September 8, 2026
- N-able N-central shipped Hotfix 4 (build 2026.3.1.14) in the early hours of 6 September UTC for CVE-2026-86218, a static code injection flaw (CWE-96) rated CVSS 4.0 10.0 by N-able as CNA, allowing unauthenticated RCE on the N-central server. Every on-prem build below 2026.3.1.14 is affected, including servers patched to Hotfix 3 roughly eight hours earlier; hosted NCOD instances are already patched. The release notes say a third party disclosed it and that N-able has "no confirmations" of production exploitation, while the incident notice on the status page says the flaw "has been observed being exploited in the wild" (The Hacker News, BleepingComputer). No IoCs, no interim mitigation, no detection guidance beyond auditing N-central user accounts. Huntress, tracking N-central attacks since August, says it reproduced a PoC exploit chain against build 2026.3.1.10 but the appliance logs had rotated, leaving it unable to say which CVE was used; it advises IP allowlisting or VPN-only access to the console (earlier coverage).
· Vulnerabilities & Exploits
- ConnectWise ScreenConnect has an unpatched flaw in file-transfer behaviour affecting both cloud and on-prem, with no CVE assigned and a fix promised later this week. The interim mitigation is to deselect the
TransferFiles (or legacy TransferFilesInSession) scoped permission on every role and session group. Shadowserver tracks nearly 6,000 internet-exposed instances (BleepingComputer). Separately, Huntress detailed the worm-like rogue-client activity from three unrelated August incidents: a four-stage VBScript chain (1.vbs–4.vbs) where stage one profiles RAM, checks for existing ScreenConnect installs and enumerates Cisco AMP, CrowdStrike, Huntress, Malwarebytes, SentinelOne, Sophos and Symantec into a three-bit state variable in %TEMP%\value.txt (The Hacker News, earlier coverage).
· Vulnerabilities & Exploits
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
September 6, 2026
- A new N-able N-central chain can create unauthorized administrator accounts. Huntress built a PoC combining CVE-2026-86206 and CVE-2026-86207, which it says is distinct from the August flaws. Huntress says a hotfix is available; its follow-up recommends hunting for anomalous accounts using
.invalid email addresses.
· Vulnerabilities & Exploits - Huntress reached the Knight Office login console by pivoting from an IP seen in an adversary-in-the-middle incident. Its phishing-kit investigation offers identity defenders a concrete view of the infrastructure behind session and credential theft. Huntress
· Threat Activity
in One Loophole, 100 Agents, 27 Minutes
September 5, 2026
- Rogue ScreenConnect clients across multiple environments are spawning Windows Script Host to run a chain of four VBS files — a clean detection opportunity on RMM parent-child process trees (Huntress).
· Threat Activity & Malware
in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May
August 29, 2026
- North Korean remote workers are moving beyond IT into sales, marketing and medical roles. Huntress identified five suspected cases in 2026 by pivoting on shared VPN, proxy and hosting infrastructure; operatives used stolen or altered IDs to get hired and remotely controlled company-issued laptops (Huntress, Dark Reading).
· Threat Activity
in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
August 14, 2026
- Akira affiliates now reboot victims into Safe Mode with Networking to strip EDR — Huntress published full analysis of the technique, and in the observed cases the crew exfiltrated data but failed to encrypt (earlier coverage). (BleepingComputer)
· Threat Activity
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
August 10, 2026
- A pre-auth RCE PoC is circulating for macOS Screen Sharing (CVE-2026-65400). Apple's fix addresses an authentication state-management bug that lets an unauthenticated network attacker reach the service without valid credentials; patched in Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 (NCSC-NL advisory). Huntress urges immediate patching and has shared detection guidance (Huntress).
· Offensive & Exploitation
in ResetNightmare PoC Drops at Black Hat: One Kerberos Flaw, Any Account's Password Reset
August 4, 2026
- N-able N-central auth bypass (CVE-2026-18577) is under active exploitation, and the first fix didn't hold. Over the weekend N-able discovered a second authentication-bypass vector that grants attackers administrator access to both hosted and on-prem N-central servers, letting them reach the customer systems those servers manage; build 2026.3.1.7 (shipped Aug 2) is the first unaffected version (The Hacker News, BleepingComputer). Huntress has published exploitation details and detection guidance (Huntress). Continues our earlier coverage.
· Vulnerabilities & Exploits
- Unpatched NTLM leak via the Windows
search: URI handler — no CVE, no fix. Huntress details a coercion primitive functionally identical to CVE-2026-33829 but closed without a CVE, with arguably higher real-world risk; mitigations include blocking outbound SMB, enforcing SMB signing, disabling NTLM, and monitoring URI-handler activity (Huntress).
