ZeroHour

Search: “NCSC”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Dutch NCSC warns two CVSS 9.8 Check Point VPN flaws enable unauthenticated RCE; patch and restrict access before exploitation begins.

The Dutch NCSC warns that CVE-2026-85102, a security-check bypass in the VPN negotiation process, and CVE-2026-85103, a heap overflow in the certificate ASN.1 decoder, both carry a CVSS score of 9.8 and allow unauthenticated remote code execution on Check Point Security Gateways and Security Management Servers. Check Point fixed the flaws on September 9 via advisories sk1000117 and sk1000118, covering R81.20, R82, R82.10, R81.10.x, R82.00.x plus end-of-support versions R80 through R81.10; R82.20 is unaffected. No public proof-of-concept exists, but the NCSC rates exploitation likelihood as high and recommends patching immediately via LivePatch Take 24 or Jumbo Hotfix and restricting VPN access to trusted IPs.

Security Affairsupdated · 5h agofirst · 3d agoVulnerability 9 sourcesCVE-2026-85102CVE-2026-85103

Water sector example added to the NCSC’s Secure connectivity principles

NCSC UK adds a water sector example to its Secure Connectivity Principles, the first ICS community-authored content on its site.

The UK NCSC has added a water sector example to its Secure Connectivity Principles guidance. It is the first content authored by the Industrial Control System Community of Interest to appear on ncsc.gov.uk. The guidance helps ICS operators apply secure connectivity practices.

NCSC UK · Aug 11, 2026Advisory

NCSC Urges Stronger Controls for Agentic AI Systems

UK's NCSC urges organizations to apply sandboxing, human oversight, and strict access controls when deploying autonomous AI agents.

The UK National Cyber Security Centre published guidance recommending stronger controls for autonomous agentic AI systems. Recommended measures include sandboxing, active human oversight, and tightly scoped access controls to limit unintended agent activity. The guidance aims to help organizations realize the benefits of agentic AI while managing its cyber risk.

Infosecurity Magazine · 27d agoAI safety & security

Cyber Adversary Simulation (CyAS): scheme documents now available

NCSC published adversary simulation guidance and the first Cyber Adversary Simulation (CyAS) scheme documents ahead of the scheme's November 2026 launch.

The UK NCSC released guidance on adversary simulation engagements and the first CyAS scheme documents, including the Scheme Standard and the Working Practices Document. The capability-led scheme, developed with cyber oversight bodies, will formally launch in November 2026 and assess companies seeking NCSC-assured provider status. NCSC describes the current version as a minimum viable product to be refined with feedback from buyers and providers.

NCSC UK · 1h agoAdvisory 2 sources

Help shape the future of resilient private 5G

The UK NCSC invites organizations to collaborate on developing secure, resilient and deployable private 5G network technologies.

The UK National Cyber Security Centre is seeking collaboration with organizations developing technologies and approaches for secure, resilient and deployable private 5G networks. The blog post is an open call to help shape future private 5G resilience.

NCSC UK · Aug 12, 2026Advisory

Disruptive cyber activity highlights risk from internet-exposed systems and edge devices

NCSC links disruptive cyber activity to internet-exposed systems and edge devices, urging OT owners to fix avoidable vulnerabilities and improve resilience.

The UK's NCSC issued guidance following disruptive cyber activity that highlights the risk to internet-exposed systems and edge devices. It encourages owners of operational technology to remediate avoidable vulnerabilities and invest in long-term cyber resilience. The notice underscores that exposed edge devices remain a common entry point for attackers against OT environments.

NCSC UK · 20d agoAdvisory in the wild

The hidden risks of shadow AI

UK NCSC guidance warns shadow AI use by employees risks data exposure, lost data control, and attacker exploitation of vulnerable AI agents.

The UK NCSC warns that 'shadow AI'—use of AI tools not captured in organizational approved systems—is widespread, with 71% of employees reporting unapproved AI tool use. Risks include exposure of sensitive company and customer data, loss of visibility and control when data goes to consumer AI services, and new attack opportunities if adversaries exploit vulnerabilities in AI agents with access to corporate systems. The NCSC advises reducing rather than eliminating the risk through positive security culture, understanding employee needs, offering secure alternatives, and following its joint guidance on careful adoption of agentic AI services.

NCSC UK · 9d agoAdvisory

Managing the cyber risk of agentic AI

UK NCSC guidance recommends safeguards, sandboxing, and active oversight to manage cyber risks of autonomous agentic AI systems.

