Periculo Blog

Threat Report 188

Written by Craig Pepper | Aug 17, 2026, 7:15:00 AM

In this week's report:

A brand new flaw in Microsoft SharePoint is already being attacked, just days after test code for breaking into it was published online.

A separate flaw in N-central, a tool IT support companies use to manage other people's computers, has let attackers take over servers even after an earlier fix failed to work properly.

A cancer diagnostics company has confirmed that hackers stole health information belonging to millions of patients after tricking staff over the phone, and the same extortion group has now published customer data taken from business communications platform RingCentral too.

And the UK's criminal records office has been formally reprimanded after failing to patch its website for years.

Read on to find out what happened, why it matters, and what you can do about it...

New SharePoint Flaw Already Under Attack, Days After Test Code Was Published

Microsoft has released fixes for two new flaws in SharePoint Server, tracked as CVE-2026-55040 and CVE-2026-63520. On their own, each flaw is serious, but chained together they let an attacker with no account at all take full control of a SharePoint server over the internet. Security researchers published a detailed technical write-up and working test code for the first flaw this month, and NHS England says attacks are now highly likely. The Hacker News reports that real attacks began within days of the test code appearing, making this the fifth SharePoint flaw to be attacked this year alone. To make things harder, support for the older SharePoint Server 2016 and 2019 has now ended, so those versions will not get this fix, or any future ones.

SharePoint is used across many NHS trusts and suppliers to store documents, policies, and patient-related records. NHS England has already warned that further attacks are likely, and this is now the fifth SharePoint flaw exploited this year, showing attackers are watching this software closely. Organisations that applied the fix for an earlier SharePoint alert (CC-4818, issued 22 July) are already protected against this new flaw too, so this is a good moment to check that earlier patch actually went in.

Recommendations:

  • Check whether you already applied the fix for NHS Cyber Alert CC-4818 (CVE-2026-50522) from 22 July; if so, you are also protected against this new flaw.
  • If not, apply Microsoft's security updates for CVE-2026-55040 and CVE-2026-63520 immediately.
  • Move off SharePoint Server 2016 or 2019 as a priority, since these versions no longer receive any security fixes at all.
  • Ask any IT provider who manages SharePoint on your behalf to confirm in writing that they have patched.
  • Report any signs of compromise to the NHS England Cyber Security Operations Centre on 0300 303 5222 or cybersecurity@nhs.net.
  • Record the patch date and version applied in your DSPT risk register.

Attackers Take Over N-central Servers After the First Fix Didn't Work

N-central is a tool that IT support companies and managed service providers use to remotely monitor and control their customers' computers from one central place. N-able, the company behind it, found that an earlier fix for a login-bypass flaw did not fully work. Attackers have been using the gap, tracked as CVE-2026-18577, to log in as an administrator without a password and take full control of N-central servers. Once inside, attackers reportedly set up hidden tunnels to keep their access even if the server is restarted, and used the platform's own remote-control features to reach the computers it manages.

Tools like N-central are exactly the kind of software that IT providers and managed service companies use to support their clients, including smaller NHS suppliers and digital health firms who rely on an outside company to manage their IT. If a criminal takes over the management platform itself, they can potentially reach every computer that platform controls in one go, not just a single victim. Because the first fix for this problem did not work, any organisation that patched earlier still needs to check it is running the very latest version.

Recommendations:

  • Check with your IT provider whether they use N-able N-central, and ask them to confirm they are running version 2026.3.1.7 or later, not just an earlier patched version.
  • Do not assume an earlier patch is enough; N-able's first fix for this issue was incomplete.
  • Ask your IT provider to check for unexpected new services or scheduled tasks on their N-central server, particularly unfamiliar tunnel or remote-access tools.
  • Review which outside companies have remote access to your systems, and confirm they have a plan for responding quickly if their own tools are compromised.
  • Treat any unusual activity from your IT provider's remote-support tools as suspicious and report it immediately.

Exact Science Cancer Diagnostics Patient Data Stolen After Staff Were Tricked Over the Phone

Exact Sciences, a cancer diagnostics company owned by healthcare giant Abbott, has confirmed that hackers broke into some of its systems and stole a large amount of patient and staff data. The attackers, a group called ShinyHunters, got in by phoning staff and tricking them into handing over access, a technique known as vishing, or voice phishing. After Abbott reportedly refused to pay a ransom, the hackers published the stolen data online, including more than 10.9 million email addresses along with names, dates of birth, and other personal and health information. The group also claims to have taken confidential notes from doctor-patient conversations and millions of medical order records, though Abbott says it is still investigating exactly what was taken.

