RMM solution provider N-able has disclosed a critical security vulnerability affecting all current versions of its N-central remote monitoring and management platform, including version 2026.3, in both hosted and on-premises deployments. The flaw, tracked as CVE-2026-18577, allows attackers to gain unauthenticated administrative access to the N-central console, giving them full control over managed environments. Note, the vulnerability is being exploited in the wild.
Threat actors are actively exploiting a critical JetBrains TeamCity vulnerability, tracked as CVE-2026-63077. The flaw is an unsafe deserialization of untrusted data issue, which allows unauthenticated attackers to execute remote code through HTTP/S requests. Security fixes are available in TeamCity versions 2025.11.7 and 2026.1.3, along with a security patch plugin for older 2017.1+ versions.
Switzerland’s federal IT office (BIT) reported that hackers exploited Microsoft SharePoint vulnerabilities to breach its servers and compromise around 200 user accounts. The agency believes the attackers used vulnerabilities fixed in Microsoft’s July 2026 security updates, possibly including CVE-2026-56164 or CVE-2026-50522, but it has not confirmed the exact flaw used.
The INC Ransomware group has been observed exploiting two recently disclosed SonicWall vulnerabilities, using the flaws to gain access, steal data, and encrypt files for extortion. The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, affect SonicWall’s Secure Mobile Access (SMA) 1000 series appliances. SonicWall released security patches on July 14, 2026, after researchers observed active exploitation beginning on June 22, 2026.
Microsoft has disclosed a large cyber-espionage campaign orchestrated by Storm-2945, a sub-group of the Russian threat actor, tracked as Midnight Blizzard (APT29/Cozy Bear), that has been active since early May 2026. The campaign, named CaptiveCrunch, targets hospitality networks that use captive portals, such as hotel Wi-Fi systems. According to Microsoft, the attackers manipulate DNS and HTTP traffic to redirect victims through attacker-controlled infrastructure.
Researchers at Bitdefender discovered a malware campaign targeting Roblox players masqueraded as an “undetected” version of the Xeno script executor. The fake tool is being spread through gaming forums and Discord communities. It launches a Java-based infection chain that imitates legitimate Xeno files and hides in trusted-looking Windows folders. The malware can steal browser cookies, Roblox and Minecraft accounts, Discord data, cryptocurrency wallet information, and payment details. It can also log keystrokes, access webcams, record desktops, modify files, run commands, and give attackers control of infected computers.
Researchers discovered a new way to bypass protections against Spectre v2 attacks and created an exploit that can leak sensitive information from Linux systems. The attack affects Intel and AMD processors that use branch predictor protection methods. Spectre v2 (also called Branch Target Injection) takes advantage of how modern CPUs predict and execute instructions early, tricking them into running attacker-controlled code paths and potentially exposing secrets.
Palo Alto Networks researchers have detailed new techniques that can compromise passkey-protected accounts. The attacks, called “Pass-ta-key,” target Google-synced passkeys stored in Chrome. The techniques rely on malware already running on a Windows computer to access Chrome’s local data and steal information about passkey-protected accounts. Advanced versions can register an attacker-controlled key or extract secrets that allow attackers to decrypt synced passkeys.
AI security company Zenity has detailed two AI browser exploitation techniques targeting Claude in Chrome and ChatGPT Atlas, demonstrating how attackers could potentially leverage the tools for account takeovers, phishing campaigns, and unauthorized Amazon purchases.
Security researchers have shown that hackers could misuse AI assistants built into email accounts after gaining access to a user's inbox. Researchers at Barracuda Networks developed a proof-of-concept attack to see how criminals might use AI tools. Instead of directly targeting a CEO, they started with a lower-level employee's compromised email account and used the AI assistant to gather information and plan an attack.
Cybersecurity firm Huntress released two separate technical reports on two macOS malware variants, one of which is a Go-based info-stealer delivered via ClickFix attacks, and the second is a full stealer and remote access tool called MacSync delivered via fake Claude install guides.
In another report, Huntress explained how hackers exploited an SQL injection flaw to breach a corporate network by installing a post-exploitation toolkit directly inside an Oracle database.
A Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices using a publicly leaked version of the DarkSword exploit kit.
In another campaign, a China-based threat actor used the DeepSeek AI model and the open-source Hermes Agent to carry out largely autonomous cyberattacks against internet-exposed servers.
A new ZeroBEC report details The Greatness, a phishing-as-a-service (PhaaS) platform that has evolved from simple credential theft into more advanced attacks, including adversary-in-the-middle and device-code phishing targeting Microsoft 365 accounts. Active since at least 2022, it targets users in several countries and now supports platforms like Microsoft 365, iCloud, Yahoo, and Google Workspace. The service is sold to cybercriminals through Telegram for $289 per month.
Some cheap Android TV boxes come with hidden apps that change the device's identity to look like Samsung, Huawei, Xiaomi, or Vivo smartphones, security researchers at Bitsight found. The fake identities are then used to click on online ads, generating illegal revenue for threat actors behind the operation.
Cybersecurity researchers have uncovered a campaign named SMOKE#SCREEN that uses fake Adobe and Zoom updates, business document requests, and system maintenance tools to trick users into installing remote access software.
A large supply chain attack has hit the NPM package registry, with more than 2,200 malicious versions of 440 packages published after attackers compromised a developer's GitHub account. The attack, called ChainDrop, began after hackers infected the keyv and cacheable packages that have more than 500 million weekly downloads. The attack quickly spread, infecting 433 more packages.
Maksim Silnikau, a Belarusian man who created and ran the Ransom Cartel ransomware group, was sentenced to 16 years in US prison. He helped organize ransomware attacks against at least 18 companies worldwide by recruiting cybercriminals, providing hacking tools, and managing ransom payments. Silnikau was arrested in Spain in 2023, later fled while awaiting extradition, but was captured again while trying to return to Belarus.
Connor Riley Moucka, a Canadian national, pleaded guilty for his role in the Snowflake data breach that affected at least 165 companies. He and his accomplices used stolen login credentials to access customer accounts, stealing sensitive personal and financial data. The group earned millions through ransom payments and selling stolen data. Moucka faces sentencing on October 27 and could receive up to 32 years in prison.
A former FBI agent has been charged with cryptocurrency theft after he used wallet recovery phrases obtained during FBI investigations to steal digital assets. Prosecutors say he made several unauthorized transfers, and authorities recovered more than $925,000 in crypto linked to the case. The agent allegedly admitted he made "very poor decisions" out of frustration and now faces federal theft-related charges.
Two Pakistani nationals were arrested for allegedly developing the Tycoon2FA phishing platform after a joint investigation by authorities in Pakistan, Singapore, and Interpol. The platform helped cybercriminals steal login credentials and bypass multi-factor authentication, affecting over 96,000 victims worldwide. Police also seized digital devices during raids, while four other suspects remain wanted by Interpol.
Ukrainian and Czech law enforcement agencies dismantled a criminal group that defrauded Czech citizens through fake investment schemes. The suspects operated a Kyiv-based call center, used remote access software to steal victims’ banking information, and laundered funds through cryptocurrency. At least nine victims lost UAH 8.4 million (~$210,000) equivalent. Ten suspects were charged and face up to 12 years in prison.