The UK National Cyber Security Centre published guidance on managing the cyber risk of agentic AI systems. It recommends safeguards, sandboxing, and active human oversight to limit unintended autonomous activity while realizing the benefits of these systems. The publication is official national guidance for organizations deploying agentic AI.

NCSC UK · 27d agoAdvisory

How BitLocker PINs help protect your data and devices

NCSC UK guidance explains that configuring BitLocker PINs mitigates many BitLocker vulnerabilities and urges readiness for future bypass flaws.

The UK National Cyber Security Centre published guidance explaining how BitLocker PINs strengthen protection of data and devices. According to NCSC, enabling a pre-boot PIN mitigates many known BitLocker vulnerabilities that rely on default TPM-only configurations. The guidance encourages organizations to configure PINs now to be prepared for the next disclosed BitLocker bypass.

NCSC UK · Aug 13, 2026Advisory

NCSC and Allies Warn of Iranian Spyware Campaign

NCSC, FBI and AIVD warn Iranian-backed actors deliver Chosen Brick spyware to regime critics via social engineering; stolen data has surfaced on pro-Iranian leak sites.

NCSC, the FBI and the Netherlands' AIVD published a joint advisory warning that a Tehran-backed campaign, active since at least 2025, targets dissidents, activists and journalists with Chosen Brick spyware. The malware persists via Windows registry keys, adds Microsoft Defender exclusions, uses Telegram for C2, and captures screens, audio, emails and Telegram or WhatsApp messages. Stolen data has surfaced on pro-Iranian leak sites in some cases, raising risks to victims' personal safety.

Infosecurity Magazineupdated · 3h agofirst · 1d agoThreat actor in the wild 7 sources

Ncsc Raises Alarms Prompt

The UK NCSC raised alarms about prompt injection risks in LLM-integrated systems, urging organizations deploying AI to review exposure.

The UK National Cyber Security Centre (NCSC) has raised alarms about prompt injection attacks against systems using large language models. The warning highlights how attackers can manipulate model instructions to bypass safeguards, exfiltrate data, or trigger unintended agent actions. Organizations deploying LLM-based features are advised to assess and mitigate their exposure to this technique.

Infosecurity Magazine · 29d agoAI safety & security

Iranian cyber targeting of dissidents, activists and journalists

UK NCSC, FBI, and Dutch AIVD expose CHOSEN BRICK spyware used by Iranian state actors against dissidents, activists, and journalists worldwide.

A joint advisory from the UK NCSC, FBI, and Dutch AIVD details CHOSEN BRICK, a Windows spyware family used by Iranian state cyber actors since at least 2025 against dissidents, activists, and journalists in the UK, US, and Netherlands. Actors build rapport on WhatsApp and Telegram impersonating known contacts or platform support, then deliver disguised payloads resembling apps such as Telegram, Norton, RunwayML, or fake MRI results. The malware persists via HKCU Run registry keys, adds Microsoft Defender exclusions, and uses a unique Telegram bot C2 per victim. Capabilities include screen capture, microphone recording, process enumeration, email and messaging data theft, file deletion, and system wiping; victim data has appeared on pro-Iranian leak sites.

NCSC UK · 1d agoThreat actor in the wild2

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

Attackers actively exploit patched macOS Screen Sharing bug CVE-2026-65400 on systems with port 5900 exposed, gaining root to install a Monero cryptominer.

The Netherlands' National Cyber Security Centre (NCSC) reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing that lets attackers authenticate without valid login credentials. Apple patched the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1, and the NCSC escalated its advisory on August 12 after proof-of-concept code went public and reports arrived of attacks on internet-exposed systems. In every reported case attackers obtained root access and installed a Monero crypto miner; users who cannot patch immediately are advised to disable Screen Sharing.

Help Net Security · Aug 17, 2026Exploit / PoC in the wildCVE-2026-65400

Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

UK, US, and Dutch agencies expose CHOSEN BRICK spyware used by Iranian MOIS hackers to surveil dissidents, journalists, and activists via fake MRI lures.

The UK NCSC, FBI, and Dutch AIVD jointly warned that Iranian state-sponsored hackers deploy CHOSEN BRICK Windows spyware against dissidents, activists, and journalists since at least 2025. Operators build rapport over WhatsApp and Telegram, often posing as known contacts or tech support, then deliver malicious files disguised as an MRI scan or installers for Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, and KeePass. The malware steals contacts, emails, and social media messages, captures screen content and microphone audio, adds Microsoft Defender exclusions, and uses per-victim Telegram bots for command and control. The FBI attributes the tradecraft to Iran's Ministry of Intelligence and Security, including the 'Handala Hack' persona, and stolen data has surfaced on pro-Iranian leak sites.

