N-able Patches N-central Flaw That Lets Attackers Run Code Before Login
Every on-premises build before 2026.3.1.14 needs Hotfix 4. N-able's records conflict on exploitation, so MSPs should patch and review RMM activity.
Read article →Reader view
Choose the default article length.
Network activity, protocols, infrastructure, and detection.
Every on-premises build before 2026.3.1.14 needs Hotfix 4. N-able's records conflict on exploitation, so MSPs should patch and review RMM activity.
Read article →Forescout ported a pre-auth PLC exploit with Claude, then bricked the device during an implant attempt. Restrict FTP and monitor crashes and outbound traffic.
Read article →Two factory firmware implants expose white-label ZBT routers through an open WAN service and an unauthenticated phone-home channel.
Read article →CERT Polska confirms attacks through internet-exposed SSH. Install a fixed build, restrict management access, and investigate the published log and account indicators.
Read article →D-Link fixed a DIR-X1860Z flaw that lets a local-network user set a new admin password; the similar DIR-X1860 has no update path.
Read article →SonicWall confirmed active attacks against two SMA1000 flaws and told customers to hotfix, seek an IoC review, and rebuild systems when compromise is found.
Read article →Fire Ant hid tunnels on Cisco routers, injected TACACS servers, and planted Linux backdoors. Sygnia's artifacts show how to test each evidence plane.
Read article →PaperCut confirms active exploitation of NG and MF servers. Release 3 patches the two-flaw chain; new log and service indicators help defenders investigate exposed hosts.
Read article →Shadowserver's retrospective Dysphoria report gives network owners 296,000 reasons to identify, rebuild, and verify compromised IoT devices.
Read article →Citrix documents denial of service; separate research finds a likely SAML path to root code execution, with an important CVE-mapping caveat.
Read article →CISA confirmed exploitation of a CVSS 10 Oracle WebLogic proxy flaw. Patch affected Apache and IIS plug-ins, then review requests for unauthorized data access.
Read article →Attackers are exploiting a Zimbra SNMP flaw through crafted SMTP requests. Version 10.1.20 fixes it; exposed servers need log and file review.
Read article →CISA says attackers are exploiting a Windows IKE remote-code flaw; verify April fixed builds and restrict UDP 500 and 4500 until every exposed host is patched.
Read article →