyone noticing. ACRO avoided a fine partly because it is a public body, but a private company or NHS supplier in the same position could face a much larger penalty, and DSPT assessments look closely at exactly this kind of accountability.
Recommendations:
RingCentral, a cloud-based platform widely used for business phone, video, and messaging, has confirmed a data breach after the ShinyHunters extortion group targeted it in a "pay or leak" campaign in July 2026. The group has since published data it claims came from RingCentral, including 1.6 million unique email addresses along with names, physical addresses, and phone numbers. RingCentral says the incident affected "a limited portion" of its customers and that it is contacting those affected directly. The breach was added to the Have I Been Pwned database on 13 August 2026, meaning anyone can now check whether their own email address was included.
This is the same ShinyHunters group behind the Exact Sciences breach covered above, and together the two incidents show the group is running a wider campaign of extortion attempts against multiple companies rather than a one-off attack. RingCentral is used by many UK businesses, including NHS suppliers and digital health firms, for day-to-day calls and messaging, so organisations should check whether they are customers. Stolen names, phone numbers, and addresses are also useful to criminals running follow-up phishing or vishing scams, echoing the tactics used against Exact Sciences.
Recommendations:
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.