The Record · 1d agoThreat actor in the wild1

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Sophos found F5 BIG-IP APM malware that injects a PHP web shell into Apache's memory, evading disk scans, linked to exploited CVE-2025-53521.

Sophos's September 7 analysis describes malware tied to F5's c05d5254 activity that hooks apr_dso_load, modifies the libphp PHP module in memory, and injects a PHP web shell when Apache loads apm_css.php3, full_wt.php3 or webtop_popup_css.php3, leaving on-disk files clean. A separate installer infects /usr/sbin/httpd and umount, runs before Apache starts, disables SELinux (per ESET's related PoisonedRefresh analysis), and opens a local socket at /run/bigtlog.pipe for shell access. The activity is linked to CVE-2025-53521 in BIG-IP APM, rated 9.8 CVSS 3.1, patched in October 2025, added to CISA KEV on March 27, 2026.

The Hacker News · 8d agoMalware in the wildCVE-2025-53521

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Hacker News ThreatsDay digest: malicious browser extensions, AI-agent intrusions, NCSC shadow AI warning, M&A wire fraud, and 119,000-domain fake shops.

Socket found four malicious Chrome and Firefox extensions (J7Tracker, VREO, Orbit Tracker) stealing session tokens and wallet data from Axiom Trade and Padre users via attacker-controlled Vercel deployments. Hunt.io reported a Chinese-speaking operator using Claude Code, Alibaba Qwen, and DeepSeek with the SecFlow orchestration framework to automate intrusions against government and financial targets in Afghanistan, Thailand, Taiwan, and the US. The UK NCSC warned shadow AI use risks breaches and regulatory failure, Microsoft announced privacy-preserving Windows Age APIs, and Gen Digital described fake M&A wire-fraud scams. A 119,000-domain fake-shop operation called DoppelCart was also highlighted.

The Hacker News · 6d agoIndustry in the wild

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

About 22,000 Microsoft Exchange servers remain unpatched against critical auth bypass CVE-2026-62911 as a working exploit circulates online.

CVE-2026-62911 is a critical authentication bypass by capture-replay in Microsoft Exchange Server that allows an authorized attacker to elevate privileges over the network, with a CVSS score of 8.0. Microsoft patched the flaw on August 11, 2026, but Shadowserver Foundation scans show roughly 22,000 servers unpatched, with the US (6,200) and Germany (5,100) leading; BSI reports 85% of on-premises Exchange servers in Germany are still vulnerable. The Netherlands' NCSC-NL flagged that a working exploit is circulating, and Exchange 2016/2019 require the Extended Security Updates program for fixes.

Help Net Security · 15d agoExploit / PoC in the wildCVE-2026-62911CVE-2026-428971

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

FBI, NCSC, and AIVD detail Iran MOIS spyware CHOSEN BRICK/HEAVYGRAM, Telegram-controlled Windows malware spying on dissidents since 2023.

A September 15 joint advisory from the FBI, UK NCSC, and Dutch AIVD attributes the Windows spyware HEAVYGRAM (NCSC name CHOSEN BRICK) to Iran's Ministry of Intelligence and Security, with the campaign dating to autumn 2023 and targeting dissidents, journalists, and activists in the UK, US, Netherlands, and worldwide. Delivered via messages impersonating known contacts or tech support, the malware assigns each victim a dedicated Telegram bot for command-and-control and exfiltration, and can take screenshots, record microphone audio, steal Telegram/WhatsApp data, saved passwords, and emails, download more malware, and wipe the computer. Persistence uses a registry Run key (SMQDService or winappx) plus Microsoft Defender exclusions, with stolen data exiting via Telegram and cloud storage services like Vultr and Storj. The US Justice Department seized four pro-Iranian leak sites in March that had published stolen victim data.

The Hacker News · 1d agoMalware in the wild1

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners

Dutch NCSC confirms active exploitation of critical macOS Screen Sharing flaw CVE-2026-65400, granting root access and installing Monero miners.

CVE-2026-65400 (CVSS 9.8) is an authentication state-management flaw in macOS's built-in Screen Sharing that lets network attackers authenticate without valid credentials. The Dutch NCSC confirmed active exploitation against systems with port 5900 exposed to the internet; in every documented case attackers obtained root access and installed a Monero cryptocurrency miner. Apple patched the bug in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, crediting Alfredo Pesoli of Bynario. A related researcher scan found roughly 40,000 exposed Screen Sharing hosts, and security firm Calif built working exploits for related flaws in about four hours using an AI coding agent.

