This week, A brand new flaw in Microsoft SharePoint is already being attacked.
A bug in Check Point's security software is also under attack.
Cl0p ransomware gang has found a fresh way into manufacturing firms through design software called PTC Windchill.
A hospital security test that shows how a friendly chat and a fake badge were enough to walk straight into a records room.
A leak from the Pope's own prayer app exposed the details of more than 700,000 users.
Now-fixed flaw that could have let an attacker plant a rogue AI agent inside a company's ChatGPT account.
Read on to find out what happened, why it matters, and what you can do about it...
Microsoft SharePoint Server has another serious flaw, tracked as CVE-2026-50522, and it scores 9.8 out of 10 for severity, nearly the highest score possible. Security researchers have already found it being used, and working attack code is publicly available. Attackers have been seen stealing SharePoint's "machine keys" with a single request, which they can then use to run their own code on the server without ever logging in. To make matters worse, support for the older SharePoint Server 2016 and 2019 ended on 14 July 2026, so those versions will not get this fix, or any future ones, at all.
SharePoint is used across many NHS trusts and suppliers to store documents, policies, and patient-related records, and it has now had several serious flaws found in it over the past few weeks. NHS England says further attacks are likely. If your organisation already fixed the SharePoint flaw covered in NHS Alert CC-4816 on 20 July, the good news is that the same fix also covers this new flaw. If you haven't, this now needs to be treated as two urgent problems, not one.
Recommendations
Check Point makes security management software that many organisations use to control their firewalls and network defences. A flaw in it, CVE-2026-16232, scoring 9.1 out of 10 for severity, lets an attacker with no account at all grab a login token and sign in with full administrator rights, as long as the management server's address is reachable from the internet. Check Point has confirmed this is already being used against a small number of customers.
Check Point's products are used by businesses and IT providers around the world, including some who support UK digital health organisations and NHS suppliers. A management server controls the security settings for many other devices at once, so if an attacker gets in here, they can potentially switch off protections across a whole network in one go, not just on a single machine. Because this is the very tool meant to keep a network safe, a break-in here is especially damaging.
Recommendations
Attackers linked to the Cl0p ransomware group are breaking into PTC Windchill and FlexPLM, software that manufacturers use to manage product designs and engineering data. They chain together two flaws: one that leaks information from FlexPLM without needing a password, and a second, more serious one in Windchill, tracked as CVE-2026-12569 and scoring 9.3 out of 10, that lets them run their own code on the server. Once inside, they search through the file system, copy out design and engineering data, and then demand payment, threatening to leak the stolen files if it isn't paid. PTC has warned customers of a rise in this kind of attack.
PTC Windchill is used by manufacturers across engineering, automotive, aerospace, and other industrial sectors, some of whom supply parts, devices, or equipment to the NHS and other UK healthcare organisations. As with the Fairlife dairy ransomware attack covered last week, this shows that an attack doesn't need to touch clinical systems directly to cause serious disruption further down the supply chain. Because this is "double extortion," stolen design data can still be leaked even if a ransom is paid, so backups alone won't protect against it.
Recommendations
A professional security tester was hired to see if he could get into a hospital's locked records room and take a specific file. He made a fake security badge that didn't actually work, then struck up a friendly conversation with the nurse on duty, complaining about a difficult doctor who needed some records urgently. The nurse sympathised, let him straight in, and he walked out with the file. At another hospital he tested, he connected to the public guest Wi-Fi in the waiting room and found that important medical devices, including an MRI machine, were on the very same network, sending patient names, dates of birth, and other personal details across the network without any encryption at all.
This isn't a hack of computer code. It's a reminder that people, not just passwords and firewalls, guard sensitive health information, and a confident, friendly manner can beat a badge system that isn't backed up by proper identity checks. It also points to a common technical weakness: many hospitals run medical devices and public guest Wi-Fi on the same network, so anyone connected to that guest network could potentially see patient data moving between devices. For NHS organisations, digital health companies, and medical device makers working towards DSPT compliance, this shows that staff training on identity checks matters just as much as network segmentation for medical devices.
Recommendations
Click To Pray, an app used by the Pope's Worldwide Prayer Network with more than 719,000 registered accounts, has been leaking users' names, email addresses, countries, and dates of birth. A security researcher called BobDaHacker found that the app hands out anyone's account details if you simply guess their account number, because each account is numbered in order (1, 2, 3, and so on) and the app never checks whether you're allowed to see that particular account's data. This kind of flaw is called an IDOR, short for "insecure direct object reference," and it's one of the simplest and most common mistakes an app can make. The researcher says she reported it in January 2026 and never got a reply, and the flaw was still live when she published her findings this week. A second bug in the sign-up process could also let someone create and verify a fake account using someone else's email address.
The mistake behind it is a common one that any organisation building an app or API needs to guard against, including in health tech. IDOR flaws happen when a system checks that you're logged in, but not whether you're allowed to see the specific record you're asking for; the same mistake could just as easily expose patient records, appointment details, or referral letters if it crept into a healthcare app or portal. It's also a reminder that trusting users, especially older or less tech-savvy ones, can make a leak far more dangerous, since exposed names and email addresses become ready-made material for convincing phishing emails.
Recommendations
Security researchers at Zenity Labs found a flaw, which they named "AgentForger," in the tool ChatGPT uses to build AI assistants for businesses, called the agent builder. By sending someone a link that looked like an ordinary ChatGPT link, an attacker could get the victim's own ChatGPT account to quietly create and switch on a new AI agent, using whatever the victim was already connected to, such as Outlook, Teams, Slack, SharePoint, or Google Drive. Rather than stealing a password, the attacker effectively planted a fake but fully authorised "member of staff" inside the company's own systems, one that checked the victim's inbox for coded instructions and carried them out automatically, including searching files, gathering sensitive documents, and sending messages that looked like they came from the employee. The researchers reported the flaw to OpenAI in early June 2026, and it was fixed within days, before it was publicly disclosed or, as far as is known, used against real victims.
This particular flaw was fixed quickly and doesn't appear to have harmed anyone, but it's an early look at a new kind of risk as AI tools are given more access to company email, chat, and files. For NHS organisations, digital health companies, and any business connecting AI assistants to systems that hold patient or staff data, it's a reminder that an AI agent with an employee's permissions can do anything that employee could do, including reading sensitive records, and that security tools built to spot stolen passwords or unusual logins may not notice an AI agent quietly acting on an attacker's behalf.
Recommendations
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.