Archive for September 8, 2026

N-able warns MSSPs, MSPs & orgs: patch critical N-central vulnerability NOW

Posted in Commentary with tags on September 8, 2026 by itnerd

N-able is urging users of on-premises N-central to immediately apply its patch for an unauthenticated remote code execution (RCE) vuln to its N-central endpoint management platform, as it’s currently being actively exploited. The platform is widely used among managed service providers (MSPs and MSSPs), and many internal corporate enterprises are also users.

The vulnerability is tracked as CVE-2026-86218 with a CVSS score of 10/10, and was discovered after N-able patched two other flaws in N-central.

“This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited. We communicated this 2026.3 hotfix  earlier today, and we want to use this post as a reminder to upgrade immediately if you haven’t already, so we can help keep you and your customers protected,” the company’s alert reads. “Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range.”

The alert also notes that N-central hosted environments don’t require the patch as it was deployed server-side.

You can read the alert here: N-central Security Update – Take Action to Apply 2026.3 HF4 – N-able

Waseem Ahmed, Head of Engineering at Secure.com

N-able makes N-central, software that IT teams and managed service providers use to watch over and control large numbers of customer computers from one central console. That reach is exactly why this bug is so dangerous.

A single flaw rated 10 out of 10 lets an attacker run code on the N-central server without any login or password first, so one weak spot can open the door to every client network hanging off that platform. Attackers love this kind of target because it turns one break-in into many.

On-premises teams should apply the 2026.3 HF4 hotfix right now, hunt their logs for scans from the flagged IP range, and look for strange new admin accounts. Trusted management tools deserve the same hard scrutiny you give the front door, because attackers already treat them as the shortest path in.

Suzu Labs CTO Denis Calderone:

The severity really comes down to the unprecedented amount of trust it has over its operating environment. It has so much control that you can basically think of a compromised N-central server as having control of a fleet of trojanized nodes; since you own the server, you automatically control all of its nodes. N-able is commonly deployed as an MSP tool, and oftentimes the end client isn’t even aware that they have N-able running because the MSP often white labels the tool as their own. What really worries me is the organization that doesn’t know they have N-able combined with the MSP that hasn’t patched yet. If you want an example of “history repeating” venture back to 2021 when Kaseya VSA got similarly popped; same results.

And the velocity here has our attention. This is N-central’s fourth emergency hotfix in five weeks and their fifth CVE since August. Huntress confirmed a compromised customer environment on September 4, two days before this patch even dropped. Someone is actively picking this platform apart, and the downstream businesses that are most exposed have no mechanism to even know whether their MSP has kept up with the patches.

If you use on-premises N-central, you need to patch all the things ASAP as it is a safe bet that the bad guys are going to leverage this against you if your on-premises N-central instance is attacked.

Google Threat Intel Findings on Adversarial AI 

Posted in Commentary with tags on September 8, 2026 by itnerd

A new report by Google Threat Intelligence Group (GTIG) took a look at the Q2 standings of adversarial AI, finding that threat actors are using multi-agent AI frameworks to automate credential theft, with one attacker building and deploying a campaign that harvested thousands of credentials in under six hours. 

Scott Miserendino, Chief Technology Officer at DataBee, A Comcast Company:

“GTIG’s findings point to a shift in the threat landscape, the same AI tools that accelerate software development and other business processes are now targets themselves. It is little surprise that threat actors have found success in leveraging AI across the kill chain. The fact that attackers are stealing API credentials to AI models and hijacking cloud environments, however, to run unauthorized AI workloads signals that access to frontier AI may be becoming as valuable as traditional data theft. Threat actors are adapting to the economics of AI not just using the technology.”

Dan Moore, Sr. Director, CIAM Strategy & Identity Standards at FusionAuth

“These multi-agent attacks move faster and hit more systems than most security platforms can detect. The prize now goes beyond ransoming or selling your confidential data – access to your proprietary AI models and compute resources are a direct target too. LLMjacking, the arbitrage of stolen IaaS and premium-model compute, is a booming business, and against the top-tier models it can cost victims over $100,000 a day.

The best defense remains short-lived tokens (and the monitoring to ensure they are not being used by attackers), keeping credentials safe from LLMs by using secrets managers, and strong permission models that enforce least privilege at every layer of the stack.”

I’ve said it before and I will say it again. Your plans to defend yourself have to include AI. If not, it is a matter of when not if you will get pwned.

Cyberattack encrypts German utility’s IT systems serving critical infrastructure

Posted in Commentary with tags on September 8, 2026 by itnerd

cyberattack that began September 1st has encrypted the central IT systems of Stadtwerke Landsberg, a municipal utility in Bavaria that provides electricity, water, wastewater treatment, district heating, fiber connectivity and other local infrastructure.

