If you just remember one thing from this briefing…
One hardcoded GitHub credential reportedly gave attackers seven months inside Arup's project data, including HS2 design files.
FulcrumSec's claimed breach of Arup Group traces to a personal access token left in a JavaScript file on a
forgotten subdomain — a housekeeping failure, not a sophisticated exploit. The group says it reached over
10,000 repositories, including Oasys and ArupCompute source code and HS2 tunnelling and station design data.
Arup has issued no public statement. Ask your design teams this week: where do our access tokens live, and who
last audited our public-facing source control.
Priority27–29 Jul
Three edge and remote-access products added to the exploited-vulnerability catalogue
CISA added Fortinet FortiOS (CVE-2025-68686), Arista VeloCloud Orchestrator (CVE-2026-16812) and Cisco Secure
FMC (CVE-2026-20316, hardcoded credentials, remediate by 1 Aug). All three sit in front of the VPN, SD-WAN and
firewall estate connecting site cabins, subcontractors and design offices.
So what: treat KEV listing as the minimum patch queue for internet-facing assets,
regardless of internal CVSS scoring. Confirm exposure today.
PrioritySince 14 Jul, ongoing
SonicWall SMA1000 zero-days chained by INC ransomware
Two vulnerabilities in the SMA1000 Work Place interface (CVE-2026-15409, CVE-2026-15410), exploited since at
least June, let an unauthenticated attacker tunnel into internal services and, when chained, execute code as
root. SMA1000 is a common choice for contractor and site remote access.
So what: confirm the vendor patch is applied, not scheduled. INC has already used
this pair operationally.
PriorityStanding risk
Invoice fraud remains construction's costliest cyber-enabled loss
NCA data show £3.9m lost to invoice fraud in September 2025 alone across 83 cases, with construction and
manufacturing together a quarter of reported losses. Attackers compromise a supplier's email thread, then
redirect a genuine payment to an account they control.
So what: make a callback to a known, previously verified number mandatory for any
bank detail change on a live project — no exceptions.
WatchOngoing
Ransomware groups continue naming UK construction and engineering firms
NCC Group's Q2 data puts construction and engineering among the most-targeted capital-goods sub-sectors,
Qilin the most active group globally. William Davis Homes (Qilin, 27 May) and, within this coverage window,
digital services provider Caspian One (Deadlock, 26 Jul) were both named.
So what: check both against your supplier and integrator register, including fourth
parties reached through subcontractors.