Criminals calling themselves Warlock are breaking into company SharePoint servers and using stolen security keys to shut off defences before locking up files with ransomware.
Cisco has confirmed attackers are breaking into its SD-WAN Manager software with no password at all, through a brand new flaw.
Fortinet's FortiMail email security software has a bug that lets hackers write files onto the system without logging in, and attacks are already happening.
Apple has rushed out a fix for a flaw in iPhones, iPads and Macs that may have been used in a highly sophisticated, targeted spying attack.
Read on to find out more...
NHS England has warned about a serious flaw, CVE-2026-65660, in Microsoft SharePoint Server, the version that organisations run on their own computers rather than the online Microsoft 365 version. The flaw lets someone who already has low-level access to a SharePoint server run their own code on it. Security researchers say a ransomware gang known as Warlock has been using flaws like this one to break in, steal special digital "keys" from the SharePoint system, and then use a separate piece of genuine but vulnerable security software to switch off anti-virus and other defences. Once defences are down, they spread ransomware across the whole network. Researchers say at least four organisations have been hit in the past two months, including two providers of critical infrastructure.
Many NHS trusts, GP practices and NHS suppliers run their own SharePoint servers for documents, intranets and shared drives. Because the stolen "keys" stay valid even after a patch is applied, simply updating SharePoint is not enough on its own. Any organisation reporting through the NHS Data Security and Protection Toolkit (DSPT) should treat an unpatched or previously compromised SharePoint server as an active ransomware risk, not routine maintenance.
Recommendations:
Cisco Catalyst SD-WAN Manager is software that controls how a company's different offices and sites connect securely to each other over the internet. A new flaw, CVE-2026-76504, is caused by the way the system reads part of a web address. By sending a specially crafted request, an attacker can trick the system into letting them straight in as an administrator, without needing a username or password. Cisco's own security team says it is aware of real attacks already using this flaw, although it has not said how many organisations have been affected.
SD-WAN Manager sits at the centre of an organisation's network, controlling traffic between sites. NHS suppliers and healthtechs that connect multiple sites, including GP practices, clinics or remote offices, often rely on this kind of technology, sometimes managed by a third-party IT provider. A break-in here could give an attacker visibility or control over traffic across an entire organisation, not just one device.
Recommendations:
FortiMail is Fortinet's email security product, used to filter and protect incoming and outgoing email. A critical flaw, CVE-2026-104286, scoring 9.8 out of 10 for severity, combines two weaknesses in how the system handles web addresses and special characters. It lets an attacker with no account at all send a crafted web request that writes files directly onto the system, which can then be used to run their own commands. Fortinet confirms criminals are already exploiting this flaw, though it has not said who is behind the attacks or how many organisations have been hit. Fixes for several affected versions are still described as "upcoming", meaning some administrators must rely on workarounds in the meantime.
Email security gateways like FortiMail sit between an organisation and the outside world, checking every email that comes in or goes out. If an attacker takes control of one, they could read or intercept confidential patient or business correspondence, send convincing phishing emails that appear to come from a trusted internal address, or use it as a stepping stone further into the network. UK businesses and NHS suppliers using FortiMail for email filtering should treat this as an urgent, active threat.
Recommendations:
Apple has released emergency updates for older iPhones, iPads and Macs to fix a flaw in CoreGraphics, the part of the software that draws images and graphics on screen. The flaw, CVE-2026-86950, could let an attacker run their own code on a device simply by getting it to process a malicious image or file. Apple says it is aware of a report suggesting the flaw "may have been exploited in an extremely sophisticated attack" against specific individuals, the kind of attack usually linked to commercial spyware rather than everyday cybercrime. The issue was found with help from security researchers at Meta, which owns WhatsApp, suggesting a messaging app may have been one way the attack was delivered.
Attacks like this are normally reserved for a small number of high-value targets, such as senior executives, government officials, journalists or clinicians handling especially sensitive information, rather than being used against the general public. However, the tools and techniques used in these attacks have a habit of becoming more widely available over time. NHS staff, suppliers and healthtechs who use iPhones, iPads or Macs for work email, clinical apps, or to approve login requests through an authenticator app should treat this update as a priority, especially for anyone in a senior, clinical or IT security role.
Recommendations:
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.