This week's Threat Report:
Hackers found a way into VPN devices made by SonicWall before a fix even existed, breaking in as far as the root of the system.
Microsoft released its biggest-ever monthly security update, fixing two bugs that criminals were already using, Microsoft SharePoint.
A Fortinet security product is also under active attack.
Coca-Cola's Fairlife dairy business had to halt production at its US plants after a ransomware attack hit its systems.
Two young men were sent to prison for potentially the biggest cybercrime case Britain has ever seen.
Pharmacy regulators have also warned that fake online pharmacies are set to exploit demand for a newly launched weight-loss pill.
Read on for what happened, why it matters, and what you can do about it...
SonicWall makes devices called Secure Mobile Access (SMA) appliances. Companies use them to let staff log in securely from outside the office, a bit like a digital front door. Security researchers at Volexity found that a group of hackers, tracked under the name UTA0533, broke into these devices using two flaws that were not yet public. One of the flaws, CVE-2026-15409, is a server-side request forgery bug that scored a perfect 10 out of 10 for severity, the highest score possible, and let an attacker with no login at all reach hidden internal services on the device. Combined with a second flaw, CVE-2026-15410, the attackers were able to reach full "root" access, meaning total control of the device, as if they were its own administrator. Because this was happening before anyone had published a fix, it counts as a zero-day attack.
SMA devices sit right at the edge of a company's network, controlling who gets in from outside. NHS England issued its own alert about this on 15 July 2026 and rated it a high-severity risk, assessing further attacks as almost certain. If an NHS supplier or digital health company uses SonicWall SMA1000 devices for remote access and has not yet patched, an attacker could take over the device completely and use it as a doorway into the rest of the network. Because the attack was already happening before a patch existed, waiting for a routine update cycle is not safe here.
Recommendations
Microsoft's July 2026 round of updates fixed 622 separate flaws, the largest number ever released in a single month, beating the previous record set only a month earlier. Microsoft confirmed that two of these flaws were already being used by attackers: CVE-2026-56164, a SharePoint flaw that lets an attacker gain higher access than they should have without even logging in properly, and CVE-2026-56155, an Active Directory Federation Services flaw that lets someone already logged in gain far more access. On the same day, the US Cybersecurity and Infrastructure Security Agency (CISA) said SharePoint is now being attacked from several directions at once, with three flaws under active use and two further critical ones, scoring 9.1 and 9.8 out of 10, that could be exploited soon. Microsoft also confirmed that support for older SharePoint Server 2016 and 2019 ended on 14 July 2026, meaning those versions will not get further fixes at all.
SharePoint is used across many NHS trusts and suppliers to store documents, patient information and internal records, and it has now been under sustained attack for several weeks running, with new flaws appearing faster than some organisations can patch. Active Directory Federation Services controls how staff log in, so a break-in there can open the door to many other systems at once. With Microsoft's largest ever patch release landing all at once, it is easy for the most urgent fixes to get lost among hundreds of others, but the actively exploited bugs need to jump to the front of the queue, especially for anyone still running an unsupported SharePoint version.
Recommendations
FortiSandbox is a security product made by Fortinet that many organisations use to catch malware before it can do damage. Two flaws in it, both scoring 9.1 out of 10 for severity, let an attacker with no login details at all run their own commands on the device simply by sending it a specially crafted request over the web. Fortinet released fixes for these flaws back in April and June, but CISA has now added both to its official list of vulnerabilities being actively exploited, alongside a third, related FortiSandbox flaw. A security firm called Defused says it has already spotted attempts to use these flaws this week, although not every attempt so far has worked properly.
Security products like FortiSandbox exist to protect a network, which makes them a valuable target in their own right; breaking into the tool that is supposed to catch malware can let criminals slip past the very defences meant to stop them. Fortinet products are widely used by UK businesses and by the IT providers who support NHS suppliers and digital health companies. If a fix has been available since April or June and has not yet been applied, this is now an urgent gap to close rather than a routine update.
Recommendations
Two British members of the cybercrime group known as Scattered Spider have each been jailed for five and a half years over a 2024 attack on Transport for London. The pair, aged 18 and 20 at sentencing, bought partial login details for TfL staff on criminal forums, then rang the TfL helpdesk and tricked a staff member into resetting an employee's password. That gave them access to internal systems, including data belonging to around 7 million people, and left TfL with a clean-up bill of around £29 million. The National Crime Agency called it the largest cybercrime prosecution ever brought before UK courts. Evidence gathered during the investigation also linked the same pair to attacks on two American healthcare organisations, SSM Health Care Corporation and Sutter Health.
Scattered Spider's method rarely relies on clever hacking of software. It relies on tricking a real person, often a helpdesk worker, into doing something they should not. This case shows the group's tactics reach healthcare organisations directly, not just transport authorities, and any organisation with a helpdesk that can reset passwords or multi-factor authentication is a potential target. UK digital health organisations and NHS suppliers should treat helpdesk identity checks as seriously as any technical control, since a single phone call was enough to bring down a major transport authority for days and cost millions to fix.
Recommendations
Fairlife, the Coca-Cola-owned dairy business behind ultra-filtered milk and Core Power protein shakes, has had to halt production at its US plants after a ransomware attack. In a filing to the US Securities and Exchange Commission, Coca-Cola said Fairlife detected unauthorised third-party access to "a portion of its systems, including its production-related systems." The company activated its incident response and business continuity plans, brought in outside cybersecurity experts, and notified law enforcement. Canadian facilities are still running, and Coca-Cola says product quality and safety have not been affected. It is unclear whether the ransomware reached the operational technology that runs the manufacturing lines directly, or whether production was halted because supporting IT systems were taken offline as a precaution. No ransomware gang has yet claimed responsibility, and Coca-Cola has not said whether any data was stolen.
Why this matters
This is a reminder that ransomware doesn't need to touch patient records or clinical systems to cause serious disruption: hitting the IT systems that support manufacturing or production is often enough to stop physical output entirely, sometimes for weeks. For any digital health company or NHS supplier that manufactures devices, diagnostics, or physical products alongside software, the same pattern applies, an attack on back-office or production IT can halt supply just as effectively as one aimed directly at clinical data. It also illustrates good incident response practice worth learning from: Fairlife appears to have isolated systems quickly, engaged external experts, and kept safety-critical claims (product quality) separate from the ongoing investigation rather than over- or under-stating impact.
Recommendations
Wegovy (semaglutide) has become available in tablet form from pharmacies across Great Britain, and the General Pharmaceutical Council (GPhC) is warning that criminals are exploiting public demand for weight-loss medicines by running fake online pharmacy websites. GPhC Chief Executive Kathie Cashell said the tablet form will be easier to counterfeit than the existing injectable version, and the regulator expects the trade in fake medicines to increase. Counterfeit products sold this way often don't contain the ingredients they claim, may contain harmful substances, or aren't suitable for the person taking them. The GPhC has launched a public awareness campaign and is working with enforcement agencies and digital platforms to take down illegal sellers, following a roundtable held in the House of Commons on the issue.
This isn't a software vulnerability, but it follows the same pattern digital health organisations need to watch for: criminals standing up convincing fake websites to exploit trust in a legitimate product and a surge in public demand. Any pharmacy, healthtech, or telehealth provider whose branding, product names, or prescribing pathways could be spoofed is a potential target for the same tactic, whether through lookalike domains, phishing pages, or fake apps. It's also a reminder that patients may reach a legitimate service having already interacted with a fraudulent one, so staff should be alert to related confusion or complaints.
Recommendations
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.