๐จ ACTIVE EXPLOITATION
- Critical Auth Bypass in N-able N-central Enables Remote Admin Takeover, Patch Issued
CVE-2026-18577
Attackers exploited an authentication bypass in N-able N-central to gain full admin access.- Applies to N-able N-central remote monitoring and management platform versions before 2026.3.1.7
- Vulnerability CVE-2026-18577 allows unauthenticated attackers to bypass authentication and take over admin accounts
- Attackers gain 'god-mode' access to RMM console, affecting both cloud-hosted and on-premises deployments
- Exploitation involves using N-central's Take Control feature and deploying Cloudflare tunnels for persistent access
- N-able released hotfix 2026.3.1.7 on August 2, 2026, after initial fix CVE-2026-18556 proved incomplete
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News, Cyber Security News
๐ต๏ธ RESEARCH & DEEP DIVES
-
Three High-Severity Flaws in Hugging Face Diffusers Enable Arbitrary Code Execution
Hugging Face Diffusers library contains vulnerabilities allowing malicious model repos to execute arbitrary code.- Applies to users of Hugging Face Diffusers Python package, widely used in AI model pipelines and enterprise environments
- Three vulnerabilities (CVE-2026-44827, CVE-2026-45804, CVE-2026-44513) allow arbitrary code execution despite trust_remote_code safeguards
- Exploits involve bypassing trust_remote_code via TOCTOU race conditions in model loading from crafted Hugging Face Hub repositories
- Attack vector uses manipulated configuration files and custom pipeline code loaded through DiffusionPipeline.from_pretrained API
- Vulnerabilities fixed in Diffusers version 0.38.0 released May 2026
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
MacSync macOS Stealer Uses Fake Claude Guide to Harvest Passwords and Crypto Wallets
MacSync malware steals credentials and crypto wallets via a fake Claude installation guide.- Targets macOS users searching for Claude AI installation instructions
- Delivers MacSync stealer through a fake guide and a Base64-obscured curl command in Terminal
- Steals browser sessions, passwords, keychain data, cloud keys, Telegram sessions, and crypto wallets
- Uses AppleScript loaded in memory and requests Full Disk Access and repeated macOS passwords
- Installs persistent remote access tool and trojanizes wallet apps to capture recovery phrases
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ CVEs & KEV
- Other: 20 CVEs (worst 9.8)