Threat Feed

Threat Report 191

Written by Craig Pepper | Sep 7, 2026, 9:00:00 AM

This week:

Hackers are breaking into SonicWall VPN boxes using two chained zero-day flaws, and NHS England says further attacks are almost certain.

Google has rushed out a Chrome update after criminals found a way to run harmful code just by getting someone to visit a booby-trapped webpage.

VMware has fixed two flaws in its Workstation and Fusion software that could let someone escape a virtual machine and take control of the real computer underneath.

Dropbox has warned thousands of users after attackers slipped in through an old sign-in link with Lenovo.

How a single sacked employee, whose access was never switched off, ended up costing one company hundreds of thousands of dollars.

Read on to find out more and what you can do about it...

Hackers Break Into SonicWall VPN Boxes Using Two Chained Zero-Days

SonicWall has confirmed that criminals are actively breaking into its SMA1000 Series devices, which many mid-size and large organisations use to let staff connect securely to work systems from outside the office, similar to a VPN. The attackers are chaining together two flaws. The first, rated the maximum possible severity of 10 out of 10, lets someone with no account at all trick the device into carrying out actions it should not. The second lets an attacker who already has an administrator account run their own commands on the device. Together, these let criminals take full control of an SMA1000 box without ever needing a password. SonicWall has released emergency fixes, called hotfixes, but says there is no other way to protect an unpatched device. This is not the first time this product line has been hit; a very similar pair of flaws was found and fixed only in July, and some of last year's SonicWall flaws were later linked to ransomware attacks.

NHS England has published its own alert about this issue and says further attacks are "almost certain." Devices like SMA1000 sit at the edge of a network, facing the internet, which makes them one of the first things criminals try to break into. NHS trusts, GP practices, and NHS suppliers often use exactly this kind of device to let staff and partners connect remotely, so a compromised box could give an attacker a way straight into systems that hold patient data. Any organisation that reports incidents like this as part of its NHS Data Security and Protection Toolkit (DSPT) submission should treat this as a live, urgent risk rather than routine maintenance.

Recommendations:

  • Check whether your organisation, or any IT provider working on your behalf, uses SonicWall SMA 6210, 7210, or 8200v appliances.
  • Apply SonicWall's hotfixes immediately; there is no workaround available.
  • Contact SonicWall's technical support team for help checking for signs of compromise.
  • If a device appears to have been compromised, reimage or redeploy it, change all passwords, and reset any authentication tokens.
  • Report any suspected compromise to the NHS England Cyber Security Operations Centre on 0300 303 5222 or cybersecurity@nhs.net.

VMware Fixes Flaws That Let Attackers Escape a Virtual Machine

Broadcom, which owns VMware, has fixed two flaws in VMware Workstation and Fusion, software that lets one computer run several "virtual" computers inside it at once. The more serious flaw scores 9.3 out of 10 for severity and lets someone who already has administrator-level access inside one of these virtual computers break out and run their own code on the real, physical machine underneath. The second flaw works in a similar way. Both need the attacker to already have some level of access inside the virtual machine first, but that access could come from something as simple as a successful phishing email. There is no workaround, so affected organisations need to install the update.

Virtual machines are supposed to be sealed off from the real computer they run on, which is exactly why many organisations use them to test risky software or isolate different tasks safely. A flaw that breaks this seal undoes that safety net entirely. VMware Workstation and Fusion are widely used by IT teams and developers across UK businesses, NHS suppliers, and healthtechs, often for testing or running older systems. An attacker who gets a foothold inside a virtual machine, for example through a phishing email, could use this flaw to take over the whole computer.

Recommendations:

  • Check whether your organisation uses VMware Workstation or VMware Fusion, particularly versions 25H2 or 26H1.
  • Update to VMware Workstation 26H1u1 or VMware Fusion 26H1u1 as soon as possible.
  • Remind staff who use virtual machines that phishing can be the first step towards this kind of attack, not just a way to steal passwords.
  • Ask your IT provider to confirm patching has been completed on any affected machines.
  • Record this advisory and your response for your risk register or DSPT evidence if relevant.

Google Rushes Out Chrome Fix for a Zero-Day Already Being Used by Attackers

Google has released an update for its Chrome browser that fixes 12 security flaws, including one that criminals are already using in real attacks. The flaw sits in V8, the part of Chrome that runs the code found on websites. A booby-trapped web page can trick this part of Chrome into confusing one type of information for another, which can then let an attacker run their own code on a victim's computer, breaking out of the safety sandbox Chrome normally keeps websites inside. A security researcher was paid a bug bounty for finding and reporting the flaw responsibly, but Google's own bulletin confirms it has already been exploited in the wild.

