N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

Cybersecurity firm N-able has issued its fourth hotfix in just five weeks for a critical vulnerability in its popular remote monitoring and management (RMM) platform, N-central. The flaw, which allows attackers to gain unauthenticated access to sensitive data and execute arbitrary code on affected systems, is particularly concerning given the widespread adoption of RMM tools … Read more

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A devastating combination of a padding oracle bug and an unauthenticated remote code execution vulnerability in Telerik UI components has been discovered, leaving numerous organizations vulnerable to serious attacks. The severity of this issue is compounded by the fact that it affects not only authenticated users but also those who are not logged in, making … Read more

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

A sophisticated cyber threat campaign has been uncovered, exploiting a vulnerability in ScreenConnect, a popular remote desktop access tool used by organizations worldwide. The attackers are using a clever four-stage VBScript chain to compromise newly connected hosts, spreading malware and potentially leading to full network breaches. The attack vector relies on an initial infection, which … Read more

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

Cloud security checklists have become a staple for organizations, but it turns out they don’t work as intended. A new analysis of 11 real-world incidents reveals that identity exposure is often the primary entry point for attackers, who then use cross-domain privilege escalation to bypass security measures and wreak havoc on cloud infrastructure. The stories … Read more

ConnectWise warns of new ScreenConnect flaw without patch

A critical vulnerability has been discovered in ConnectWise’s ScreenConnect remote access platform, leaving millions of systems exposed to potential attacks. The security flaw affects both cloud and on-premises deployments of ScreenConnect, which is widely used by managed service providers (MSPs), IT departments, and support teams for troubleshooting, patching, and system maintenance. The vulnerability allows attackers … Read more

Hackers exploit new MikroTik RouterOS flaws to hijack routers

MikroTik Routers Under Attack: Hackers Exploit Critical Flaws for Full Control A serious security threat is unfolding as hackers have started exploiting a chain of two recently discovered vulnerabilities in MikroTik routers, allowing them to take control of devices with SSH services exposed to the internet. Poland’s CERT agency has dubbed this exploit chain “MikroTrick,” … Read more

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

A new strain of malware called JSCeal has been discovered, capable of bypassing even Google’s advanced authentication mechanisms by exploiting stolen session cookies. This highly sophisticated attack vector has left many wondering how it works and what it means for online security. At its core, JSCeal is a type of malware designed to intercept and … Read more

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

A critical vulnerability in N-central, a network monitoring and management platform used by thousands of IT service providers worldwide, has left customers scrambling for yet another hotfix from vendor N-able. This marks the fourth such patch in just five weeks, raising concerns about the company’s ability to keep pace with security threats. The vulnerability, identified … Read more

N-able patches max severity N-central flaw amid ongoing attacks

A Critical Vulnerability in Popular IT Management Platform Exposes Thousands of Systems to Attack N-able, a leading provider of remote monitoring and management (RMM) solutions, has released an emergency hotfix to address a maximum-severity vulnerability affecting its N-central platform. This critical flaw, tracked as CVE-2026-86218, allows threat actors to execute malicious code on unpatched systems … Read more