Threat Report 186
This week, A brand new flaw in Microsoft SharePoint is already being attacked.
A bug in Check Point's security software is also under attack.
Cl0p ransomware gang has found a fresh way into manufacturing firms through design software called PTC Windchill.
A hospital security test that shows how a friendly chat and a fake badge were enough to walk straight into a records room.
A leak from the Pope's own prayer app exposed the details of more than 700,000 users.
Now-fixed flaw that could have let an attacker plant a rogue AI agent inside a company's ChatGPT account.
Read on to find out what happened, why it matters, and what you can do about it...
New Microsoft SharePoint Flaw Already Being Attacked
Microsoft SharePoint Server has another serious flaw, tracked as CVE-2026-50522, and it scores 9.8 out of 10 for severity, nearly the highest score possible. Security researchers have already found it being used, and working attack code is publicly available. Attackers have been seen stealing SharePoint's "machine keys" with a single request, which they can then use to run their own code on the server without ever logging in. To make matters worse, support for the older SharePoint Server 2016 and 2019 ended on 14 July 2026, so those versions will not get this fix, or any future ones, at all.
SharePoint is used across many NHS trusts and suppliers to store documents, policies, and patient-related records, and it has now had several serious flaws found in it over the past few weeks. NHS England says further attacks are likely. If your organisation already fixed the SharePoint flaw covered in NHS Alert CC-4816 on 20 July, the good news is that the same fix also covers this new flaw. If you haven't, this now needs to be treated as two urgent problems, not one.
Recommendations
- Update on-premises SharePoint Server to the fixed builds: 2016 (16.0.5561.1001 or later), 2019 (16.0.10417.20175 or later), or Subscription Edition (16.0.19725.20434 or later).
- If you're still running SharePoint Server 2016 or 2019, plan an urgent upgrade, as these versions no longer receive any security fixes.
- Rotate credentials on any internet-facing SharePoint servers, since attackers have been stealing machine keys.
- Check whether you've already completed the fix for NHS Alert CC-4816 (CVE-2026-58644) from 20 July, as it also resolves this flaw.
- Report any signs of compromise to the NHS England Cyber Security Operations Centre on 0300 303 5222 or cybersecurity@nhs.net.
- Record the patch date and version applied in your DSPT risk register.
Attackers Break Into Check Point Security Servers Without Logging In
Check Point makes security management software that many organisations use to control their firewalls and network defences. A flaw in it, CVE-2026-16232, scoring 9.1 out of 10 for severity, lets an attacker with no account at all grab a login token and sign in with full administrator rights, as long as the management server's address is reachable from the internet. Check Point has confirmed this is already being used against a small number of customers.
Check Point's products are used by businesses and IT providers around the world, including some who support UK digital health organisations and NHS suppliers. A management server controls the security settings for many other devices at once, so if an attacker gets in here, they can potentially switch off protections across a whole network in one go, not just on a single machine. Because this is the very tool meant to keep a network safe, a break-in here is especially damaging.
Recommendations
- Check whether your organisation or IT provider runs Check Point Quantum Security Management Server or Multi-Domain Security Management (versions R81.10 and below, R81.20, R82, or R82.10).
- Apply the fix in Check Point advisory sk185169 as soon as possible.
- Make sure the management server's IP address is not exposed directly to the internet, and restrict which clients are trusted.
- Ask any managed service provider to confirm in writing whether they run affected Check Point products and have patched them.
- Review management server logs for unusual login attempts or unexpected changes to security policy.
- Plan an upgrade if you're still running R81.10 or earlier, as it is no longer supported.
Cl0p Ransomware Gang Breaks Into Design Software Used by Manufacturers
Attackers linked to the Cl0p ransomware group are breaking into PTC Windchill and FlexPLM, software that manufacturers use to manage product designs and engineering data. They chain together two flaws: one that leaks information from FlexPLM without needing a password, and a second, more serious one in Windchill, tracked as CVE-2026-12569 and scoring 9.3 out of 10, that lets them run their own code on the server. Once inside, they search through the file system, copy out design and engineering data, and then demand payment, threatening to leak the stolen files if it isn't paid. PTC has warned customers of a rise in this kind of attack.
PTC Windchill is used by manufacturers across engineering, automotive, aerospace, and other industrial sectors, some of whom supply parts, devices, or equipment to the NHS and other UK healthcare organisations. As with the Fairlife dairy ransomware attack covered last week, this shows that an attack doesn't need to touch clinical systems directly to cause serious disruption further down the supply chain. Because this is "double extortion," stolen design data can still be leaked even if a ransom is paid, so backups alone won't protect against it.
Recommendations
- Check whether your organisation, or any supplier, runs PTC Windchill or FlexPLM, especially if it's reachable from the internet.
- Apply PTC's security patches for CVE-2026-12569 and the related FlexPLM information-disclosure flaw without delay.
- Where possible, take Windchill and FlexPLM off the open internet and restrict access to a VPN or trusted network.
- Check for unexpected web shell files or unfamiliar scripts under Windchill login directories.
- Review file system logs for unusual bulk file access or copying.
- Include design-software and manufacturing suppliers in your third-party risk assessments, since a breach there can disrupt your own supply chain.