· Vulnerabilities & Exploits
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
August 3, 2026
- N-able N-central has a critical vulnerability that grants attackers "god-mode" access to the RMM console, according to Huntress, which is actively tracking it. An attacker who exploits it could run scripts, push tooling, and open remote sessions on any managed endpoint — the classic RMM-to-fleet blast radius that makes these platforms prime initial-access targets.
· Vulnerabilities & Exploits
in God-Mode Access in N-able N-central Tops a Day of Fresh Exploits
July 29, 2026
- Huntress declassified its role in an FBI manhunt tied to the 2021 Silk Typhoon Exchange campaign — which it puts at 88,000 compromised servers, far beyond the "limited and targeted" framing at the time — ending in the arrest of a state-backed operator (Huntress).
· Threat Activity
- Huntress is also tracking an active SonicWall credential-stuffing campaign that has produced successful unauthorized logins to VPN and firewall accounts across dozens of organizations; the blog carries IOCs (Huntress).
· Threat Activity
in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route
July 26, 2026
- Infostealer operators are hosting phishing pages as Claude Artifacts, Huntress reports — the malicious link genuinely resolves to claude.ai, defeating URL-reputation checks and hitting 29 organizations.
· AI & Model Security
- North Korea's Contagious Interview campaign is hiding OTTERCOOKIE malware inside SVG images, per Huntress via gbhackers.
· Threat Activity
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 4, 2026
- LDAP Ping (cLDAP) is a blind spot for AD detection. Huntress researchers (@HuntressLabs, @4ndr3w6S) showed that using LDAP Ping to enumerate AD usernames leaves no trace in Windows audit logs — requests are handled by
netlogon.dll rather than ntdsa.dll, so the usual Event 1644 never fires. The pre-auth, no-credentials technique yields confirmed account names for follow-on password spraying and BloodHound/PowerView recon; traffic is still visible at the network level (UDP/389, WFP traces). Huntress
· Offensive & Red Team
in Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat
July 2, 2026
- Huntress is tracking an ongoing, automated password-spray campaign against Azure CLI, abusing the OAuth ROPC flow (which bypasses MFA) from an IPv6 range (
2a0a:d683::/32) attributed to LSHIY LLC / AS32167 and linked to China. Over 81 million login attempts between June 12–26 compromised at least 78 Microsoft accounts across ~64–78 orgs. Recommended mitigations: enforce comprehensive MFA and block ROPC. Huntress, BleepingComputer.
· Cloud & Identity
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US
July 1, 2026
- Huntress revisited device-code phishing, dissecting the variations attackers favor and the "buy-the-tool-skip-the-setup" gaps that keep making it work. Huntress (X)
· Cloud & Identity
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread
June 23, 2026
- Klue breach fallout widens to a who's-who of security vendors — after Icarus posted stolen data on June 22, affected Klue customers now include HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Huntress says no product data, telemetry, passwords, or card data were touched — exposure is limited to business metadata (names, products trialed, subscription/pricing, sales notes) — and warns the data is ripe for Klue/Huntress impersonation. SecurityWeek · Huntress
· Threat Intelligence
in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces
June 21, 2026
- Klue, a competitive-intelligence platform, confirmed attackers stole OAuth tokens used to connect to customers' Salesforce environments, and the new Icarus extortion group has claimed it (BleepingComputer). Salesforce disabled the Klue Battlecards integration on June 11; this is the third Salesforce-connected app abused for CRM data theft, and confirmed victims include security vendors Huntress and Recorded Future (SecurityWeek, The Hacker News).
· Cloud & Identity
- ClickFix campaigns expanded with three new loaders — BabaDeda, Lorem Ipsum, and Potemkin — per Morphisec, BlueVoyant, and Huntress, with the Lorem Ipsum activity possibly tied to Vice Society (The Hacker News). Microsoft also detailed CryptoBandits, a USB-LNK worm spreading a Windows clipper that uses Windows Script Host, ActiveX, and a bundled Tor proxy for C2 (BleepingComputer).
· Threat Intelligence
- Huntress walked through containing a real intrusion at a nursing-facility network: initial access via an exposed RDWeb portal and a compromised test account, followed by RDP lateral movement, enumeration, and persistence attempts — caught and shut down by Managed EDR, Defender telemetry, and SOC response that disabled accounts and blocked the attacker IP before full compromise (Huntress). A useful reminder that internet-exposed RDWeb plus weak test accounts remains a top initial-access path.
· Detection & Purple Team
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.