View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical Auth Bypass in N-able N-central Enables Remote Admin Takeover

๐Ÿšจ ACTIVE EXPLOITATION

  • Critical Auth Bypass in N-able N-central Enables Remote Admin Takeover, Patch Issued CVE-2026-18577
    Attackers exploited an authentication bypass in N-able N-central to gain full admin access.
    • Applies to N-able N-central remote monitoring and management platform versions before 2026.3.1.7
    • Vulnerability CVE-2026-18577 allows unauthenticated attackers to bypass authentication and take over admin accounts
    • Attackers gain 'god-mode' access to RMM console, affecting both cloud-hosted and on-premises deployments
    • Exploitation involves using N-central's Take Control feature and deploying Cloudflare tunnels for persistent access
    • N-able released hotfix 2026.3.1.7 on August 2, 2026, after initial fix CVE-2026-18556 proved incomplete
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News, Cyber Security News

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Three High-Severity Flaws in Hugging Face Diffusers Enable Arbitrary Code Execution
    Hugging Face Diffusers library contains vulnerabilities allowing malicious model repos to execute arbitrary code.

    • Applies to users of Hugging Face Diffusers Python package, widely used in AI model pipelines and enterprise environments
    • Three vulnerabilities (CVE-2026-44827, CVE-2026-45804, CVE-2026-44513) allow arbitrary code execution despite trust_remote_code safeguards
    • Exploits involve bypassing trust_remote_code via TOCTOU race conditions in model loading from crafted Hugging Face Hub repositories
    • Attack vector uses manipulated configuration files and custom pipeline code loaded through DiffusionPipeline.from_pretrained API
    • Vulnerabilities fixed in Diffusers version 0.38.0 released May 2026
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • MacSync macOS Stealer Uses Fake Claude Guide to Harvest Passwords and Crypto Wallets
    MacSync malware steals credentials and crypto wallets via a fake Claude installation guide.

    • Targets macOS users searching for Claude AI installation instructions
    • Delivers MacSync stealer through a fake guide and a Base64-obscured curl command in Terminal
    • Steals browser sessions, passwords, keychain data, cloud keys, Telegram sessions, and crypto wallets
    • Uses AppleScript loaded in memory and requests Full Disk Access and repeated macOS passwords
    • Installs persistent remote access tool and trojanizes wallet apps to capture recovery phrases
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ”“ CVEs & KEV

  • Other: 20 CVEs (worst 9.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check