CVE-2026-17583, CVE-2026-18556, CVE-2026-18577, CVE-2026-31431, CVE-2026-44513, CVE-2026-44827, CVE-2026-45804
IP Addresses:
173.249.252.200, 87.249.138.34, 37.19.210.32, 37.153.90.88, 92.118.112.181, 68.235.46.214
Get tomorrow's brief in your inbox
Today: N-able shipped an incomplete patch for an authentication bypass in N-central RMM that let attackers take over servers and reach managed endpoints. CrowdStrike reports adversaries are exploiting vulnerabilities within 48 hours of PoC release, with Belarus-linked groups moving in under 24 hours. Russian SVR hackers compromised hotel WiFi gateways across seven states to steal credentials and deploy RATs.
N-able N-central Authentication Bypass (CVE-2026-18577, CVE-2026-18556)
N-able's initial fix for an authentication bypass in N-central was incomplete. Attackers exploited the flaw to gain remote administrative access to RMM servers and used Take Control to reach managed endpoints, where they installed Cloudflare tunnels as persistent services. CVE-2026-18577 affects all builds prior to 2026.3.1.7. The first vulnerability, CVE-2026-18556, was fixed in 2026.2, but an alternate exploitation path remained open through 2026.3. Both flaws are rated CVSS 8.2 and classified as authentication bypass through alternate path (CWE-288). N-able discovered the attacks July 31 after unusual licensing errors from on-premises customers. A limited number of customers were affected. After compromising N-central servers, attackers registered Cloudflare tunnels as services on managed devices to maintain access after the N-central route was revoked.
Linux LPE CVE-2026-31431 Exploited in Under 24 Hours
Belarus-nexus adversary UMBRAL BISON exploited Linux LPE vulnerability CVE-2026-31431 within 20 hours of public disclosure. The vulnerability was disclosed April 29 with PoC exploit and technical details. CrowdStrike OverWatch detected widespread deployment April 30, with 94% of events in the first 24 hours related to PoC testing. CVE-2026-31431 is on CISA KEV with due date May 15, 2026. EPSS score is 0.945 (100th percentile). This is part of a broader trend where 88% of observed exploitation of vulnerabilities with public PoCs occurred within 48 hours of release from January through June 2026.
Brinks Home Data Breach
ShinyHunters extortion group claims responsibility for stealing nearly 5 million records from Brinks Home's Salesforce environment. Brinks Home has confirmed the breach of its IT systems. The company is one of North America's largest residential security providers.
Sumner County Schools Data Breach Forces Delayed Start
Sumner County Schools in Tennessee delayed the start of the 2026-27 school year due to a network breach reported July 21. The district is still working through the incident with limited public detail available.
N-able N-central Attack Infrastructure
Six IP addresses associated with N-able N-central attacks: - 173.249.252.200 - 87.249.138.34 - 37.19.210.32 - 37.153.90.88 - 92.118.112.181 - 68.235.46.214
Huntress identified four of these as Mullvad or NordVPN exit nodes. Correlate with N-central UI, network, and endpoint logs.
Three attacker domains (Huntress): - mousears.synology.me - wagoosh.direct.quickconnect.to - who-ripped-one.direct.quickconnect.to
Endpoint indicators: - svchost.exe in users' Documents folders - Service named Cloudflared - Outbound connections to the listed IPs
Russian SVR Hackers Compromise Hotel WiFi Gateways Across 7 States (CaptiveCrunch Campaign)
Microsoft attributes recent hotel and public WiFi gateway compromises to Storm-2945, a subgroup of Midnight Blizzard (APT29, Cozy Bear, Russian SVR). The campaign, dubbed CaptiveCrunch, started in May and targeted WiFi networks at hotels, conference centers, and other shared venues across at least seven states. Attackers modified DNS and HTTP traffic from captive portal networks to redirect users to credential phishing sites and malware downloads. The campaign affects hospitality, financial services, professional services, legal, healthcare, energy, and retail sectors. Storm-2945 deployed CornFlake RAT (Golang-based Windows RAT) and ChocoShell (PowerShell infostealer) via fake browser update ClickFix pages. The malware enables reconnaissance, credential and session token theft, file and keystroke collection, audio/video surveillance, and remote shell access. The attackers also targeted Android users with similar techniques to deliver APK files. Infrastructure is managed via FruitStone web-based C&C panel. Recent activity includes device code phishing where victims are instructed to enter device codes into Microsoft sign-in pages to authenticate the attacker's session, bypassing MFA. This integrates device code phishing (previously reported since August 2024) into captive portal operations.