Security Affairs · Aug 15, 2026Exploit / PoC in the wildCVE-2026-65400

[Control Systems] National Instruments security advisory (AV26-914)

Canada's Cyber Centre relayed a National Instruments advisory covering improper access control and cleartext sensitive-information flaws in NI SystemLink and SystemLink Server.

Advisory AV26-914, dated September 11, 2026, notes that NI SystemLink and SystemLink Server prior to or equal to 2026 Q3 Patch 1 are affected by improper access controls and storage of sensitive information in cleartext. The Canadian Centre for Cyber Security urges users and administrators to review the vendor's links and apply available security updates.

Canadian Centre for Cyber Security · 5d agoAdvisory2

Apple macOS Screen Sharing Flaw Exploited on Internet

Actively exploited CVE-2026-65400 in macOS Screen Sharing grants pre-auth root access; attackers deploy Monero miners on exposed systems.

NCSC-NL reported active exploitation of CVE-2026-65400 (CVSS 9.8), an authentication flaw in macOS Screen Sharing patched on August 6, 2026, with root access gained and a Monero miner planted on internet-exposed systems using port 5900. Related Screen Sharing bugs CVE-2026-43779, CVE-2026-43777, and CVE-2026-43760 were fixed in macOS Tahoe 26.6, and researcher @osxreverser noted a pre-auth flaw fixed alongside them affecting roughly 40,000 exposed hosts. Calif said an AI agent produced working exploits for both pre-auth bugs in four hours, underscoring the shrinking gap between patch release and weaponization.

The Hacker News · 29d agoExploit / PoC in the wildCVE-2026-65400CVE-2026-43779CVE-2026-43777+1 CVEs

NCSC Warns Shadow AI Creates New Security Risks

UK NCSC warns that unapproved AI tools used by 71% of UK employees expose corporate data and create hard-to-detect organizational security risks.

The UK's National Cyber Security Centre warned on 7 September that shadow AI, unapproved AI tools used outside organizational controls, creates visibility gaps and raises risks of data breaches, intellectual property loss, and regulatory non-compliance. It cited Microsoft research finding 71% of UK employees had used AI tools not approved by their employer. NCSC also warned AI agents can carry critical vulnerabilities, allowing attackers who exploit one to inherit the agent's data access, services and privileges, and that attackers are highly likely to abuse agents with looser guardrails. The agency recommended reducing rather than eliminating shadow AI through positive security culture and clear guardrails.

Infosecurity Magazine · 9d agoAI safety & security

Zelensky appoints former police chief to lead Ukraine’s cyber coordination center

Zelensky appoints former police chief Ihor Klymenko to head Ukraine's National Cybersecurity Coordination Center amid broader security leadership reshuffle.

Ukrainian President Volodymyr Zelensky appointed Ihor Klymenko, former National Police head, interior minister, and NSDC secretary, to lead the National Cybersecurity Coordination Center (NCCC). The NCCC, created in 2016 under the National Security and Defense Council, coordinates government agencies' responses to major cyberthreats including Russian operations. The appointment comes amid a wider reshuffle of Ukraine's defense and security leadership.

The Record · 1d agoPolicy & legal

CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks

CISA and Five Eyes agencies issued joint guidance detailing 17 Active Directory attack techniques like Kerberoasting and DCSync, with hardening and detection advice.

CISA, the NSA, and cyber agencies from Australia, Canada, the UK, and New Zealand released joint guidance on September 15 covering 17 techniques attackers use to compromise Active Directory, including AD CS, Certificate Services, and Federation Services attacks. Named techniques include Kerberoasting, AS-REP roasting, password spraying, DCSync, NTDS.dit dumping, Golden and Silver Tickets, Golden SAML, and Skeleton Key. Recommendations include minimizing SPN accounts, enforcing AES encryption, disabling NTLM, account lockout thresholds of five attempts, phishing-resistant MFA, and Tier 0 prioritization. The guide also lists Windows event IDs 4769, 4768, 4625, 4771, and 2889 for detecting Kerberoasting and password spraying on domain controllers.

GBHackers · 1d agoAdvisory

10th August – Threat Intelligence Report

North Carolina Ports suffered a cyberattack forcing Wilmington and Morehead City operations onto manual processes; the authority says it is contained.

