Threat Report 195
Criminals calling themselves Warlock are breaking into company SharePoint servers and using stolen security keys to shut off defences before locking up files with ransomware.
Cisco has confirmed attackers are breaking into its SD-WAN Manager software with no password at all, through a brand new flaw.
Fortinet's FortiMail email security software has a bug that lets hackers write files onto the system without logging in, and attacks are already happening.
Apple has rushed out a fix for a flaw in iPhones, iPads and Macs that may have been used in a highly sophisticated, targeted spying attack.
Read on to find out more...
Criminals Exploit Microsoft SharePoint Flaws to Disable Security Tools and Deploy Ransomware
NHS England has warned about a serious flaw, CVE-2026-65660, in Microsoft SharePoint Server, the version that organisations run on their own computers rather than the online Microsoft 365 version. The flaw lets someone who already has low-level access to a SharePoint server run their own code on it. Security researchers say a ransomware gang known as Warlock has been using flaws like this one to break in, steal special digital "keys" from the SharePoint system, and then use a separate piece of genuine but vulnerable security software to switch off anti-virus and other defences. Once defences are down, they spread ransomware across the whole network. Researchers say at least four organisations have been hit in the past two months, including two providers of critical infrastructure.
Many NHS trusts, GP practices and NHS suppliers run their own SharePoint servers for documents, intranets and shared drives. Because the stolen "keys" stay valid even after a patch is applied, simply updating SharePoint is not enough on its own. Any organisation reporting through the NHS Data Security and Protection Toolkit (DSPT) should treat an unpatched or previously compromised SharePoint server as an active ransomware risk, not routine maintenance.
Recommendations:
- Identify any on-premises (self-hosted) SharePoint servers in your organisation; this does not affect SharePoint Online in Microsoft 365.
- Apply Microsoft's security patch for CVE-2026-65660 as a priority.
- Rotate SharePoint's ASP.NET machine keys after patching, since stolen keys remain usable even once the flaw is fixed.
- Check servers for unfamiliar web shells, new scheduled tasks, or unexpected local admin accounts.
- Make sure backups are stored offline or immutably so ransomware cannot reach or encrypt them too.
- Keep a record of this check as evidence for your DSPT submission if you handle NHS data.
Cisco Confirms Attackers Breaking Into SD-WAN Manager With No Password Needed
Cisco Catalyst SD-WAN Manager is software that controls how a company's different offices and sites connect securely to each other over the internet. A new flaw, CVE-2026-76504, is caused by the way the system reads part of a web address. By sending a specially crafted request, an attacker can trick the system into letting them straight in as an administrator, without needing a username or password. Cisco's own security team says it is aware of real attacks already using this flaw, although it has not said how many organisations have been affected.
SD-WAN Manager sits at the centre of an organisation's network, controlling traffic between sites. NHS suppliers and healthtechs that connect multiple sites, including GP practices, clinics or remote offices, often rely on this kind of technology, sometimes managed by a third-party IT provider. A break-in here could give an attacker visibility or control over traffic across an entire organisation, not just one device.
Recommendations:
- Identify any Cisco Catalyst SD-WAN Manager instances used directly or through a supplier or managed service provider.
- Upgrade to the first fixed release for your software version without delay, given exploitation is already confirmed.
- Never expose the Manager's management interface or API directly to the internet; restrict access to trusted internal networks only.
- Review logs for unexpected administrator actions, logins or new accounts.
- Ask any IT provider or MSP managing your SD-WAN to confirm, in writing, that they have patched this.
Hackers Exploit FortiMail Zero-Day That Needs No Login At All
FortiMail is Fortinet's email security product, used to filter and protect incoming and outgoing email. A critical flaw, CVE-2026-104286, scoring 9.8 out of 10 for severity, combines two weaknesses in how the system handles web addresses and special characters. It lets an attacker with no account at all send a crafted web request that writes files directly onto the system, which can then be used to run their own commands. Fortinet confirms criminals are already exploiting this flaw, though it has not said who is behind the attacks or how many organisations have been hit. Fixes for several affected versions are still described as "upcoming", meaning some administrators must rely on workarounds in the meantime.
Email security gateways like FortiMail sit between an organisation and the outside world, checking every email that comes in or goes out. If an attacker takes control of one, they could read or intercept confidential patient or business correspondence, send convincing phishing emails that appear to come from a trusted internal address, or use it as a stepping stone further into the network. UK businesses and NHS suppliers using FortiMail for email filtering should treat this as an urgent, active threat.
Recommendations:
- Check whether your organisation or IT provider uses FortiMail, and which version.
- Apply Fortinet's patch immediately if one is available for your version.
- If your version's fix is still pending, follow Fortinet's workaround: disable Identity Based Encryption if it is not required, and ensure the management interface cannot be reached from the internet.
- Check systems against the indicators of compromise Fortinet has published, since a workaround alone will not remove files an attacker may have already planted.
- Treat any exposed FortiMail system as potentially compromised and investigate accordingly, even after applying a fix or workaround.
Apple Rushes Out Fix After Sophisticated Spyware-Style Attack
Apple has released emergency updates for older iPhones, iPads and Macs to fix a flaw in CoreGraphics, the part of the software that draws images and graphics on screen. The flaw, CVE-2026-86950, could let an attacker run their own code on a device simply by getting it to process a malicious image or file. Apple says it is aware of a report suggesting the flaw "may have been exploited in an extremely sophisticated attack" against specific individuals, the kind of attack usually linked to commercial spyware rather than everyday cybercrime. The issue was found with help from security researchers at Meta, which owns WhatsApp, suggesting a messaging app may have been one way the attack was delivered.
Attacks like this are normally reserved for a small number of high-value targets, such as senior executives, government officials, journalists or clinicians handling especially sensitive information, rather than being used against the general public. However, the tools and techniques used in these attacks have a habit of becoming more widely available over time. NHS staff, suppliers and healthtechs who use iPhones, iPads or Macs for work email, clinical apps, or to approve login requests through an authenticator app should treat this update as a priority, especially for anyone in a senior, clinical or IT security role.
Recommendations:
- Update any iPhones and iPads to iOS/iPadOS 26.7.1 or later, and Macs to macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1 or later.
- Turn on automatic updates for all company and personal (BYOD) mobile devices used for work.
- Prioritise updates for senior leaders, IT administrators and anyone handling sensitive patient, financial or otherwise confidential data.
- Consider Apple's Lockdown Mode or Advanced Protection Program for staff most likely to be targeted.
- Record mobile device patch levels as part of your asset and vulnerability management evidence for DSPT purposes.
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.