Threat Report 185
This week's Threat Report:
Hackers found a way into VPN devices made by SonicWall before a fix even existed, breaking in as far as the root of the system.
Microsoft released its biggest-ever monthly security update, fixing two bugs that criminals were already using, Microsoft SharePoint.
A Fortinet security product is also under active attack.
Coca-Cola's Fairlife dairy business had to halt production at its US plants after a ransomware attack hit its systems.
Two young men were sent to prison for potentially the biggest cybercrime case Britain has ever seen.
Pharmacy regulators have also warned that fake online pharmacies are set to exploit demand for a newly launched weight-loss pill.
Read on for what happened, why it matters, and what you can do about it...
VPN Devices Broken Into Using Flaws Nobody Knew About Yet
SonicWall makes devices called Secure Mobile Access (SMA) appliances. Companies use them to let staff log in securely from outside the office, a bit like a digital front door. Security researchers at Volexity found that a group of hackers, tracked under the name UTA0533, broke into these devices using two flaws that were not yet public. One of the flaws, CVE-2026-15409, is a server-side request forgery bug that scored a perfect 10 out of 10 for severity, the highest score possible, and let an attacker with no login at all reach hidden internal services on the device. Combined with a second flaw, CVE-2026-15410, the attackers were able to reach full "root" access, meaning total control of the device, as if they were its own administrator. Because this was happening before anyone had published a fix, it counts as a zero-day attack.
SMA devices sit right at the edge of a company's network, controlling who gets in from outside. NHS England issued its own alert about this on 15 July 2026 and rated it a high-severity risk, assessing further attacks as almost certain. If an NHS supplier or digital health company uses SonicWall SMA1000 devices for remote access and has not yet patched, an attacker could take over the device completely and use it as a doorway into the rest of the network. Because the attack was already happening before a patch existed, waiting for a routine update cycle is not safe here.
Recommendations
- Check whether your organisation runs SonicWall SMA1000 series appliances (models 6210, 7210 or 8200v).
- Apply SonicWall's hotfix releases for CVE-2026-15409 and CVE-2026-15410 immediately.
- Check appliance logs for signs of compromise, including unusual login/logout requests and suspicious activity in the management console.
- Ask any IT provider or supplier who manages remote access on your behalf whether they use SonicWall SMA devices and whether they have patched.
- If any signs of compromise are found, re-image the appliance, change all passwords, and reset multi-factor authentication tokens.
- Log the patch status and date in your DSPT risk register.
Microsoft's Biggest Ever Monthly Update Fixes Bugs Already Being Used by Attackers
Microsoft's July 2026 round of updates fixed 622 separate flaws, the largest number ever released in a single month, beating the previous record set only a month earlier. Microsoft confirmed that two of these flaws were already being used by attackers: CVE-2026-56164, a SharePoint flaw that lets an attacker gain higher access than they should have without even logging in properly, and CVE-2026-56155, an Active Directory Federation Services flaw that lets someone already logged in gain far more access. On the same day, the US Cybersecurity and Infrastructure Security Agency (CISA) said SharePoint is now being attacked from several directions at once, with three flaws under active use and two further critical ones, scoring 9.1 and 9.8 out of 10, that could be exploited soon. Microsoft also confirmed that support for older SharePoint Server 2016 and 2019 ended on 14 July 2026, meaning those versions will not get further fixes at all.
SharePoint is used across many NHS trusts and suppliers to store documents, patient information and internal records, and it has now been under sustained attack for several weeks running, with new flaws appearing faster than some organisations can patch. Active Directory Federation Services controls how staff log in, so a break-in there can open the door to many other systems at once. With Microsoft's largest ever patch release landing all at once, it is easy for the most urgent fixes to get lost among hundreds of others, but the actively exploited bugs need to jump to the front of the queue, especially for anyone still running an unsupported SharePoint version.
Recommendations
- Apply Microsoft's July 2026 security updates as a priority, starting with CVE-2026-56164 and CVE-2026-56155.
- If you run on-premises SharePoint Server, also check for and apply fixes for the critical CVE-2026-55040 and CVE-2026-58644.
- Check whether you are still running SharePoint Server 2016 or 2019 and plan an upgrade, since these are no longer supported.
- Review Active Directory Federation Services logs for unusual sign-ins or privilege changes.
- Confirm that Antimalware Scan Interface (AMSI) protection is switched on for your SharePoint web applications.
- Record patch dates and versions applied in your DSPT risk register.
Attackers Target Critical Flaws in Widely Used Fortinet Security Product
FortiSandbox is a security product made by Fortinet that many organisations use to catch malware before it can do damage. Two flaws in it, both scoring 9.1 out of 10 for severity, let an attacker with no login details at all run their own commands on the device simply by sending it a specially crafted request over the web. Fortinet released fixes for these flaws back in April and June, but CISA has now added both to its official list of vulnerabilities being actively exploited, alongside a third, related FortiSandbox flaw. A security firm called Defused says it has already spotted attempts to use these flaws this week, although not every attempt so far has worked properly.
Security products like FortiSandbox exist to protect a network, which makes them a valuable target in their own right; breaking into the tool that is supposed to catch malware can let criminals slip past the very defences meant to stop them. Fortinet products are widely used by UK businesses and by the IT providers who support NHS suppliers and digital health companies. If a fix has been available since April or June and has not yet been applied, this is now an urgent gap to close rather than a routine update.
Recommendations
- Check whether your organisation, or any IT provider working on your behalf, runs FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS.
- Apply Fortinet's fixes for CVE-2026-39808, CVE-2026-25089 and CVE-2026-39813 immediately if this has not already been done.
- Review logs for unusual HTTP requests or unexpected command activity on affected devices.
