Threat Report 193
This week's threat report:
Criminals are breaking into company networks through a Cisco flaw that scores the maximum possible severity rating, no password needed.
Check Point has fixed a similarly serious flaw in the servers that manage its security systems, one that could be exploited before anyone even logs in.
A London property manager has warned customers that bank details and the codes to their key lockboxes may have been stolen.
Malicious code hidden inside 13 developer tools has been caught quietly stealing saved passwords from Chrome.
A scheduling contractor's forgotten login left 4,000 patient records exposed for three years, and nobody at the practice knew it was there.
Google Pixel phones have been hit by an attack that takes over the phone without the owner clicking, tapping, or doing anything at all.
Read on to find out more...
Cisco Identity Services Engine Flaw Scores a Perfect 10 and Is Already Under Attack
Cisco has found a serious flaw in Identity Services Engine, or ISE, software that checks who and what is allowed to connect to a company's network, a bit like a security guard on the door. The flaw scores the maximum possible severity rating, 10 out of 10. It lets an attacker with no account at all send a specially crafted request that tricks the system into letting them straight in, without needing a password. Cisco says criminals are already using this flaw in real attacks, and NHS England says further attacks are highly likely.
ISE controls who and what can connect to a network, so a break-in here can hand an attacker the keys to everything else behind it. Many NHS trusts, GP practices, NHS suppliers and healthtechs use Cisco networking equipment, often set up and managed by an IT provider. Because no password is needed, this is an easy way in for criminals, and the flaw is already being used in the wild. Organisations reporting through the NHS Data Security and Protection Toolkit (DSPT) should treat this as an active, urgent risk rather than routine maintenance.
Recommendations:
- Check whether your organisation or IT provider uses Cisco ISE or ISE-PIC.
- Update to a patched version (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4) as soon as possible.
- If you cannot patch immediately, use access control lists to restrict who can reach the management interface.
- Review ISE access logs across every node for unusual usernames or unexpected activity.
- Report any suspected compromise to the NHS England Cyber Security Operations Centre on 0300 303 5222 or cybersecurity@nhs.net.
Check Point Fixes Critical Flaw in Its Security Management Servers
Check Point has fixed a serious flaw in the servers that manage its security systems, including its Security Management Server and Log Server. The flaw sits in the sign-in process itself, before anyone even logs in, and could let an attacker run their own commands on the server with full, "root" level control. It scores 9.8 out of 10 for severity.
These servers sit at the centre of an organisation's security setup, managing firewalls and storing security logs. If an attacker takes control here, they could switch off protections or hide their tracks completely. UK businesses, NHS suppliers and healthtechs that use Check Point to manage their network security should treat this as a high priority, especially anyone still running older, unsupported versions.
Recommendations:
- Check whether your organisation or IT provider uses Check Point Security Management Server, Multi-Domain Security Management Server, Log Server or Multi-Domain Log Server.
- Apply the fix described in Check Point advisory sk1000155 as soon as possible.
- Move off any end-of-support versions (R80 and earlier) as a priority.
- Ask your IT provider to confirm the update has been applied.
- Record this check as part of your supplier and vulnerability management evidence for DSPT purposes.
London Property Manager Breach Exposes Bank Details and Door Codes
City Relay, a company that manages rental properties in London, has told customers that criminals broke into a cloud analytics tool it uses, called Metabase, not once but twice. The attackers took personal data including names, addresses, phone numbers, bank account details and passwords. Because the company also stores the codes for lockboxes that hold property keys, some of those codes may have been exposed too. City Relay has since changed the affected codes and says it has found no evidence the stolen data has been misused.
This shows how a single weak point in a connected tool, in this case an analytics platform, can expose highly sensitive information, including bank details and information that affects physical security, not just data on a screen. Many UK businesses, including NHS suppliers and healthtechs, connect similar analytics or reporting tools to their core systems. If sensitive data is stored in a connected tool without proper protection, a single breach can expose far more than anyone intended.
Recommendations:
- Check what analytics, reporting or dashboard tools are connected to your organisation's core databases, and what data they can see.
- Make sure sensitive information such as passwords and financial details is encrypted, not stored in plain, readable form.
