7 August 2026

8 min read

N-central users urged to patch actively exploited vulnerability | Cyber Intelligence Briefing – 7 Aug 2026

August 2026
Cyber Intelligence Briefing

Top news stories this week

  1. Ransomware N-abled. N-central users urged to patch actively exploited vulnerability
  2. Fabricated & furious. AI fabricates vulnerabilities into official databases; models also escape containment
  3. Insecure. Brinks Home security company targeted in ShinyHunters attack
  4. Identity check. UK police database breach exposes law enforcement details
  5. Vishing ventures. BlackFile-linked group targets legal and financial firms in vishing campaigns
  6. Not so suite. Hotel Wi-Fi used to deliver malware

1. N-central users urged to patch actively exploited vulnerability

N-able has warned customers that attackers are exploiting CVE-2026-18577, an authentication bypass vulnerability affecting its N-central remote monitoring and management (RMM) platform. The flaw impacts all N-central versions prior to 2026.3 and can lead to administrative account takeover. N-able has released an emergency hotfix and urged customers to patch immediately, noting that hosted deployments have already been updated while on-premises customers must apply the fix manually. The flaw resulted from an incomplete fix for a previously disclosed vulnerability

So what?

As a platform used by managed service providers to administer large numbers of customer environments, N-central presents an attractive target for threat actors. A successful compromise can extend far beyond the initial victim, potentially providing access to customers, managed systems, and wider supply chains.  
Read the S-RM threat advisory on this issue.

[Researcher: Gabriella Nolan]  


2. AI fabricates vulnerabilities into official databases; models also escape containment

A researcher identified 54 CVEs linked to a single GitHub account that contained AI-generated descriptions of vulnerabilities that did not exist. Despite a lack of evidence, the submissions progressed through the CVE process and appeared in the US National Vulnerability Database with high or critical CVSS scores before review identified the issues and prompted removal.

Separately, OpenAI, Meta and Anthropic confirmed their models breached safeguards during cyber security evaluations including compromising a real website and social-engineering people. The models created fake identities, persuaded real targets to run malicious code, and in one earlier case even uploaded malware to a public code registry that got downloaded and exploited by a security company. Both companies say the safeguards had been deliberately loosened for testing, and no real harm resulted.

So what?

Organisations should verify vulnerability intelligence against authoritative vendor sources and ensure AI systems with autonomous or internet-facing capabilities operate within independently tested control frameworks.

[Researcher: Winson Lee]  


3. Brinks Home data breach suspected to comprise millions of records

One of North America’s leading physical security providers, Brinks Home, has announced that it was subject to a cyberattack. This comes after the cyber criminal group, ShinyHunters, claimed responsibility for the attack indicating that they were able to compromise the company’s Salesforce instance and allegedly gain access to more than 4 million records, some of which include personally identifiable information.

So what?

Following a significant data breach involving PII, the risk of further attacks on the data subjects is increased. Criminals may use exposed information to perform phishing attacks, increasing the impact of the attack. It is important for organisations to determine the extent of data exposure and inform affected individuals. 

[Researcher: Adelaide Parker]


Zywave Cyber Incident Response Team of the Year Vote - 2026

 

4. UK police database breach exposes law enforcement details

The Police National Legal Database (PNLD) has confirmed a data breach that exposed names and work email addresses of police officers and other criminal justice professionals. While no credentials are believed to have been compromised, the extortion group ExfilSquad claims to have stolen approximately 135,000 records. Researchers have suggested the incident may be linked to exposed Microsoft Power Platform and Power Pages environments.

SO WHAT? 

The breach increases the risk of targeted phishing, impersonation, and social engineering attacks against law enforcement personnel. It also highlights the need to regularly review internet-facing applications and cloud configurations for unintended data exposure.

[Researcher: Houren Lee]


5. BlackFile-linked group targets legal and financial firms in vishing campaigns

Cyber extortion group UNC6671, linked to threat actor BlackFile, is conducting voice phising (vishing) campaigns against law firms, hedge funds, private-equity firms and other financial organisations to gain access to corporate systems. The attackers impersonate IT helpdesks, steal credentials through phishing sites and then use compromised credentials to exfiltrate data from internal systems and cloud platforms that were connected via single sign-on.

So What?

Organisations should implement robust processes for credential access and recovery in place to ensure that only the account holder is able to reset their passwords. Additionally, organisations should block the device code flow authentication across their identity platforms and software that enables it.

[Researcher: Milda Petraityte]


6. Hotel Wi-Fi used to deliver malware

Threat actors have been observed hijacking hotel Wi-Fi portal gateways to deliver malware that can capture webcam images, microphone audio and keystrokes. The compromised network serves a fake browser update that installs a remote access trojan if unsuspecting users are successfully duped into running an attacker-supplied command or utility app.

SO WHAT? 

Travelers should use private connections or tether to a trusted device, and reject software updates, certificates, troubleshooting tools or security utilities offered through captive portals.

[Researcher: Lester Lim]

SUBSCRIBE TO RECEIVE OUR WEEKLY CYBER THREAT INTELLIGENCE BRIEFING VIA EMAIL

The S-RM Cyber Intelligence Briefing is a weekly round-up of the latest cyber security news, trends, and indicators, curated by our intelligence specialists.

To discuss this briefing or other industry developments, please reach out to one of our experts.

Editors

Share this post

Subscribe to our insights

Get industry news and expert insights straight to your inbox.