CTIPilot

Live threat brief

LIVE updated 07 Sep 06:45 UTC
ACT NOW · CRITICALCVE-2026-86206 +2 · exploited · 6 sources · 07 Sep 04:33Z

N-able ships a fourth emergency hotfix in a month after a fully patched N-central server was compromised again through a brand-new flaw

N-able's N-central RMM platform has shipped four emergency hotfixes against three separate, unrelated authentication/RCE flaw sets since 1 August 2026. Huntress found on 2026-09-04 that a customer's already-patched N-central server was compromised again; N-able's Hotfix 3 (CVE-2026-86206, CVE-2026-86207) followed on 2026-09-05, and a third, independent researcher then reported CVE-2026-86218, a pre-auth CVSS 10.0 remote-code-execution zero-day N-able's own Active Incident dashboard states has been observed exploited in the wild. Hotfix 4 (build 2026.3.1.14) is mandatory even for servers already on Hotfix 3.

N-able's own Active Incident dashboard and N-able's Jason Murphy both state CVE-2026-86218 (a pre-authentication remote-code-execution flaw rated CVSS 10.0) has been observed exploited in the wild, even though the concurrently published Hotfix 4 release notes hedge to no confirmed production exploitation. Hotfix 4 supersedes Hotfix 3 and is required even for servers already upgraded to it; hosted (NCOD) instances are already patched by N-able. Self-hosted administrators must apply Hotfix 4 immediately, restrict the N-central console to a VPN or IP allowlist, and audit user/role tables for accounts created without authorization, the exploit chain grants full administrative control over user management.

Open the full advisory to act →

Do now6

  • Upgrade every self-hosted N-central server to 2026.3 Hotfix 4 (build 2026.3.1.14) now, even if already on Hotfix 3 (HF3 does not close CVE-2026-86218) and restrict the console to a VPN or IP allowlist.
    FindingCVE-2026-86206 +2
  • Audit N-central user/role tables for accounts created without authorization, watching in particular for email addresses appended with an unexpected string such as ".invalid".
    FindingCVE-2026-86206 +2
  • Disable the "Microsoft Office File Suspicious Macro Removal Windows" prevention setting in CrowdStrike Falcon next-gen antivirus policy (under Clean infected Microsoft Office files) on every managed endpoint until CrowdStrike ships a fix; Cloud Anti-malware for Microsoft Office Files continues to block malicious macros with that setting off.
    FindingUnpatched SYSTEM escalations in CrowdStrike Falcon…
  • Confirm which Gen Digital antivirus products are deployed anywhere in the estate, including on unmanaged or contractor endpoints: Avast is confirmed affected with no patch yet, and the researcher states AVG and Norton may share the flaw.
    FindingUnpatched SYSTEM escalations in CrowdStrike Falcon…
  • Upgrade every Dell Secure Connect Gateway to the fixed releases, Application version 5.36.00.00 or Appliance version 5.36.00.16; there is no interim mitigation, since Dell's advisory lists its workarounds as None.
    FindingCVE-2026-80172 +3
  • Until the upgrade lands, confirm no SCG instance answers from an untrusted segment, and treat SSH access to the SCG host as equivalent to root on it: any operator account with SSH reaches host root through the exposed Docker socket without a password.
    FindingCVE-2026-80172 +3
7findings
1critical
3high
1exploited
1updated
Categories3 vulnerability2 incident1 annual-report1 threat

06.09.2026 06:4507.09.2026 06:45 UTC · last 24h

Latest findings

Criticality
Kind
Topic
Region
07 Sep 06:45Z· run · 5 findings
07 Sep04:47ZUPD
HIGHupdatedNATOB2

Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida

Update · Follow-up reporting establishes for the first time that the published leak extends well beyond personnel data: it includes records tied to district heating and power plants, fuel depots, backup-power installations, electrical substations, prisons and defense-industrial / Bundeswehr-related material. Germany's BSI issued a public warning of an elevated threat level from the leak (heightened targeted-phishing risk plus a hack-and-leak risk given Berlin's 20 September state election) while assessing the underlying intrusion itself as financially motivated. Berlin's government set up a dedicated coordination unit (BSI, BKA and the domestic intelligence service BfV jointly reviewing the material) and started a risk-based notification process for affected citizens, employees and companies. (first published 2026-08-30)

incident30 Aug 04:35Zmulti-sourceopen ↗
07 Sep04:43ZNEW
NOTABLENATOB2

Recorded Future's H1 2026 Malware and Vulnerability Trends: two clusters reuse an identical post-exploitation tool stack across thirteen and ten unrelated initial CVEs

Recorded Future's Insikt Group published its H1 2026 Malware and Vulnerability Trends report on 2026-09-03, tracking 215 actively exploited CVEs. Its most actionable defender-facing finding is that post-exploitation tool-stack reuse persists across otherwise-unrelated initial-access vulnerabilities: a cluster designated StrikeShark applied an identical six-tool stack across thirteen separate CVEs spanning multiple vendors, and Storm-1175 linked the same credential-theft and ransomware tooling across ten different initial CVEs.

annual-report07 Sep 04:43Zsingle-sourceopen ↗
07 Sep04:40ZNEW
NOTABLENATOC2

ChimeraZ claims France's Département de l'Aveyron employment platform, exposing 20,000+ people's data including 1,499 CVs, a customer account without MFA, an IDOR flaw and a misconfigured Odoo database, per one of two trackers who reviewed the leak