Check Point's weekly threat intelligence bulletin reports that North Carolina Ports, the US authority operating the ports of Wilmington and Morehead City among others, suffered a cyberattack. The incident forced some operations onto manual processes. The authority claims it has contained the attack.

Check Point Research · Aug 10, 2026Data breach

Peers ask why UK cyber bill leaves execs off the personal liability hook

UK peers propose amendments to the Cyber Security and Resilience Bill adding personal executive liability and board-level cyber responsibility; government defends fines-only approach.

Baronesses Kidron and Ludford backed amendments to the UK Cyber Security and Resilience Bill that would introduce personal civil liability for senior executives and mandate board-level cybersecurity responsibility, citing NIS2 and financial-sector accountability rules. Cybersecurity minister Baroness Lloyd defended the bill's existing regime of fines up to £17 million or 4% of annual turnover, with governance requirements to come via secondary legislation. Peers also debated the bill's 24-hour and 72-hour incident reporting requirements, with Baroness Harding proposing an additional 14-day intermediate report and a one-month final report.

The Register · Security · 10d agoPolicy & legal

CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild

CISA added CVE-2026-86218, a CVSS 10.0 unauthenticated RCE in N-able N-central RMM, to its KEV catalog; on-premises admins must patch to 2026.3.1.14.

CISA added CVE-2026-86218, a CVSS 10.0 static code injection (CWE-96) enabling unauthenticated RCE in N-able N-central, to the Known Exploited Vulnerabilities catalog on September 8, 2026. The flaw affects all on-premises builds before 2026.3.1.14 across the 2025.4 through 2026.3 release lines; N-able shipped Hotfix 4 for 2026.3 on September 5-6, 2026. Huntress research indicates at least one customer's N-central instance was compromised on September 4, and federal civilian agencies must mitigate by September 11 under BOD 26-04. Hosted environments were patched server-side, but a compromised RMM server can serve as a single point of entry into entire MSP client bases.

Why APAC Enterprises Need Real-Time Threat Intelligence as Singapore, Malaysia, and Thailand Tighten Cyber Compliance in 2026new

Singapore, Malaysia, and Thailand all tightened cyber compliance in 2026, mandating continuous monitoring and rapid incident reporting for critical infrastructure.

Singapore's CSA issued the Cybersecurity Code of Practice 2026 for Critical Information Infrastructure on 29 July 2026, adding board cyber-resilience duties, annual training, and controls on Interconnected Systems, with most obligations effective by 29 July 2027. Malaysia's Cyber Security Act 2024 requires NACSA-licensed providers, audits, and fast incident notification, with fines up to RM500,000 and up to ten years' imprisonment. Thailand's NCSA cloud security standard has been enforced since 10 September 2026, with a Website Security Standard effective 16 September 2026. The vendor article argues detection speed has become a compliance metric driving demand for real-time threat intelligence.

Cyble · 57m agoPolicy & legal

Critical N-able N-central Vulnerability and Active Exploitation

N-able N-central pre-auth RCE zero-day CVE-2026-86218 (CVSS 10.0) is exploited in the wild; on-prem admins must upgrade to 2026.3 HF4.

N-able disclosed a third N-central vulnerability, CVE-2026-86218, a pre-authentication RCE rated CVSS 10.0, and released hotfix 2026.3 HF4 superseding build 2026.3.1.13. Huntress reproduced an exploit chain involving an authentication bypass (CVE-2026-86206/CVE-2026-86207) after a fully patched customer's N-central production server was compromised on September 4. Attackers appended strings like .invalid to account names and probed the /remoteControlAction.do?method=getPierDetails endpoint; Huntress worked with Cloudflare to disable adversary tunnel infrastructure. Hosted N-central instances are already patched; on-prem administrators must upgrade immediately.

Huntress · 10d agoExploit / PoC in the wildCVE-2026-86218CVE-2026-86206CVE-2026-86207+2 CVEs

Suspected Iran-linked attack knocked UK power plant offline for days

Suspected Iranian hackers knocked a small UK power plant offline for four days in July 2026, with no noticeable impact on the national grid.

Sources told The Telegraph that a British power plant was offline for four days in July 2026 following a suspected Iranian cyberattack, reported to the National Cyber Security Centre. The UK energy minister said the incident affected a small-scale energy generator with no noticeable effect on the power supply, and energy CEOs were briefed and given further advice afterward. The attack followed warnings about Iranian cyber activity against US energy, water, and government networks, including a coordinated attack on 30+ US community water utilities.