Chrome is one of the most widely used web browsers in UK offices, GP surgeries, and NHS trusts, and this flaw needs nothing more than a visit to a malicious web page to work, no download or extra click required. Because so many staff use Chrome every day for email, patient systems, and everyday browsing, an unpatched browser is a very easy way for an attacker to get a foothold on a work computer. This is a quick, low-effort fix that closes off a real and active threat.

Recommendations:

  • Check that Chrome is updated to version 152.0.7977.82 or later across all work devices.
  • Restart Chrome after installing the update, as updates only take effect once the browser is relaunched.
  • Turn on automatic updates for Chrome and other browsers wherever possible so fixes like this are applied quickly.
  • Remind staff to restart their browser regularly rather than leaving tabs open for days or weeks.
  • Apply the same urgency to any other Chromium-based browsers your organisation uses, such as Microsoft Edge.

Attackers Slip Into 5,000 Dropbox Accounts Through an Old Lenovo Sign-In Link

Dropbox has told around 5,000 users that criminals accessed their accounts by abusing an old feature that let people sign in to Dropbox using a Lenovo account instead of a Dropbox password. Attackers found a weakness in the way Lenovo checked email addresses, which let them register a Lenovo account using someone else's email address and then use it to walk straight into that person's Dropbox account, no Dropbox password needed. The break-ins happened between 4 and 21 August, and none of the affected accounts had two-factor authentication (2FA) turned on. Dropbox has since cut the link between Lenovo accounts and Dropbox entirely and is telling affected users to change their passwords and switch on 2FA.

This incident is a reminder that a weakness in one company's systems, in this case Lenovo's, can be used to break into a completely different company's accounts, in this case Dropbox, when the two are linked together. UK businesses, NHS suppliers, and healthtechs increasingly connect different cloud services and sign-in tools together for convenience, and this shows how a single weak link in that chain can undo the security of everything connected to it. It is also a clear demonstration of why 2FA matters: not one of the affected accounts had it switched on.

Recommendations:

  • Review any "sign in with" or single sign-on links between your organisation's cloud services and third-party accounts.
  • Switch on two-factor authentication (2FA) for all cloud storage and business accounts, including Dropbox, without exception.
  • Ask suppliers and partners how they verify identity before linking accounts together, especially for older, legacy integrations.
  • If your organisation or staff use Dropbox, check for any sign-in activity from unfamiliar Lenovo-linked sessions.
  • Build reviews of old or legacy third-party integrations into your regular supplier and third-party risk assessments.

A Sacked Worker Still Had Access, and It Cost the Company Hundreds of Thousands of Dollars

A company with more than 1,000 staff sacked an employee, but nobody switched off their access to internal systems. The former worker logged back in days later and started causing damage: deleting files, locking other people out of their accounts, and corrupting a database. The mix-up happened because nobody had been clearly given the job of cutting off access. Human resources assumed the IT team would handle it once the termination was processed, and the IT team was waiting for a formal request from HR that never came. Because the former employee had wide-ranging admin rights across several connected systems, the damage spread quickly. The company involved says the clean-up cost hundreds of thousands of dollars and delayed an important project by weeks, and recovery was made harder because the person best placed to fix the damage was the one who caused it.

This was not a clever hack. It was a simple gap in a leaver's checklist, and it is exactly the kind of gap that can happen at any organisation, including UK businesses, NHS suppliers, and healthtechs. Staff who leave, whether on good terms or not, often keep access to shared admin accounts, cloud platforms, and project systems for far longer than anyone realises, especially when responsibility for offboarding is not clearly assigned to one person. For organisations handling patient data or reporting through the NHS Data Security and Protection Toolkit (DSPT), timely access removal after a leaver departs is a basic control that assessors will expect to see evidence of.

Recommendations:

  • Make one named person or team clearly responsible for disabling a leaver's access on their last working day, not "whoever gets to it."
  • Remove access the same day a termination is confirmed, rather than waiting for a separate request to be raised.
  • Regularly review who holds shared admin accounts or wide-ranging system permissions, and avoid letting one person hold sole access to a critical system.
  • Include access revocation and a review of shared credentials on your formal offboarding checklist, alongside returning equipment.
  • Keep a record of leaver access reviews for your risk register or DSPT evidence.

 

Want Help Staying Ahead of Threats Like These?

Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.