If you just remember one thing from this briefing…
A forged-token bypass in on-premises SharePoint reached the federal exploited list this fortnight — many contractors run their document platform on it.
CISA added CVE-2026-55040 on 18 August: an unauthenticated attacker can forge a valid token against
on-premises SharePoint, bypassing login entirely. SharePoint remains a common project extranet and document
platform. Ask this week: is ours patched, and if it faces the internet, why?
Priority18 Aug
SharePoint and vCenter join the exploited-vulnerability catalogue together
CISA added Microsoft SharePoint's authentication bypass (CVE-2026-55040) and Broadcom VMware vCenter's
path traversal flaw (CVE-2026-59310) on 18 August, both CVSS 9.8, alongside Windows IKE and macOS flaws.
SharePoint commonly hosts project extranets; vCenter underpins servers many contractors run on.
So what: confirm patch status on any internet-facing SharePoint or vCenter instance
today. Federal remediation was due 21 August — treat that as your own deadline.
Priority30 Aug
UK consultancy named on Qilin's leak site
Qilin claimed Absolute Consultancy Services, a UK-based firm, on 30 August, listing disruption to company
systems and data. Neither the company nor a client has issued a public statement; the claim is unverified
beyond the leak-site posting.
So what: check the name against your consultant and subcontractor register,
including any design or advisory work reaching live projects.
WatchQ1 2026 data
Construction climbs to the fourth most-targeted sector for ransomware
GuidePoint's GRIT report recorded 131 construction ransomware victims in Q1 2026, up 44% year-on-year,
moving the sector from sixth to fourth most affected globally, behind only manufacturing, technology and
healthcare.
So what: budget on the assumption attackers now see construction as a soft,
high-value target, not a niche one.
WatchStanding risk
Payment diversion fraud remains construction's costliest cyber loss
UK construction firms lost over £200,000 in Q1 2026 to payment diversion scams, where criminals
impersonating suppliers or colleagues redirect bank-detail changes on live projects — still more costly in
aggregate than encryption events.
So what: make a callback to a previously verified number mandatory for any
bank-detail change, whoever is asking.