US Water Sector Cyberattacks Hit at Least 7 States
The July 26-27 cyberattack campaign targeting US water and wastewater facilities affected at least seven states: Minnesota (30+ facilities), Michigan, South Dakota, Georgia, and three unnamed states. Federal investigators are examining Iran's involvement. WaterISAC reported Minnesota's Fusion Center found evidence aligned with previous Iran-linked campaigns. Most facilities reported no operational impact and drinking water remained safe. One city briefly took its water plant offline. Rapid City, South Dakota experienced an incident involving a lift station. Attacks targeted equipment connected via cellular communications, consistent with Iran's previous tactics using vulnerable cellular routers. CISA updated an April advisory days before the attacks, warning that Iranian threat actors target ICS made by Siemens, Schneider Electric, and Rockwell Automation. Censys reports roughly 10,000 Rockwell, Siemens, and Schneider PLCs are exposed to the internet.
NotVPN / SplitVPN "No-Logs" VPN Breach Exposes 58 Million Connection Logs
A threat actor on Altenen cybercrime forum is distributing a 17 GB SQL database claimed to be from SplitVPN (formerly NotVPN), a Russian VPN service. The service advertised a "no logs" policy but the database contains 58 million connection logs according to MysteriumVPN research.
Hugging Face Diffusers Code Injection (CVE-2026-44827, CVE-2026-45804, CVE-2026-44513)
Three high-severity flaws in Hugging Face's Diffusers library allow crafted model repositories to execute arbitrary code when loaded, bypassing the trust_remote_code security safeguard. The vulnerabilities (collectively named FaceHugger) are TOCTOU (Time-of-Check to Time-of-Use) issues where the trust check runs only in the first phase but model download uses two sequential HTTP requests. CVE-2026-44827 (CVSS 8.8) allows code injection via a pipeline named "None.py" with trust_remote_code=False. CVE-2026-45804 (CVSS 7.5) is a race condition allowing code to be injected between hf_hub_download and snapshot_download calls. CVE-2026-44513 (CVSS 8.8) allows arbitrary code loading through custom_pipeline flow despite trust_remote_code=False. Fixed in Diffusers 0.38.0 released early May 2026. Diffusers was downloaded 8.1 million times in July 2026 alone.
Thermo Fisher DNA Analysis Software Flaw (CVE-2026-17583)
Thermo Fisher Scientific patched a high-severity flaw (CVE-2026-17583, CVSS 8.2) in Applied Biosystems human identification software that could allow .fsa and .hid DNA data files to be altered before analysis software loads them if laboratory controls are bypassed. Changes could be nearly undetectable without the fix. The updates add digital signatures to verify files have not been modified. Five product lines received updates; three EOL products (3130 Series, ABI PRISM 3100/3100-Avant, ABI PRISM 310) receive no fix. An attacker would need local or remote access to laboratory servers and knowledge of DNA testing workflows. Researchers demonstrated successful file modification in 45 minutes using Anthropic's Claude. Modified files raised no warnings in analysis software. Thermo Fisher told WSJ it knows of no exploitation instances.
Exploitation timelines continue to collapse. CrowdStrike observed 88% of vulnerability exploitation with public PoCs occurring within 48 hours of release, with nation-state actors moving in under 24 hours. AI is emerging as both an attack tool and target, with LLMJacking campaigns generating 200,000 API requests in two minutes and vishing intrusions doubling in H1 2026. The rise of trust abuse across identity systems, cloud environments, and developer workflows is forcing defenders to distinguish malicious activity from legitimate AI-driven behavior, with AI agent-triggered detection leads now 2.5x higher than manual activity.