The utility’s office and communications systems are disrupted, leaving employees with limited access to phone and email, but operational systems responsible for electricity, water and other essential utility services were unaffected and continue to operate normally.

Stadtwerke Landsberg said it can’t yet rule out whether attackers accessed or stole customer data, including names, addresses, phone numbers, email addresses and bank information.

Jeremiah Fowler, Cybersecurity Researcher, Black Hills Information Security:

Stadtwerke Landsberg Cyber Attack: An incident like this serves as a reminder that smaller and regional infrastructure providers face the same threats as national utility providers, but they often don’t have comparable cybersecurity budgets or staffing to face the growing threats. This is also a good example of why it is important to have segmentation between business IT networks and operational technology. The ability to isolate compromised systems can also help prevent a cyberattack from becoming a doomsday scenario.

Attackers may see regional critical infrastructure as low hanging fruit when it comes to being a target and these systems could also serve as testing grounds for larger attacks against bigger targets. Another concern is the potential theft of PII. Targeted phishing attempts are a real concern when individuals can be connected to services. Criminals would know account numbers, payment history, and much more that makes these attempts believable and much more dangerous.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

Stadtwerke Landsberg runs electricity, water, wastewater, heating, fiber, and EV charging for a Bavarian town. When it gets breached, the attacker gets a near-complete household profile, names, bank details, addresses, and phone numbers for services residents can’t switch away from. You can change your grocery store after a breach. You can’t change your municipal water provider.

IT/operational technology (OT) segmentation kept Landsberg’s water and power running. That’s the difference between a data breach and a service outage. The thirty-plus U.S. water systems hit across seven states in July show what happens without it.

This happened the same day Germany blamed Russia for a drone strike at Leipzig/Halle airport and saboteurs hit two power substations. I don’t think the attacks are connected, but the operating environment for municipal utilities has changed. Landsberg follows GSW Kamen in June and Windsbach in July.

Article 34 of the General Data Protection Regulation (GDPR) requires notifying affected individuals only when the risk to them is high. Landsberg issued one six days after the encryption.

Ransomware crews want the data. Nation-state actors want the infrastructure. A municipal utility serving one Bavarian town is expected to defend against both.

Noelle Murata, Chief Operating Officer, Xcape, Inc.

A ransomware event against a municipal utility managing electricity, water, wastewater treatment, district heating, and fiber connectivity highlights the multifaceted risk exposure facing regional infrastructure providers. While Stadtwerke Landsberg successfully isolated its operational technology (OT) environment to keep core public services running, central administrative IT systems were encrypted, leaving staff without routine communication tools and raising immediate data exfiltration concerns. The good news is that essential utility delivery remained online during this incident; the bad news is that when multiservice utilities succumb to compromise, the potential failure modes multiply rapidly across a community. The precise initial entry vector and the extent of customer data theft remain unconfirmed.

This incident arrives as German authorities pivot toward a fundamentally proactive cyber posture. Spurred by domestic political activism from anti-fossil fuel movements and internal extremism, along with heightened external threats following the Russian invasion of Ukraine, Germany recently updated legislative frameworks to permit active cyber defense and offensive countermeasures. This reform transforms national strategy from a traditionally reactive stance to one focused on deepening intelligence around specific threat actors, disrupting attacker infrastructure, and deploying counter-intelligence.

Cybersecurity professionals have long debated the efficacy of active defense. As Germany operationalizes these new spy laws, defenders will closely monitor whether proactive disruption deters threat actors or simply accelerates adversarial tactics against critical infrastructure.

Her Critical Takeaways

  • Operational isolation preserved core municipal services at Stadtwerke Landsberg, but administrative IT encryption created severe communication disruptions and data breach risks.
  • German legislative reforms mark a major strategic shift from reactive defense to proactive cyber countermeasures and intelligence gathering against internal and external actors.
  • Security leaders must continuously validate active directory boundaries and cross-domain access controls to prevent administrative IT compromises from threatening operational networks.

Mark my words, something like this is coming to the USA soon. I say that because The CISA is about to be defunded leaving critical infrastructure undefended. Which is bad for everyone.

September Patch Tuesday Commentary From Fortra

Posted in Commentary with tags on September 8, 2026 by itnerd

By Tyler Reguly, Associate Director, Security R&D, Fortra

I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning. This is not a Microsoft specific problem… we see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key and gift cards for extra coffee for your admins would likely be appreciated.