- Ask suppliers of connected tools how quickly they patch known flaws and how they notify customers of incidents.
- Review whether physical security details, such as door codes, are stored digitally, and how well they are protected.
- Watch bank accounts and email inboxes for suspicious activity if a supplier reports a breach.
Malicious Code Hidden in Developer Tools Steals Browser Data
Security researchers have found 13 packages on npm, a library that software developers use to download ready-made pieces of code, that secretly install a new piece of malware called WeaselBiscuit. Once installed, it quietly collects information stored by Chrome browser extensions, which can include saved passwords and login sessions. Researchers say the malware shares similarities with tools previously linked to North Korean hacking groups, though this has not been confirmed.
Developers at NHS suppliers, healthtechs and UK businesses regularly use npm packages to build and maintain software. A single infected package, installed without anyone noticing, can quietly steal credentials and open the door to a much bigger attack on the products or systems that organisation builds. This is a reminder that supply chain risk does not just come from big software vendors, it also comes from the small building blocks developers use every day.
Recommendations:
- Review which npm packages your development team uses and where they come from.
- Use tools that scan for known malicious or suspicious packages before they are installed.
- Avoid installing new or rarely used packages without checking their reputation first.
- Limit what data browser extensions used by developers can access.
- Include software supply chain checks in your regular third-party and supplier risk reviews.
A Forgotten Contractor Account Left 4,000 Patient Records Exposed for Years
A routine security review at a dental practice turned up three accounts with full access to its patient database. One of them belonged to a scheduling contractor the practice had stopped using back in 2021. Nobody at the practice knew the account still existed. It had sat there, forgotten and active, for at least three years, able to reach 4,000 patient records the whole time. The auditor who found it has since discovered the same kind of forgotten account at six other healthcare practices he has checked.
This wasn't a clever hack, it was a login nobody remembered to remove. The same thing happens easily in the UK: practices, NHS suppliers and healthtechs often give contractors, scheduling tools and other third-party systems access to patient or client data, then forget to take it away once the relationship ends. For organisations reporting through the NHS Data Security and Protection Toolkit (DSPT), being unable to show a full, current list of who and what can access patient data is exactly the kind of gap assessors look for, and it is far easier to prevent than to explain after the fact.
Recommendations:
- Keep a full, current list of every account, including contractor and third-party logins, that can access patient or client data.
- Review that list at least twice a year, and remove anything you can't immediately justify.
- Make ending a vendor or contractor relationship automatically trigger a review of any access they were given.
- Don't assume small suppliers or one-off contractors are low risk; check their access the same way you would a large IT provider.
- Keep a record of these access reviews as evidence for your DSPT submission.
Google Pixel Phones Hit by Zero-Click Spyware-Style Attack
Google has fixed a serious flaw in the part of Pixel phones that handles mobile network signals, known as the modem. The flaw let an attacker take over parts of the phone without the owner clicking, opening, or doing anything at all, known as a "zero-click" attack. Google says it may already have been used in a small number of targeted attacks. The US government's cyber agency, CISA, has ordered federal agencies to fix it within three days, and says this type of flaw is often used by companies that build surveillance tools to secretly watch specific people's phones.
Zero-click attacks are especially dangerous because there is nothing for a person to notice or avoid, no dodgy link, no suspicious attachment. Pixel and other Android phones are used across UK businesses, NHS trusts and healthtechs, often to access work email, clinical apps, or approve login requests through an authenticator app. A compromised phone can become a way into an organisation's wider systems, not just a personal privacy problem. Because this kind of attack is normally reserved for high-value or high-risk targets, anyone in a senior, clinical or IT security role should treat it seriously.
Recommendations:
- Check that any Pixel phones used by your organisation are updated to the September 2026 security patch.
- Encourage staff to turn on automatic updates on all mobile devices, not just laptops and desktops.
- Review which staff use their phones to access sensitive systems or approve logins, and prioritise updates for them first.
- Consider extra protection, such as Google's Advanced Protection Program, for staff most likely to be targeted, such as senior leaders, IT admins, and those handling sensitive data.
- Keep a record of mobile device patch levels as part of your asset and vulnerability management evidence.
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.