- Ask managed service providers to confirm in writing that their FortiSandbox systems are patched.
- Treat any unpatched FortiSandbox device as an active risk rather than something to schedule for later.
Two Britons Jailed Over Record-Breaking Cyber-Attack on Transport for London
Two British members of the cybercrime group known as Scattered Spider have each been jailed for five and a half years over a 2024 attack on Transport for London. The pair, aged 18 and 20 at sentencing, bought partial login details for TfL staff on criminal forums, then rang the TfL helpdesk and tricked a staff member into resetting an employee's password. That gave them access to internal systems, including data belonging to around 7 million people, and left TfL with a clean-up bill of around £29 million. The National Crime Agency called it the largest cybercrime prosecution ever brought before UK courts. Evidence gathered during the investigation also linked the same pair to attacks on two American healthcare organisations, SSM Health Care Corporation and Sutter Health.
Scattered Spider's method rarely relies on clever hacking of software. It relies on tricking a real person, often a helpdesk worker, into doing something they should not. This case shows the group's tactics reach healthcare organisations directly, not just transport authorities, and any organisation with a helpdesk that can reset passwords or multi-factor authentication is a potential target. UK digital health organisations and NHS suppliers should treat helpdesk identity checks as seriously as any technical control, since a single phone call was enough to bring down a major transport authority for days and cost millions to fix.
Recommendations
- Review your helpdesk's process for verifying identity before resetting passwords or multi-factor authentication.
- Train helpdesk and support staff to recognise social engineering and impersonation attempts.
- Require a second, independent method of verification for any sensitive account changes, not just a phone call.
- Consider callback procedures, where the helpdesk calls the employee back on a number already on file, rather than trusting the caller.
- Test your organisation's resilience to helpdesk-focused social engineering through simulated exercises.
- Keep an incident response plan ready that covers identity-based attacks, not just malware.
Ransomware Halts Production at Coca-Cola's Fairlife Dairy Business
Fairlife, the Coca-Cola-owned dairy business behind ultra-filtered milk and Core Power protein shakes, has had to halt production at its US plants after a ransomware attack. In a filing to the US Securities and Exchange Commission, Coca-Cola said Fairlife detected unauthorised third-party access to "a portion of its systems, including its production-related systems." The company activated its incident response and business continuity plans, brought in outside cybersecurity experts, and notified law enforcement. Canadian facilities are still running, and Coca-Cola says product quality and safety have not been affected. It is unclear whether the ransomware reached the operational technology that runs the manufacturing lines directly, or whether production was halted because supporting IT systems were taken offline as a precaution. No ransomware gang has yet claimed responsibility, and Coca-Cola has not said whether any data was stolen.
Why this matters
This is a reminder that ransomware doesn't need to touch patient records or clinical systems to cause serious disruption: hitting the IT systems that support manufacturing or production is often enough to stop physical output entirely, sometimes for weeks. For any digital health company or NHS supplier that manufactures devices, diagnostics, or physical products alongside software, the same pattern applies, an attack on back-office or production IT can halt supply just as effectively as one aimed directly at clinical data. It also illustrates good incident response practice worth learning from: Fairlife appears to have isolated systems quickly, engaged external experts, and kept safety-critical claims (product quality) separate from the ongoing investigation rather than over- or under-stating impact.
Recommendations
- If your organisation runs manufacturing, production, or fulfilment systems, confirm these are segmented from corporate IT so a compromise in one doesn't force a shutdown of the other.
- Review whether operational technology (OT) environments have their own incident response and business continuity plans, separate from standard IT ones.
- Test your ability to keep production running, or fail over safely, if supporting IT systems have to be taken offline suddenly.
- Ensure any public or regulatory disclosure plan for a ransomware event is ready in advance, including who signs off statements about product safety or quality.
- Treat supply chain partners' manufacturing resilience as part of your own risk assessment, since a ransomware hit on a supplier's production line can disrupt your supply just as an attack on your own systems would.
Fake Online Pharmacies Set to Exploit New Weight-Loss Pill Launch
Wegovy (semaglutide) has become available in tablet form from pharmacies across Great Britain, and the General Pharmaceutical Council (GPhC) is warning that criminals are exploiting public demand for weight-loss medicines by running fake online pharmacy websites. GPhC Chief Executive Kathie Cashell said the tablet form will be easier to counterfeit than the existing injectable version, and the regulator expects the trade in fake medicines to increase. Counterfeit products sold this way often don't contain the ingredients they claim, may contain harmful substances, or aren't suitable for the person taking them. The GPhC has launched a public awareness campaign and is working with enforcement agencies and digital platforms to take down illegal sellers, following a roundtable held in the House of Commons on the issue.
This isn't a software vulnerability, but it follows the same pattern digital health organisations need to watch for: criminals standing up convincing fake websites to exploit trust in a legitimate product and a surge in public demand. Any pharmacy, healthtech, or telehealth provider whose branding, product names, or prescribing pathways could be spoofed is a potential target for the same tactic, whether through lookalike domains, phishing pages, or fake apps. It's also a reminder that patients may reach a legitimate service having already interacted with a fraudulent one, so staff should be alert to related confusion or complaints.
Recommendations
- If your organisation prescribes, dispenses, or promotes weight-loss medicines, monitor for lookalike domains or social media accounts impersonating your brand.
- Direct patients and customers to the GPhC's online register to verify any pharmacy they use, and consider linking to it from your own patient-facing materials.
- Brief customer-facing and clinical staff on the rise in fake online pharmacies so they can flag related patient concerns appropriately.
- Report any impersonation of your organisation's brand to the GPhC and relevant platforms promptly.
- Treat brand-impersonation monitoring as part of your wider digital risk programme, not a one-off check.
Want Help Staying Ahead of Threats Like These?
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.