Help Net Security · 24d agoThreat actor

UK Government Begins Moving 23 Million Users Away From Passwords

UK government rolls out passkeys for GOV.UK One Login, giving 23 million users phishing-resistant passwordless access to public services.

The UK government has begun deploying passkeys across GOV.UK One Login for more than 23 million users, replacing passwords and SMS one-time codes with FIDO2 cryptographic credentials. A trial saw over 300,000 people adopt passkeys, and nearly one in ten daily authentications already use them, cutting SMS verification costs by almost £600 per day. Passkeys remain optional, with password-based sign-in retained as a fallback, and the NCSC endorses the approach as phishing-resistant.

Cyber Security News · 2d agoPolicy & legal

[Control Systems] National Instruments security advisory (AV26-856)

Canada's Cyber Centre relayed National Instruments advisories for memory corruption, out-of-bounds read, and out-of-bounds write flaws in LabVIEW versions.

The Canadian Centre for Cyber Security published control systems advisory AV26-856 covering National Instruments LabVIEW. Affected versions include releases before 23.0.0, 23.3.10, 24.3.7, 25.3.5, and 26.3.1. The flaws include memory corruption, an integer conversion out-of-bounds read, and an integer overflow out-of-bounds write. Users and administrators are urged to review the links and apply NI security updates.

Canadian Centre for Cyber Security · 19d agoAdvisory

UK.gov begins killing off passwords for 23 million users

UK government rolls out passkeys to 23 million GOV.UK One Login users, saving £600 daily in SMS costs and resisting phishing.

The UK government is expanding passkey sign-in across GOV.UK One Login for more than 23 million users after a trial with over 300,000 people. Nearly one in ten daily One Login sign-ins already use passkeys, which the government says are up to eight times faster than password plus 2FA code. The switch saves taxpayers nearly £600 per day in SMS costs, and the NCSC is encouraging adoption while passwords remain optional.

The Register · Security · 3d agoPolicy & legal

CVE-2026-86218 | N-able N-central Pre-Authentication Remote Code Execution Vulnerability

N-able N-central pre-auth RCE CVE-2026-86218 (CVSS 10.0) is actively exploited; CISA added it to KEV and a hotfix is available.

CVE-2026-86218 is a critical pre-authentication remote code execution flaw (CWE-96 static code injection) in N-able N-central servers, scored 10.0 CVSS 4.0 by N-able and 9.8 CVSS 3.1 by NIST. N-able fixed it in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) on September 5, 2026, and has already patched hosted NCOD environments. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 8, 2026, citing evidence of active exploitation, though researchers have not attributed every reported N-central compromise to this flaw. Horizon3 released a NodeZero Rapid Response test to validate exposure and recommends log review for prior compromise.

Horizon3.ai · 18h agoExploit / PoC in the wildCVE-2026-862183· 1 read

Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program

SE Labs launched PIVOT, a six-month vendor detection testing program backed by CrowdStrike, Fortinet, Palo Alto Networks and Sophos, as major vendors exit MITRE evaluations.

SE Labs unveiled PIVOT on September 15, a six-month testing program in which its ethical hackers replicate nation-state and criminal attack chains against participating vendor products, with results due January 2027. Broadcom (Symantec/Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks and Sophos have confirmed participation, and Gartner and Forrester analysts will verify the underlying evidence before publication. The launch follows declining participation in MITRE Engenuity ATT&CK Evaluations: Enterprise, which fell from 30 vendors in 2023 to 11 in 2025 after public withdrawals by Microsoft, SentinelOne and Palo Alto Networks.

Infosecurity Magazineupdated · 2h agofirst · 1d agoIndustry 12 sources

The G7 tells industry to hurry up and prep for post-quantum encryption

A G7 working group report urges governments and industry to accelerate post-quantum cryptography migration, framing quantum risk as a near-term economic threat.

A cybersecurity working group formed at the June 2026 G7 Summit in France called on organizations to stop postponing migration of critical systems to post-quantum cryptography, warning that harvest-now-decrypt-later attacks against currently encrypted data exist today. The report was signed by CISA, the UK NCSC, France's ANSSI, Germany's BSI, Canada's CSE, Japan's NCO, and Italy's ACN. It also cautions that some NIST-selected PQC algorithms have already been broken on classical computers, reinforcing support for crypto-agility. The push aligns with a recent US executive order moving federal PQC migration timelines from 2035 to 2030, while Google and others target 2029.

CyberScoop · 13d agoPolicy & legal