If you just remember one thing from this briefing…
The tools that manage your identity and remote access are this fortnight's biggest exposure, not the systems they protect.
Cisco confirmed a maximum-severity, unauthenticated bypass in Identity Services Engine this fortnight, and two
remote-monitoring platforms MSPs use to reach client sites — ConnectWise ScreenConnect and N-able N-central —
remain under active exploitation. All three grant root-level control of whatever they manage. Ask this week:
which of these three sit in our estate or our MSP's, and are they patched.
Priority16 Sep
Maximum-severity Cisco identity platform flaw exploited
CISA added CVE-2026-76460 to its exploited-vulnerability catalogue on 16 September: an unauthenticated API
bypass in Cisco Identity Services Engine, CVSS 10. Exploitation grants root-level admin access, letting an
attacker rewrite authentication and network-access policy for every device the platform controls.
So what: confirm today whether any ISE deployment is internet-facing or otherwise
reachable, and patch immediately. Treat any unpatched instance as already compromised.
PriorityEarly Sep, ongoing
Two MSP remote-management platforms under mass exploitation
ConnectWise ScreenConnect (CVE-2026-84869) and N-able N-central (CVE-2026-86218), both patched in early
September, remain under confirmed active exploitation — giving unauthorised file execution or full remote
code execution on client systems reached through the console.
So what: ask whoever manages your site IT which platform they run and whether it is
patched. One compromised console can reach every connected site at once.
WatchH1 2026, ongoing
Qilin remains the most active operator against UK targets
Qilin's leak site listed up to 37 UK organisations through H1 2026, more than any other group, with
construction among its most-hit sectors. No new UK construction victim was confirmed this fortnight, but
the group's pace against the sector has not slowed.
So what: check new leak-site postings against your supplier and subcontractor
register every week, not only when a name looks familiar.
WatchOngoing
Payment diversion fraud continues to outpace encryption losses
The National Crime Agency and National Federation of Builders' joint campaign highlights payment diversion
fraud costing the sector over £200,000 in Q1 2026 alone, with deepfake and business-email-compromise tactics
growing more convincing across long subcontractor payment chains.
So what: require a callback to a known number before changing any bank detail,
whatever the email or call sounds like.