This case shows that even large, well-resourced healthcare companies can be beaten by a simple phone call rather than clever computer code. Anyone in digital health or an NHS-supplier role who handles patient data should treat this as a warning that staff, not just systems, need to be ready to spot and stop this kind of trick. Health information is especially sensitive because, unlike a password, it cannot be changed once it has been stolen, and can be used for years afterwards in scams or identity theft.

Recommendations:

  • Train staff who handle sensitive data to verify the identity of anyone requesting access by phone, using a separate, trusted contact method before granting anything.
  • Set up a clear process for staff to challenge or escalate unusual access requests, even if the caller seems confident or claims urgency.
  • Review which staff can grant system access over the phone, and limit this to as few people as possible.
  • Check what patient or health data your organisation or suppliers hold, and make sure it is only kept for as long as it is needed.
  • Have an incident response plan ready that covers extortion demands, including who makes the decision on ransom payments and who needs to be told.

UK Criminal Records Office Reprimanded for Years of Missed Patches

ACRO, the UK's criminal records office, has been formally reprimanded by the Information Commissioner's Office after an investigation found major security failings. Attackers had quiet, ongoing access to ACRO's website and its content management system for more than seven months in 2022 and 2023, and had prepared sensitive data, including police certificates, passport details, and biometric data, ready to steal. ACRO had not applied years of patches and hotfixes to the software running its website, largely because nobody was clear on whether ACRO or its IT supplier was responsible for doing so. Antivirus software raised alerts about the problem, but the investigation found no one was checking them.

This is a clear lesson for any UK organisation, including NHS suppliers and digital health companies, that outsources IT support to another company. A gap in who is responsible for patching, or who checks security alerts, can leave known weaknesses unfixed for years without anyone noticing. ACRO avoided a fine partly because it is a public body, but a private company or NHS supplier in the same position could face a much larger penalty, and DSPT assessments look closely at exactly this kind of accountability.

Recommendations:

  • Put in writing, with your IT provider or supplier, exactly who is responsible for identifying and applying security patches.
  • Make sure someone is clearly responsible for reviewing security and antivirus alerts, and that this is checked regularly, not left to chance.
  • Keep an up-to-date record of which software versions you are running and when they were last patched.
  • Review contracts with managed service providers to confirm patching and monitoring responsibilities are clearly stated.
  • Use this case as a prompt to check your patching policy exists, is documented, and is actually being followed, ahead of your next DSPT submission.

Same Extortion Group Publishes RingCentral Customer Data

RingCentral, a cloud-based platform widely used for business phone, video, and messaging, has confirmed a data breach after the ShinyHunters extortion group targeted it in a "pay or leak" campaign in July 2026. The group has since published data it claims came from RingCentral, including 1.6 million unique email addresses along with names, physical addresses, and phone numbers. RingCentral says the incident affected "a limited portion" of its customers and that it is contacting those affected directly. The breach was added to the Have I Been Pwned database on 13 August 2026, meaning anyone can now check whether their own email address was included.

This is the same ShinyHunters group behind the Exact Sciences breach covered above, and together the two incidents show the group is running a wider campaign of extortion attempts against multiple companies rather than a one-off attack. RingCentral is used by many UK businesses, including NHS suppliers and digital health firms, for day-to-day calls and messaging, so organisations should check whether they are customers. Stolen names, phone numbers, and addresses are also useful to criminals running follow-up phishing or vishing scams, echoing the tactics used against Exact Sciences.

Recommendations:

  • Check whether your organisation is a RingCentral customer, and look out for a direct breach notification from RingCentral.
  • Use Have I Been Pwned (https://haveibeenpwned.com) to check whether your work email address was included in this or other breaches.
  • Be alert to follow-up phishing or vishing attempts that use your real name, phone number, or address to appear more convincing.
  • Remind staff that no legitimate company will ask for a password or one-time passcode over the phone, especially in the wake of a breach like this.
  • Review the RingCentral security bulletin for full details and any account actions it recommends.

Want Help Staying Ahead of Threats Like These?

Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.