The criminal-forum handle ChimeraZ, already tracked for a recurring data-theft campaign against French departmental fire-and-rescue services (SDIS); claims to have exfiltrated and published data from OnRecrute.EnAveyron.fr, the Département de l'Aveyron's employment platform, exposing 23,381 records covering 20,316 people plus roughly 1,499 PDF CVs. One of two independent reviewers of the leaked files attributes access to a no-MFA customer account combined with an IDOR flaw reaching a misconfigured Odoo database; the other declines to confirm any mechanism. No statement has been issued by the Département or the platform operator.

incident07 Sep 04:40Zmulti-sourceopen ↗
07 Sep04:37ZNEW
NOTABLENATOB2

"ted backdoor" and curlRAT, a DPRK-nexus actor recompiles a victim's own HAProxy source tree to hide C2 inside the load balancer's self-reported connection statistics

Rapid7 Labs documents a previously undocumented Linux espionage toolkit against two South Korean media and automotive-sector organizations: a custom HAProxy filter ("ted backdoor") compiled directly into a recompiled HAProxy 2.8.12 binary that decrements the proxy's own live connection counters after every command-and-control exchange, paired with a companion RAT (curlRAT) built into trojanized replacements of crond, agetty, atd and polkitd. Attributed with medium confidence to a DPRK-nexus cluster via C2-infrastructure overlap with APT37.

threat07 Sep 04:37Zmulti-sourceopen ↗
07 Sep04:33ZNEW
CRITICALCVE-2026-86206 +2exploitedNATOB2

CVE-2026-86206 / CVE-2026-86207 / CVE-2026-86218, N-able N-central: a third, unrelated auth-bypass/RCE chain in five weeks, the third CVE a pre-auth CVSS 10.0 zero-day N-able says is already exploited

N-able's N-central RMM platform has shipped four emergency hotfixes against three separate, unrelated authentication/RCE flaw sets since 1 August 2026. Huntress found on 2026-09-04 that a customer's already-patched N-central server was compromised again; N-able's Hotfix 3 (CVE-2026-86206, CVE-2026-86207) followed on 2026-09-05, and a third, independent researcher then reported CVE-2026-86218, a pre-auth CVSS 10.0 remote-code-execution zero-day N-able's own Active Incident dashboard states has been observed exploited in the wild. Hotfix 4 (build 2026.3.1.14) is mandatory even for servers already on Hotfix 3.

vulnerability07 Sep 04:33Zmulti-sourceopen ↗
06 Sep 16:00Z· run · gap 15h · 2 findings
06 Sep14:00Z
HIGHNATOB2

Chaotic Eclipse turns its zero-day drops on third-party security products: unpatched local privilege escalation in CrowdStrike Falcon and Avast, with working proof-of-concept code public

The pseudonymous researcher tracked as Chaotic Eclipse / Nightmare Eclipse published working local-privilege-escalation proof-of-concept code against three security products in early September 2026, without vendor notice. FalconFlank abuses CrowdStrike Falcon Sensor's Office malicious-macro remediation to reach SYSTEM on fully patched Windows 11 25H2 and Windows Server 2025; CrowdStrike has no fix and advises disabling the "Microsoft Office File Suspicious Macro Removal Windows" policy setting. PrettyPrague dumps the SAM database and spawns a SYSTEM shell through the Avast Sandbox component, with Gen Digital still developing a patch. Kaspersky's HardBreacher is fixed. No CVEs are assigned to any of the three.

vulnerability06 Sep 14:00Zmulti-sourceopen ↗
06 Sep13:55Z

Dell Secure Connect Gateway DSA-2026-382: an unauthenticated request replayed indefinitely mints ADMIN tokens, and Dell ships no workaround for any of the 105 flaws

Dell's DSA-2026-382, released 2026-08-31, fixes 105 proprietary-code CVEs in Secure Connect Gateway 5.0, the on-premises gateway that carries diagnostics and remote-support traffic from a customer's Dell estate to Dell. CVE-2026-80172 (CVSS 9.8) lets an unauthenticated attacker replay one captured request without limit to mint ADMIN access and refresh tokens; CVE-2026-61410 (9.4) is unauthenticated remote command execution through a single crafted request; CVE-2026-80238 (9.3) turns SSH access into host root through an exposed Docker socket. Dell lists no workarounds: the fixed releases are Application version 5.36.00.00 and Appliance version 5.36.00.16. No exploitation is reported.

vulnerability06 Sep 13:55Zsingle-sourceopen ↗
06 Sep 06:49Z· run · gap 9h · quiet window

Explore the knowledge base

Machine-readable: briefbook.json · search.json · RSS feeds · STIX 2.1 · llms.txt · every entry's raw source at entries/<date>/<slug>/index.md

Continuous cyber threat intelligence

Read the signal, not the noise.

CTIPilot is continuous cyber threat intelligence for Swiss government entities: national, cantonal and communal administrations, emergency services, police and armed forces. Published the hour it is verified; source-linked, IOC-free, autonomously generated by an LLM.

Everything verified or updated in the last 24 hours, held to a constant relevance bar. An update or correction to an earlier finding floats it back to the top under the run that made it. How this works →