Even though I think it is temporary and we will return to manageable Patch Tuesday’s, I think it’s important that we acknowledge our current normal. Specifically, have you considered your people and processes during what could easily be called trying times? This is a great time to consider if your processes are designed to handle major changes and potential patching bottlenecks. While the number of patches may not have increased greatly (due to cumulative updates), they have increased as we see more and more one-off patches. How do you handle those one-off patches that may require a manual reinstall of the software or the extraction of a zip file to a specific location to overwrite a vulnerable version? These last few months may have disrupted your normal processes, so this is a great time to step back and really look at them. Are there places for improvement? What about your people. How are they handling the current levels of patches and the tickets that those produce. Are they managing? Are they struggling? Have you even stopped to ask them?

It’s time to put our CISOs and CSOs on notice. How are you helping your teams through these difficult times? Are you eliminating soak tests because some public guidance has suggested ridiculously short patch timeframes? Does that put added stress on your teams because they don’t know what outages they may see as a result? If you’re doing this… STOP! Patches still need to be tested because not all vendors can be trusted and many have broken the trust they had previously gained. Test your patches before you deploy them. Then, think about your deployment. Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.

Right now, if you are in charge of teams managing patches, you are probably struggling with what to do. Support your team, be aware of the difficulties they face, and ask them how things can be improved. If you still prioritize based on CVSS, you are hurting your organization and your employees. If you are constantly flip-flopping as guidance changes, you are putting your organization at risk and jeopardizing employee happiness. You are essentially steering a ship through rough waters, and you need a steady hand to accomplish that. If you keep the ship on course, your team will be able to do the rest.

MikroTik routers have been pwned

Posted in Commentary on September 8, 2026 by itnerd

If you own a MikroTik router, bad news. You router is vulnerable to getting pwned:

Critical MikroTik authentication-bypass and privilege escalation vulnerabilities allow external attackers to seize control of routers via exposed SSH ports, and active exploitation is already underway. The manufacturer chose to issue a vaguely worded security update, even as 122,500+ MikroTik routers sit with SSH exposed.

MikroTik shipped RouterOS fixes on September 3rd, 2026, with release notes that mention only an “important security update.” The company strongly recommends an update, but provides no technical details.

For the first time ever, MikroTik also sent users a push notification through its app to alert them about the update.

“To give time to update your systems, we are not currently publishing detailed information,” the security advisory reads.

Larry Pesce, VP of Services, Finite State (https://www.linkedin.com/in/larrypesce)

“The interesting thing about MikroTik isn’t the CVE chain itself, it’s what it says about where attackers keep choosing to point their effort. This is a very old argument dressed up in new CVEs. Network infrastructure was the original attack surface, back when worms and DNS cache poisoning and route hijacking were the front page news. Then defenders hardened the perimeter, and attackers moved to the endpoint: client-side exploits, macros, phishing. Then EDR got good at watching endpoints, and attackers moved again, first to cloud and identity, then to the explosion of IoT and connected devices that nobody was watching at all.

“Now the pendulum is swinging back toward infrastructure. Edge appliances, VPN gateways, and routers like these MikroTik boxes are attractive again for exactly the reason they were attractive twenty years ago: almost nothing runs an agent on them, almost nobody patches them promptly, and almost nobody actually knows how many of them they have exposed to the internet.

“That last point is the one worth sitting with. Most organizations have spent the last decade building real inventory and telemetry for laptops and servers. Very few have done the same for the network gear sitting between those systems and the internet. A router doesn’t show up in your EDR console. It usually isn’t in the CMDB unless someone remembered to put it there. It gets touched during install and then left alone until something breaks. That is precisely the blind spot this kind of campaign is built to exploit, and it’s also why 120,000 exposed devices is a plausible number rather than a shocking one. Nobody set out to leave that many boxes reachable on purpose. It’s an accumulation of the same basic inventory gap, repeated at scale.

“There’s also a targeting-philosophy shift worth naming. Compromising a router at scale isn’t usually about that one router. It’s about building a broad, disposable base, proxy points, relay infrastructure, a wide net of footholds, rather than a single surgical intrusion into one high-value target. That’s a different economic model than the supply-chain-style precision compromise we talk about more often, and it changes what ‘defense’ needs to look like.

“You’re not trying to stop one determined actor from reaching one target. You’re trying to avoid being one anonymous node in somebody’s infrastructure, which is a numbers game, and numbers games get won or lost on unglamorous things like patch cadence and knowing what you actually have exposed.

“None of this is new. It’s the same swing the industry has made every few years: infrastructure, then endpoint, then cloud, then device, and back to infrastructure again, each time landing wherever defenders most recently stopped paying attention.

“The lesson isn’t really about MikroTik. It’s that ‘know your inventory’ never stopped being step one, and the network layer is overdue for the same rigor we finally applied to endpoints.”

