This week's threat report:
Criminals used a maximum-severity flaw in Cisco's own security software to break in and spread Qilin ransomware.
A serious bug in GitLab, the tool many developers use to store and manage code, is already being tested by attackers after details were made public.
A remote management tool used by IT support companies has needed four emergency fixes in five weeks after signs it may already be under attack.
Microsoft has just released its biggest ever monthly batch of security updates, fixing 974 problems, two of which criminals are already using.
A jailed phone shop worker shows why text-message security codes are not as safe as many people think.
Read on to find out more...
Cisco has confirmed that criminals linked to ransomware gangs and state-sponsored hacking groups are breaking into Firepower Management Center, software many organisations use to control their network security and firewalls. They found two flaws. The first is rated the maximum severity of 10 out of 10 and lets an attacker skip the login step completely and take control of the system through its web interface. Cisco's own security team, Talos, says it has seen attackers use this to install extra tools, steal passwords and, in some cases, deploy the Qilin ransomware, which locks up files and demands payment. Cisco has released emergency hotfixes.
Why this matters: Firepower Management Center sits at the heart of an organisation's network defences, so a break-in here can undo every other security control in place. Ransomware gangs are actively using this flaw right now, not just testing it. Any UK business, NHS supplier or healthtech that uses Cisco security products, directly or through an IT provider, should treat this as an emergency. Organisations that report through the NHS Data Security and Protection Toolkit (DSPT) should record their response as evidence of active vulnerability management.
Recommendations:
GitLab, a tool used by software developers worldwide to store and manage their code, has released updates fixing several serious flaws. The worst one scores the maximum severity of 10 out of 10. It lets someone read files they should not be able to see, by tricking the system into thinking they are looking somewhere else, a trick known as path traversal. Security researchers say criminals are already testing this flaw on GitLab servers that can be reached from the internet, and the US Cybersecurity and Infrastructure Security Agency confirmed real-world exploitation on 11 September.
Why this matters: Source code tools like GitLab often hold passwords, private keys and unfinished software, so a break-in here can lead straight to a much bigger attack. UK businesses, healthtechs and NHS suppliers that build or maintain their own software are likely to use GitLab or something similar. If attackers gain access to a healthtech's code, they could find a way into the products or systems that organisation builds for its customers, including the NHS.
Recommendations:
N-able N-central is software that IT support companies and managed service providers use to monitor and control their customers' computers from a distance. A serious flaw, scoring the maximum severity of 10 out of 10, could let an attacker with no account at all run their own commands on an N-central server. N-able has now released its fourth emergency fix for this issue in five weeks, and its own release notes are unclear about whether the flaw has already been used in real attacks, with some describing it as a "critical zero-day". Security firm Huntress says it has been tracking attacks on N-central since August.
Why this matters: Tools like N-central are especially attractive to criminals because a single compromised server can give access to every customer network that IT provider manages, not just one organisation. Many smaller NHS suppliers, healthtechs and GP practices rely on managed IT providers who may use exactly this kind of software. If your IT support is provided by a third party, a flaw like this is as much your risk as theirs, and it is worth asking directly whether they use N-central and whether it has been fixed.
Recommendations:
Microsoft has released its September round of security updates, fixing 974 problems across Windows, Office, Azure, Exchange Server, SharePoint Server and other products, its largest single batch on record. Two of the flaws are described as zero-days, meaning criminals were already using them before a fix was ready. Both let an attacker who already has some access to a computer gain much higher-level control over it. Microsoft and NHS England both say further attacks using these flaws are highly likely.
Why this matters: Windows and Office are used by almost every UK business, NHS trust, GP practice and healthtech, so a delay in applying these updates leaves a very wide door open. Because the two zero-days are about gaining higher-level access rather than getting in from scratch, they are often used as the second step in an attack, after a phishing email or another break-in. Keeping systems patched quickly reduces the damage an attacker can do once they are inside.
Recommendations:
A former mobile phone shop worker in the United States has been sentenced to 16 months in prison for helping criminals take over customers' phone numbers, a trick known as SIM swapping. Kenneth Carter worked at an AT&T store and used his access to the company's systems to move victims' phone numbers onto phones controlled by his criminal partners. Once a number was moved, the criminals could receive the victim's text message security codes and password reset messages, then use them to break into online bank accounts. Three victims faced a combined $600,000 at risk, and one lost almost $100,000. Carter was paid roughly $1,000 to $2,000 for each swap.
Why this matters: This case shows two things that matter well beyond one US phone shop: a single member of staff with the right access can quietly enable serious fraud, and text message codes are not a strong way to protect an account once a phone number can be moved. UK businesses, NHS suppliers and healthtechs that still rely on SMS text messages for security codes or password resets are exposed to the same trick, since SIM swapping happens in the UK too. Anyone handling patient data or financial information should move away from SMS-based checks wherever possible.
Recommendations:
Want help staying ahead of threats like these? Contact Periculo and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.