This week's Threat Report, a UK bank that serves thousands of charities, has been locked out of its own online banking for over a week after a fraud attempt and a flaw in outside software.
A set of very serious flaws in VMware's virtualisation software, which many NHS trusts and suppliers rely on to run their servers.
Elsewhere, hackers linked to the ShinyHunters group have stolen millions of records from a well-known security company through Salesforce.
Russian state hackers have been caught hijacking hotel Wi-Fi to plant spyware on business travellers' laptops, and Scotland's university procurement body has confirmed a break-in that may have exposed decades of historic data.
Read on to find out what happened, why it matters, and what you can do about it...
CAF Bank, which is owned by the Charities Aid Foundation and serves more than 14,000 UK charities and social enterprises, has had no online banking for over a week. The bank says it spotted people trying to commit fraud on some accounts and shut down online access to stop it.
While investigating, it found a previously unknown weakness in the way its systems connect to software made by another company. CAF Bank's chief executive has apologised, but says the service cannot be switched back on until the bank is sure it is safe to do so. Charities have told the BBC they are struggling to pay staff and suppliers because of the outage.
Many UK charities, including health and social care charities, rely on CAF Bank for their everyday banking. A week without online banking can mean staff going unpaid and vital services being delayed, even though no charity did anything wrong. This is also a reminder that a weakness in a third-party supplier's connection, not just your own systems, can shut down an organisation's ability to operate. Any NHS supplier or digital health company that relies on outside software to move money or data should ask how well that connection is protected.
Recommendations
Broadcom, which makes VMware, has released fixes for several serious flaws in its ESX, vCenter, Workstation, and Fusion products. Three of the flaws score 9.8 out of 10 for severity, nearly the highest score possible, and could let an attacker bypass logins, read files they should not be able to see, or run their own code on the system. VMware software is used by organisations of all sizes to run many virtual computers on one physical machine, which makes it a foundation for a lot of everyday IT.
Recommendations
Brinks Home, a well-known home and business security company, has confirmed that someone accessed part of its IT systems without permission. The hacking group ShinyHunters says it took around 4.9 million records from Brinks Home's Salesforce system, some of which contain people's personal information, and has threatened to leak the data unless it is paid. Brinks Home says its actual alarms and security products are not affected. ShinyHunters has carried out similar break-ins at many other companies this year, often by finding Salesforce accounts that were left open to the public by mistake.
Salesforce is used by all kinds of organisations, including many NHS suppliers and digital health companies, to manage customer and patient contact details. This case shows how a single mistake in the settings of a widely used cloud system can lead to millions of records being stolen, and how criminal groups are now actively hunting for these mistakes across many companies at once. Any organisation using Salesforce or similar cloud systems should check its own settings rather than assume the platform is secure by default.
Recommendations
Microsoft has reported that hackers linked to Russia's foreign intelligence service have been hijacking hotel Wi-Fi networks to trick guests into installing spyware. The hackers, tracked as Storm-2945 and believed to be part of the well-known group Midnight Blizzard, take control of the hotel's Wi-Fi login page and use it to send fake "update available" messages to a guest's laptop. Some versions trick the victim into copying and running a command in a terminal window themselves. Once installed, the spyware, called CornFlake, can turn on the webcam and microphone and record everything typed on the keyboard.
Staff who travel for conferences, supplier visits, or meetings, including those working in digital health and NHS-related roles, often connect to hotel Wi-Fi without a second thought. This attack shows that a hotel network can be turned into a tool for spying on a guest's device, capturing sensitive conversations, documents, and login details. Because the trick relies on a fake update message rather than a technical break-in, normal antivirus software may not catch it straight away.
Recommendations
Advanced Procurement for Universities and Colleges (APUC), which negotiates supplier contracts worth hundreds of millions of pounds on behalf of Scottish universities and colleges, has confirmed that criminals broke into its IT systems and accessed historic data. APUC says it contained the intrusion, which happened in mid-July, and is investigating with outside specialists. Sources told The Register that the attackers claim to have stolen data going back 20 years after getting hold of an employee's admin account, and are demanding a ransom, though APUC has not confirmed these details and had not appeared on any ransomware leak site at the time of writing.
APUC's Framework Agreements are used by universities and colleges across Scotland to buy goods and services, so a breach here could expose supplier and procurement records tied to many organisations at once, not just APUC itself. The claim that attackers got in through a single employee's admin account is a reminder that one compromised login can give criminals access to decades of sensitive commercial data. Any NHS supplier or digital health company that takes part in framework agreements or similar collective procurement schemes should consider whether their own data could be exposed if a partner organisation is breached.
Recommendations
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.