Threat Feed

Threat Report 192

Written by Craig Pepper | Sep 14, 2026, 8:14:59 AM

This week's threat report:

Criminals used a maximum-severity flaw in Cisco's own security software to break in and spread Qilin ransomware.

A serious bug in GitLab, the tool many developers use to store and manage code, is already being tested by attackers after details were made public.

A remote management tool used by IT support companies has needed four emergency fixes in five weeks after signs it may already be under attack.

Microsoft has just released its biggest ever monthly batch of security updates, fixing 974 problems, two of which criminals are already using.

A jailed phone shop worker shows why text-message security codes are not as safe as many people think.

Read on to find out more...

Criminals Break Into Cisco Security Software to Spread Ransomware

Cisco has confirmed that criminals linked to ransomware gangs and state-sponsored hacking groups are breaking into Firepower Management Center, software many organisations use to control their network security and firewalls. They found two flaws. The first is rated the maximum severity of 10 out of 10 and lets an attacker skip the login step completely and take control of the system through its web interface. Cisco's own security team, Talos, says it has seen attackers use this to install extra tools, steal passwords and, in some cases, deploy the Qilin ransomware, which locks up files and demands payment. Cisco has released emergency hotfixes.

Why this matters: Firepower Management Center sits at the heart of an organisation's network defences, so a break-in here can undo every other security control in place. Ransomware gangs are actively using this flaw right now, not just testing it. Any UK business, NHS supplier or healthtech that uses Cisco security products, directly or through an IT provider, should treat this as an emergency. Organisations that report through the NHS Data Security and Protection Toolkit (DSPT) should record their response as evidence of active vulnerability management.

Recommendations:

  • Check whether your organisation or IT provider uses Cisco Firepower Management Center.
  • Apply Cisco's hotfixes immediately rather than waiting for a routine patch cycle.
  • Review Firepower logs for unusual admin activity or unexpected new accounts.
  • Ask your security provider to check for signs of Qilin ransomware or unfamiliar tools on the network.
  • Report any suspected compromise to the NHS England Cyber Security Operations Centre on 0300 303 5222 or cybersecurity@nhs.net.

Serious GitLab Flaw Already Being Tested by Attackers

GitLab, a tool used by software developers worldwide to store and manage their code, has released updates fixing several serious flaws. The worst one scores the maximum severity of 10 out of 10. It lets someone read files they should not be able to see, by tricking the system into thinking they are looking somewhere else, a trick known as path traversal. Security researchers say criminals are already testing this flaw on GitLab servers that can be reached from the internet, and the US Cybersecurity and Infrastructure Security Agency confirmed real-world exploitation on 11 September.

Why this matters: Source code tools like GitLab often hold passwords, private keys and unfinished software, so a break-in here can lead straight to a much bigger attack. UK businesses, healthtechs and NHS suppliers that build or maintain their own software are likely to use GitLab or something similar. If attackers gain access to a healthtech's code, they could find a way into the products or systems that organisation builds for its customers, including the NHS.

Recommendations:

  • Check whether your organisation runs a self-managed GitLab instance and confirm which version it is on.
  • Update to GitLab 19.3.2, 19.2.6, 19.1.8 or later as soon as possible.
  • Restrict access to GitLab instances from the public internet wherever possible.
  • Review access logs for unusual file requests or repository activity.
  • Rotate any credentials or private keys stored in repositories if compromise is suspected.

Remote IT Management Tool Needs Fourth Emergency Fix in Five Weeks

N-able N-central is software that IT support companies and managed service providers use to monitor and control their customers' computers from a distance. A serious flaw, scoring the maximum severity of 10 out of 10, could let an attacker with no account at all run their own commands on an N-central server. N-able has now released its fourth emergency fix for this issue in five weeks, and its own release notes are unclear about whether the flaw has already been used in real attacks, with some describing it as a "critical zero-day". Security firm Huntress says it has been tracking attacks on N-central since August.

Why this matters: Tools like N-central are especially attractive to criminals because a single compromised server can give access to every customer network that IT provider manages, not just one organisation. Many smaller NHS suppliers, healthtechs and GP practices rely on managed IT providers who may use exactly this kind of software. If your IT support is provided by a third party, a flaw like this is as much your risk as theirs, and it is worth asking directly whether they use N-central and whether it has been fixed.

Recommendations:

  • Ask your IT provider or managed service provider directly whether they use N-able N-central.
  • Confirm they have applied Hotfix 4 (version 2026.3.1.14 or later) to any on-premises N-central server.
  • Ask whether they have checked for indicators of compromise, given the uncertainty over prior exploitation.
  • Review contracts with IT providers to confirm they will notify you promptly of security incidents affecting shared infrastructure.
  • Record this check as part of your third-party and supply chain risk review for DSPT purposes.

Microsoft Releases Record-Breaking Round of Security Updates

Microsoft has released its September round of security updates, fixing 974 problems across Windows, Office, Azure, Exchange Server, SharePoint Server and other products, its largest single batch on record. Two of the flaws are described as zero-days, meaning criminals were already using them before a fix was ready. Both let an attacker who already has some access to a computer gain much higher-level control over it. Microsoft and NHS England both say further attacks using these flaws are highly likely.

Why this matters: Windows and Office are used by almost every UK business, NHS trust, GP practice and healthtech, so a delay in applying these updates leaves a very wide door open. Because the two zero-days are about gaining higher-level access rather than getting in from scratch, they are often used as the second step in an attack, after a phishing email or another break-in. Keeping systems patched quickly reduces the damage an attacker can do once they are inside.

Recommendations:

  • Apply Microsoft's September 2026 security updates to all Windows and Office systems as soon as possible.
  • Prioritise devices and servers that are exposed to the internet or handle sensitive data.
  • Ask your IT provider to confirm patching is complete across all managed devices.
  • Review privileged account activity for anything unusual following the update.
  • Record patch completion for your risk register or DSPT evidence if relevant.

Phone Shop Worker Jailed for Helping Criminals Hijack Phone Numbers

A former mobile phone shop worker in the United States has been sentenced to 16 months in prison for helping criminals take over customers' phone numbers, a trick known as SIM swapping. Kenneth Carter worked at an AT&T store and used his access to the company's systems to move victims' phone numbers onto phones controlled by his criminal partners. Once a number was moved, the criminals could receive the victim's text message security codes and password reset messages, then use them to break into online bank accounts. Three victims faced a combined $600,000 at risk, and one lost almost $100,000. Carter was paid roughly $1,000 to $2,000 for each swap.

Why this matters: This case shows two things that matter well beyond one US phone shop: a single member of staff with the right access can quietly enable serious fraud, and text message codes are not a strong way to protect an account once a phone number can be moved. UK businesses, NHS suppliers and healthtechs that still rely on SMS text messages for security codes or password resets are exposed to the same trick, since SIM swapping happens in the UK too. Anyone handling patient data or financial information should move away from SMS-based checks wherever possible.

Recommendations:

  • Move away from SMS text messages for two-factor authentication where possible, and use an authenticator app or hardware key instead.
  • Ask your mobile provider what extra protections it offers against SIM swapping, such as a PIN or passphrase on your account.
  • Limit and monitor which staff can access customer account systems at any telecoms or service provider you rely on.
  • Train staff to recognise that being asked to "just do their job" can still mean unknowingly enabling fraud, and encourage reporting of suspicious requests.
  • Review which of your own accounts or services still rely on SMS codes as a single point of failure, and prioritise the highest-risk ones for change first.

Want Help Staying Ahead of Threats Like These?

Want help staying ahead of threats like these? Contact Periculo and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.