๐จ ACTIVE EXPLOITATION
-
N-central Zero-Day Let Attackers Control Servers and Managed Devices
CVE-2026-18577Attackers exploited a zero-day in N-able N-central to gain administrative access.- N-able N-central customers using hosted or on-premises deployments were affected.
- CVE-2026-18577 affected N-central versions through 2026.3.1 and enabled unauthenticated administrative access.
- Attackers abused N-central Take Control to reach domain controllers, backup servers, and application servers.
- Threat actors deployed AnyDesk, TacticalRMM, TeamViewer, RustDesk, SimpleHelp, HopToDesk, and Cloudflare tunnels for persistent access.
- Observed indicators included renamed cloudflared files such as MicrosoftEdgeUpdate64.exe or msmp.exe, plus IPs 173.249.252.200, 87.249.138.34, 37.19.210.32, 37.153.90.88, 92.118.112.181, and 68.235.46.214. ๐ Source: n-able.com ยท ๐ Coverage: sophos.com ยท ๐ via @GossiTheDog@cyberplace.social
-
UPDATE: SMOKE#SCREEN campaign uses fake updates to deploy ScreenConnect RMM SMOKE#SCREEN attackers are using fake software updates to install ScreenConnect for persistent remote access.
- Windows and macOS users are targeted with fake Zoom, Adobe, document-review, and system-maintenance lures.
- The campaign silently installs legitimate ConnectWise ScreenConnect agents, giving attackers persistent remote desktop access.
- Spear-phishing delivers VBScript droppers, batch loaders, .NET executables, or HTML phishing pages.
- Cloudflare Quick Tunnels and a WsgiDAV staging server at 207.174.0[.]143:8080 deliver payloads and support relay traffic.
- ScreenConnect relays include 207.174.0[.]143:8041, 142.202.191.225:8041/80, and blog.derrspecial-onlinedmin.live:8041. ๐ Source: securonix.com ยท ๐ Coverage: thehackernews.com ยท ๐ via @GossiTheDog@cyberplace.social
๐ CVEs & KEV
- CVE-2026-56162 โ CVSS 10.0 โ Azure SQL Database Elevation of Privilege VulnerabilityImproper authenticatio...
- CVE-2026-65667 โ CVSS 10.0 โ Microsoft Teams Elevation of Privilege VulnerabilityMissing authorization in ...
- CVE-2026-50515 โ CVSS 9.9 โ Azure Service Bus Remote Code Execution VulnerabilityDeserialization of untru...
- CVE-2026-59115 โ CVSS 9.9 โ Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability'......
- CVE-2026-50481 โ CVSS 9.9 โ Azure Active Directory Elevation of Privilege VulnerabilityModification of as...
- CVE-2026-62873 โ CVSS 9.8 โ Microsoft 365 Admin Center Elevation of Privilege VulnerabilityImproper verif...
- CVE-2026-70332 โ CVSS 9.6 โ Microsoft Office SharePoint Spoofing VulnerabilityServer-side request forgery...
- CVE-2026-62896 โ CVSS 9.6 โ Microsoft Teams Elevation of Privilege VulnerabilityImproper authentication i...
- CVE-2026-59118 โ CVSS 9.3 โ Microsoft Power Apps Elevation of Privilege VulnerabilityImproper authorizati...
- CVE-2026-68823 โ CVSS 9.1 โ Azure Confidential Ledger Remote Code Execution VulnerabilityExposed dangerou...
- CVE-2026-49163 โ CVSS 8.8 โ Application Insights Profiler Elevation of Privilege VulnerabilityImproper li...
- CVE-2026-62836 โ CVSS 8.7 โ Azure SQL Managed Instance Elevation of Privilege VulnerabilityImproper restr...