CISA added CVE-2026-18577, an actively exploited N-able N-central authentication bypass, to its KEV catalog as N-able pushed build 2026.3.1.7. Other August 3…
CISA Adds N-able N-central Flaw to KEV (8.3)
Overview
- CISA added CVE-2026-18577 to its KEV catalog after active exploitation of an N-able N-central authentication bypass.
- PNLD confirmed that U.K. police, government and customer contact details were compromised and published on the dark web.
- Thermo Fisher patched CVE-2026-17583 in select Applied Biosystems human identification software used with DNA data files.
- Censys tied an iOS-targeting campaign to more than 100 web properties, many posing as AWS sign-in pages.
Details
CISA Adds Exploited N-able N-central Bug to KEV
CISA said it added CVE-2026-18577 to the Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw affects N-able N-central, a remote monitoring and management platform used by service providers to administer customer systems.
The Hacker News reported that attackers used the authentication bypass to gain remote administrative access to N-central servers. N-able said its first fix did not fully close the issue, and the first unaffected build is 2026.3.1.7, released on August 2.
The impact is larger than a single server compromise because N-central sits inside managed-service workflows. A successful compromise can expose the systems that an administrator can reach through the platform. CISA described this class of vulnerability as a frequent attack vector.
Key takeaway: CVE-2026-18577 is a patch-now issue because it combines active exploitation with remote administrative access in a managed-service platform.
PNLD Confirms Police and Government Contacts Were Exposed
The Police National Legal Database confirmed that police, government and customer contact information was compromised and published on the dark web, according to The Hacker News. The affected data included names, organisations and work email addresses.
The incident was identified on July 26. The exposed records involved police officers, police staff, criminal justice professionals, government partners and customers. The source data does not report passwords, operational case files or classified material.
Even limited contact data can create downstream risk. Names, job roles, government affiliations and work email addresses are useful for phishing, impersonation and targeted credential-harvesting attempts. The practical response is therefore less about password resets alone and more about warning affected staff to expect convincing lures.
Key takeaway: The PNLD breach is a confirmed contact-data exposure, and its main near-term risk is targeted phishing against police, justice and government staff.
Thermo Fisher Patches Applied Biosystems DNA File Tampering Flaw
Thermo Fisher Scientific patched a flaw in select Applied Biosystems human identification software, The Hacker News reported. The issue could allow data files to be altered before analysis software loads them.
The vendor's July 31 bulletin said changes to .fsa and .hid outputs could be nearly undetectable if laboratory controls are circumvented. Thermo Fisher tracks the flaw as CVE-2026-17583.
The case is notable because it touches evidence integrity rather than ordinary data theft. In forensic and human-identification workflows, the trust question is whether the file that reaches analysis software is the same file produced by the instrument and preserved by lab controls.
Key takeaway: CVE-2026-17583 is an integrity issue in sensitive laboratory workflows, so patching should be paired with tighter control over DNA output files.
Censys Links iOS Campaign to Fake AWS Sign-In Pages
The Hacker News reported that an unknown Chinese-speaking threat actor targeted Apple iOS devices using a publicly leaked version of the DarkSword exploit kit. The campaign also used fake Amazon Web Services sign-in pages.
Censys said it identified more than 100 web properties tied to the activity. Most were fake AWS sign-in pages on a domain that also hosted exploit infrastructure, according to the report.
The available evidence points to a blended operation: phishing-style credential collection on one side and exploit-kit delivery on the other. The source material does not provide CVE IDs, affected iOS versions or a confirmed count of compromised devices.
Key takeaway: The iOS campaign is best read as an infrastructure and targeting warning, not proof of broad compromise; defenders should correlate mobile, web and cloud-login signals.
Morning Breaking Updates
- feeds.feedburner.com: 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users - Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part
- feeds.feedburner.com: Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts - Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victi
- feeds.feedburner.com: INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws - The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN app
At a glance
| Fact | Publisher | Source |
|---|---|---|
| CISA added CVE-2026-18577 to KEV based on active exploitation evidence. | cisa.gov | cisa.gov |
| CVE-2026-18577 affects N-central builds before 2026.3.1.7. | feeds.feedburner.com | thehackernews.com |
| N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. | feeds.feedburner.com | thehackernews.com |
| PNLD said names, organisations and work email addresses were compromised. | feeds.feedburner.com | thehackernews.com |
| Thermo Fisher tracks the Applied Biosystems issue as CVE-2026-17583. | feeds.feedburner.com | thehackernews.com |
| Censys identified more than 100 web properties tied to the iOS campaign. | feeds.feedburner.com | thehackernews.com |
FAQ
Sources
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks - feeds.feedburner.com
- CISA Adds One Known Exploited Vulnerability to Catalog - cisa.gov
- FOMO in the SOC: Where AI Platforms like Claude Actually Fit - feeds.feedburner.com
- Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS - feeds.feedburner.com
- PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web - feeds.feedburner.com
- Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable - feeds.feedburner.com
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete - feeds.feedburner.com
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code - feeds.feedburner.com
- National Vulnerability Database - NIST
- Microsoft Security Response Center - Microsoft
- Google Online Security Blog - Google
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users - feeds.feedburner.com
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts - feeds.feedburner.com
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws - feeds.feedburner.com
Last updated: 2026-08-04T01:29:46.437Z
댓글
댓글 쓰기