How a Friendly Chat and a Fake Badge Got a Tester Into a Hospital Records Room
A professional security tester was hired to see if he could get into a hospital's locked records room and take a specific file. He made a fake security badge that didn't actually work, then struck up a friendly conversation with the nurse on duty, complaining about a difficult doctor who needed some records urgently. The nurse sympathised, let him straight in, and he walked out with the file. At another hospital he tested, he connected to the public guest Wi-Fi in the waiting room and found that important medical devices, including an MRI machine, were on the very same network, sending patient names, dates of birth, and other personal details across the network without any encryption at all.
This isn't a hack of computer code. It's a reminder that people, not just passwords and firewalls, guard sensitive health information, and a confident, friendly manner can beat a badge system that isn't backed up by proper identity checks. It also points to a common technical weakness: many hospitals run medical devices and public guest Wi-Fi on the same network, so anyone connected to that guest network could potentially see patient data moving between devices. For NHS organisations, digital health companies, and medical device makers working towards DSPT compliance, this shows that staff training on identity checks matters just as much as network segmentation for medical devices.
Recommendations
- Review how staff verify identity before granting access to records rooms or other sensitive areas, rather than relying on a badge alone.
- Train reception, records, and clinical staff to politely question unfamiliar visitors, even if they seem to belong.
- Keep medical devices on their own separate network, away from guest Wi-Fi and general office systems.
- Check whether medical devices such as scanners and monitors encrypt patient data as it travels across the network; ask the manufacturer if you're not sure.
- Run physical and social engineering security tests alongside your usual technical penetration testing.
- Keep records of any such test as evidence for your NHS DSPT submission.
Pope's Prayer App Leaks Details of Over 700,000 Users
Click To Pray, an app used by the Pope's Worldwide Prayer Network with more than 719,000 registered accounts, has been leaking users' names, email addresses, countries, and dates of birth. A security researcher called BobDaHacker found that the app hands out anyone's account details if you simply guess their account number, because each account is numbered in order (1, 2, 3, and so on) and the app never checks whether you're allowed to see that particular account's data. This kind of flaw is called an IDOR, short for "insecure direct object reference," and it's one of the simplest and most common mistakes an app can make. The researcher says she reported it in January 2026 and never got a reply, and the flaw was still live when she published her findings this week. A second bug in the sign-up process could also let someone create and verify a fake account using someone else's email address.
The mistake behind it is a common one that any organisation building an app or API needs to guard against, including in health tech. IDOR flaws happen when a system checks that you're logged in, but not whether you're allowed to see the specific record you're asking for; the same mistake could just as easily expose patient records, appointment details, or referral letters if it crept into a healthcare app or portal. It's also a reminder that trusting users, especially older or less tech-savvy ones, can make a leak far more dangerous, since exposed names and email addresses become ready-made material for convincing phishing emails.
Recommendations
- If your organisation builds or commissions apps or APIs, check that every request for a record verifies the requester is actually allowed to see that specific record, not just that they're logged in.
- Avoid using simple sequential numbers as account or record identifiers where possible; use random, hard-to-guess identifiers instead.
- Add rate limiting to API endpoints so that even a working flaw can't be used to scrape an entire user base in one go.
- Make sure security researchers have a clear, monitored way to report vulnerabilities, and respond to them promptly.
- Treat any leaked names and email addresses as a phishing risk, and warn staff or users if their details may have been exposed.
- If you operate a patient-facing app or portal, review it for the same class of flaw as part of your regular security testing and DSPT preparation.
One Click on a Fake ChatGPT Link Could Have Planted a Rogue AI Agent Inside Your Company
Security researchers at Zenity Labs found a flaw, which they named "AgentForger," in the tool ChatGPT uses to build AI assistants for businesses, called the agent builder. By sending someone a link that looked like an ordinary ChatGPT link, an attacker could get the victim's own ChatGPT account to quietly create and switch on a new AI agent, using whatever the victim was already connected to, such as Outlook, Teams, Slack, SharePoint, or Google Drive. Rather than stealing a password, the attacker effectively planted a fake but fully authorised "member of staff" inside the company's own systems, one that checked the victim's inbox for coded instructions and carried them out automatically, including searching files, gathering sensitive documents, and sending messages that looked like they came from the employee. The researchers reported the flaw to OpenAI in early June 2026, and it was fixed within days, before it was publicly disclosed or, as far as is known, used against real victims.
This particular flaw was fixed quickly and doesn't appear to have harmed anyone, but it's an early look at a new kind of risk as AI tools are given more access to company email, chat, and files. For NHS organisations, digital health companies, and any business connecting AI assistants to systems that hold patient or staff data, it's a reminder that an AI agent with an employee's permissions can do anything that employee could do, including reading sensitive records, and that security tools built to spot stolen passwords or unusual logins may not notice an AI agent quietly acting on an attacker's behalf.
Recommendations
- If your organisation uses ChatGPT or similar AI agent tools connected to email, chat, or file storage, review what permissions and connected apps staff are allowed to set up.
- Require an approval step before any new AI agent can act automatically, rather than letting agents run unsupervised tasks by default.
- Review which AI tools are already connected to systems holding patient, staff, or customer data as part of your regular risk assessments.
- Treat unusual outgoing messages or file access from an AI-connected account with the same suspicion as unusual login activity.
- Keep an eye on vendor security bulletins for AI platforms your organisation uses, since this is a fast-moving area.
- Include AI agent permissions and connected accounts in staff security awareness training, alongside phishing and password advice.
Want Help Staying Ahead of Threats Like These?
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.