threat-intel China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw China-linked threat actor Storm-1175 has deployed a new ransomware strain, StormEncryptor, leveraging a vulnerability in N-able N‑central to gain initial access and subsequently deploy ransomware. This follows a pattern of exploiting various vulnerabilities to quickly compromise systems and exfiltrate data. The group i… The Hacker News · Aug 10, 2026 High CVE-2026-18577CVE-2026-18556CVE-2023-37679CHransomwarevulnerabilitypatch-bypass
ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
supply-chain China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns China-linked hackers, believed to be part of the Storm-1175 group, are exploiting a critical vulnerability in N-central, a remote monitoring and management (RMM) tool, to deploy ransomware. This supply-chain attack is le… The Record · Aug 10, 2026 High CVE-2026-18577CHsupply-chainransomwarezero-day
vulnerability N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist N-able has released a second hotfix (Hotfix 2) to address a critical zero-day vulnerability (CVE-2026-18577) in its N-central RMM product, which was being actively exploited by threat actors. The vulnerability allows for… The Hacker News · Aug 8, 2026 Critical CVE-2026-18577CVE-2026-18556zero-dayremote accesscloudflare
threat-intel N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands A flaw in N-able’s God mode feature allowed attackers to gain unauthorized access to customer networks. The vendor has confirmed that attackers exploited this vulnerability to compromise systems, and a second hotfix has… The Register · Aug 7, 2026 Critical CVE-2026-18577vulnerabilityremote managementcyberattack
vulnerability CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities The CISA has issued a warning about three actively exploited vulnerabilities affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These vulnerabilities – CVE-2026-9198, CVE-2026-18556, and CVE-2026-34486 – ar… SecurityWeek · Aug 5, 2026 High CVE-2026-9198CVE-2026-18556CVE-2026-18577CHcvepatchremote code execution
threat-intel CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited The U.S. CISA has added three vulnerabilities to its KEV catalog, including a critical code injection flaw in Langflow, a Tomcat encryption bypass, and an authentication bypass in N-able N-central. These flaws are curren… The Hacker News · Aug 5, 2026 Critical CVE-2026-9198CVE-2026-34486CVE-2026-18556CNvulnerabilitythreat-actorai
vulnerability Feds get 3 days to patch N-able God mode flaw under active exploit A critical vulnerability, actively being exploited, has been discovered in N-able God Mode, a system management tool. Federal agencies have been given a short window to patch the flaw, highlighting a significant risk of… The Register · Aug 4, 2026 Critical CVE-2026-18577CVE-2026-18556zero-daypatchingsystem management
threat-intel CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in N-able N-central to its KEV catalog due to active exploitation. This flaw, stemming from incomplete patching of… The Hacker News · Aug 4, 2026 High CVE-2026-18577CVE-2026-18556CVE-2025-8875GEICSWvulnerabilityremote monitoringremote management
vulnerability Attackers Exploit N-able Patch Bypass Flaw on RMM Servers N-able disclosed a patch bypass vulnerability (CVE-2026-18577) that allowed attackers to gain administrative access to N-central servers, its remote monitoring and management (RMM) platform. Threat actors exploited this… Dark Reading · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556patch-bypassremote-managementrmm
threat-intel ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks This week’s cybersecurity recap highlighted a concerning trend of AI-powered exploit generation, alongside a series of high-impact security incidents. A vulnerability in Coldcard hardware wallets led to an $88.6 million… The Hacker News · Aug 3, 2026 High CVE-2026-42897CVE-2026-66066CVE-2026-48449USIRaiexploithardware wallet
vulnerability N‑able Patches Vulnerability Exploited to Hack N-central Servers A vulnerability in N-able's N-central remote monitoring and management product has been actively exploited in the wild, allowing attackers to gain administrative access to customer servers. The issue stems from a bypass… SecurityWeek · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556CVE-2025-8875patchremote managementmsp
threat-intel N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete N-able has revealed that attackers exploited a vulnerability in its N-central remote monitoring and management platform to gain remote administrative access to customer systems. Despite a patch release, attackers continu… The Hacker News · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556FIauthenticationremote accessvulnerability