View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Attackers Exploit N-able Patch Bypass Flaw CVE-2026-18577 on RMM

๐Ÿšจ ACTIVE EXPLOITATION

  • Attackers Exploit N-able Patch Bypass Flaw CVE-2026-18577 on RMM Servers CVE-2026-18577
    Attackers are exploiting an authentication bypass flaw in N-able Remote Monitoring and Management (RMM) servers allowing administrator-level access through a patch bypass attack vector.
    • Applies to N-able Remote Monitoring and Management (RMM) servers
    • Vulnerability is an authentication bypass flaw tracked as CVE-2026-18577
    • Allows attackers to gain administrator-level access
    • Discovered through a new attack vector enabling patch bypass
      ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • AIOHTTP prior to 3.14.2 vulnerable to HTTP request smuggling via WebSocket upgrade CVE-2026-69243
    AIOHTTP versions before 3.14.2 have an HTTP request smuggling vulnerability in WebSocket upgrades that can cause trailing bytes to be misinterpreted, enabling request smuggling attacks.

    • Applies to AIOHTTP asynchronous HTTP client/server framework for Python asyncio
    • Vulnerability affects server-side HTTP parsers before version 3.14.2
    • Attack exploits edge case in WebSocket upgrade with request body causing protocol switch before full body receipt
    • Leads to trailing bytes being misinterpreted as upgraded protocol or pipelined data, enabling request smuggling
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Researcher Accesses Active C2 Server Attacking Brazilian Government Systems
    A researcher accessed a live command-and-control server used in attacks against Brazilian government networks, revealing attacker tools and poor operational security.

    • Targets: Brazilian government systems under active attack
    • Attack tools: AD credential theft, database exports, web shells, cryptominers, persistence mechanisms
    • Attack origin: Likely Chinese threat actors with AI/MCP-style orchestration
    • Discovery: Accessed C2 server via compromised system thread, revealing attacker environment and reused Monero wallet
    • Outcome: Server went offline after exposure, indicating poor operational security by attackers
      ๐Ÿ“Ž Coverage: reddit.com ยท ๐Ÿ‘ via r/cybersecurity
  • Chinese Actor Uses DeepSeek AI Agent for Proxyjacking Campaign Targeting SMBs
    A Chinese threat actor deployed a DeepSeek AI agent to conduct proxyjacking attacks on over 1,200 small-to-medium business hosts and their cloud providers by compromising weakly secured servers and deploying MicroSocks SOCKS5 proxies.

    • Targets: Small-to-medium-sized businesses hosting websites and applications, plus their cloud providers
    • Attack: Proxyjacking campaign compromising weakly secured servers to deploy MicroSocks SOCKS5 proxies
    • Method: Autonomous AI agent conducted hundreds of short-lived SSH sessions for reconnaissance and profiling
    • Scale: Over 1,200 victim hosts identified, with stolen credentials used to build relay infrastructure
    • Attribution: Indicators include Beijing time zone activity and Chinese characters in payloads, pointing to a Chinese origin
      ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ“Œ UNDER-REPORTED

  • Iranian-Linked Cyb3rAvengers Target US Water Infrastructure in Recent Attacks
    Iranian state-backed group Cyb3rAvengers has been attacking US municipal water systems by exploiting exposed PLCs, weak passwords, and unpatched devices to remotely control water supply pumps, forcing manual operations with minimal reported damage.
    • Targets: US municipal water systems, including over 30 in Minnesota and others in Michigan, Georgia, South Dakota, and California
    • Attacker: Cyb3rAvengers, an Iranian IRGC-linked APT group active since 2020 against critical infrastructure
    • Attack methods: Exploiting internet-exposed PLCs, weak passwords, unpatched devices, and remote access vulnerabilities
    • Impact: Remote control takeover of water supply pumps, forced manual operations, minimal reported damage in recent attacks
    • Sector challenges: Small municipal budgets, limited OT/IT expertise, lack of cybersecurity regulation and standards in water sector
      ๐Ÿ“Ž Coverage: linkedin.com ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ”“ CVEs & KEV

  • Other: 19 CVEs reported this cycle, highest CVSS score 7.8

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check