Blog
CVE-2026-18556 & CVE-2026-18577: N-able N-Central’s Failed Patch Left MSP Networks Open to God-Mode Takeover — Act Now
N-able N-central's incomplete patch for CVE-2026-18556 led to CVE-2026-18577; attackers gained unauthenticated RMM admin access and planted persistent Cloudflare tunnels. Patch to 2026.3.1.7 immediately.
Read More →Microsoft Teams Is Now a Ransomware Entry Point: STAC4749 Deploys Chaos in Under 17 Hours
Sophos tracked STAC4749, a Conti-lineage ransomware campaign that impersonates IT helpdesk via Microsoft Teams to deploy Chaos ransomware in under 17 hours. Learn how to defend your organisation.
Read More →Microsoft Teams Is Now a Ransomware Entry Point: STAC4749 Deploys Chaos in Under 17 Hours
Sophos tracked STAC4749, a Conti-lineage ransomware campaign that impersonates IT helpdesk via Microsoft Teams to deploy Chaos ransomware in under 17 hours. Learn how to defend your organisation.
Read More →CVE-2026-66066 (CVSS 9.5): KindaRails2Shell — Any Rails Image Upload Can Expose Your Master Key and Hand Attackers Full RCE
CVE-2026-66066 (CVSS 9.5) lets unauthenticated attackers upload a crafted file to read arbitrary Rails server files — including the secret_key_base — and escalate to full remote code execution.
Read More →Iran-Linked CyberAv3ngers Hit 30+ US Water Systems With an Unpatchable PLC Flaw — Boil-Water Notices Issued, 7 States on Alert
Iran-linked CyberAv3ngers exploited unpatchable CVE-2021-22681 in Rockwell Allen-Bradley PLCs to disrupt 30+ Minnesota water utilities. CISA issues urgent disconnect order as 7 US states report incidents.
Read More →CVE-2026-57092 (CVSS 9.9): Windows VMSwitch Use-After-Free Lets Hyper-V Guest VMs Escape to Own the Host — Patch Now
CVE-2026-57092 is a CVSS 9.9 use-after-free in Windows VMSwitch allowing Hyper-V guest VMs to break out and escalate to full host control. All Windows Server versions affected — patch now.
Read More →CVE-2026-58644 (CVSS 9.8): Microsoft SharePoint Servers Are Being Hit by Active RCE Exploitation Right Now
CVE-2026-58644 is a CVSS 9.8 Microsoft SharePoint deserialization RCE actively exploited in the wild. CISA added it to KEV on 17 July 2026. Learn what SharePoint versions are affected, how…
Read More →CVE-2026-20316: Cisco Firewall Management Center Zero-Day — Hard-Coded Password Actively Exploited, CISA Orders Patch by August 1
CVE-2026-20316 is a zero-day hard-coded credential flaw in Cisco Secure Firewall Management Center. CISA added it to the KEV catalog on July 29, 2026 with a federal deadline of August…
Read More →Sapphire Sleet: North Korea Backdoored npm’s debug & chalk — Affecting 2 Billion Weekly Downloads
Amazon linked North Korea’s Sapphire Sleet to the npm poisoning of debug, chalk, and axios — packages with 2B+ weekly downloads. Timeline, technical breakdown, and defence playbook inside.
Read More →CVE-2026-63077 (CVSS 9.8): Unauthenticated RCE in JetBrains TeamCity — Your CI/CD Pipeline Is One HTTP Request Away from Compromise
CVE-2026-63077 (CVSS 9.8) lets unauthenticated attackers execute OS commands on any JetBrains TeamCity On-Premises server. Patch to 2025.11.7 or 2026.1.3 now.
Read More →