If you have one of these routers, update now. If you can’t update it, toss it and get a new one. Because you can bet that the bad guys are trying to pwn everything that they can.

A misconfigured database exposed 220 million traveler records tied to Vietnam

Posted in Commentary with tags on September 8, 2026 by itnerd

Security researchers found an exposed Elasticsearch cluster holding roughly 220.7 million passenger and crew records from a Vietnam-linked Advance Passenger Information System, spanning January 2017 through April 2026, reachable through a cloud-based path that accepted default credentials. Singapore Airlines’ security team helped coordinate the response, and the database was secured June 8, five days after researchers reported it, with no confirmed evidence anyone malicious got there first.

More details here: Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

Jason Brown, Director of Customer Advisory Counter Fraud Lead, iCOUNTER had this to say:

“A passport number tied to a name, date of birth, and travel history is a complete identity kit, not a fragment. Stolen card numbers get frozen the moment a bank flags fraud. A passport record doesn’t expire that way. It stays useful for building a synthetic identity or supporting document fraud years after the original trip happened, which is why nine years of records sitting in one place matters more than the headline number suggests. Fraud is only half of it. Nation-state actors use exactly this kind of collection to track individuals of interest and their movement for espionage and other targeting. Travel history at this depth is a pattern of life record, not just an identity record. 

What actually got this database exposed is almost mundane compared to what was in it. Direct access to the cluster was locked down, a second cloud path was not, and that one accepted default credentials. It is the same failure I chased for years on the law enforcement side, someone secures the route they built and never finds the one they inherited, and the route nobody documented is still running the password it shipped with. The good news here is narrower than the headlines suggest. 

Researchers reported and it was secured within five days. That is not the same as knowing nobody else got there first, as there were no server logs and scanning platforms had the host indexed as a database years before anyone reported it. But a system like this is not Vietnam’s exposure alone. Every airline that fed passenger data into it, and every country whose citizens transited through, inherited that risk the moment it was accessible, whether or not anyone malicious got there first. The response should be the same as if this had been confirmed stolen: assume the exposure window was real, and go check what else in your own vendor chain is reachable by a path nobody documented and a password nobody rotated.”

This would be a really good time to check to see if you have the same issues. Because you do not wish to be sitting on a ticking time bomb now would you.

FortiGate Post-Exploitation RAT, PivotC2 Spotted by SOCRadar

Posted in Commentary with tags on September 8, 2026 by itnerd

The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon. Successful exploitation delivers PivotC2, a Node.js RAT designed specifically as a FortiGate post-exploitation tool. PivotC2 supports features such as interactive shells, tunneling, network scanning, and configuration harvesting.

Based on the observed inline comments and usage guidance, the actors highly likely leveraged AI to develop the RAT. Active exploitation has been observed since at least July 2026 and is still ongoing. The threat actors targeted more than 30,000 IP addresses, leading to the exploitation and infection of 178 devices with PivotC2.

For full details, the analysis of this post-exploitation RAT can be read here: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/

August Ransomware Attacks Hit Record-Breaking High Says Comparitech

Posted in Commentary with tags on September 8, 2026 by itnerd

Comparitech researchers today published a study looking at August 2026 ransomware, finding that last month saw a record-breaking high for attacks at 32 attacks per day.

Key findings for August 2026

  • 997 attacks in total — 77 confirmed attacks (confirmed by the entity involved)
  • Of the 77 confirmed attacks:
    • 49 were on businesses
    • 18 were on government entities
    • 8 were on healthcare companies
    • 2 were on educational institutions
  • Of the 920 unconfirmed attacks*:
    • 812 were on businesses
    • 21 were on government entities
    • 61 were on healthcare companies
    • 22 were on educational institutions
  • The most prolific ransomware gangs were Qilin (157) and The Gentlemen (107)
  • Qilin had the most confirmed attacks (12), followed by The Gentlemen (8)
  • The US saw the most attacks (417), followed by Germany and Italy (48 each), the UK (36), and Canada (35)

Commenting on this study is Rebecca Moody, Head of Data Research at Comparitech

“Ransomware threats are escalating across most sectors and continue to have a devastating impact on those affected. One of August’s key attacks was on the government of Berlin, Germany. While the state government should be applauded for not meeting Rhysida’s ransom demand ($2.3M), the ransom looks set to be a drop in the ocean when compared to the costs the government is likely to face. Some recent statements suggest the computer rebuild could cost as much as €100 million (USD $116M) and the breach of over 1 million files is rumored to be the biggest state-level data breach in Germany to date.

Data relating to critical infrastructure is also believed to have been included in the Berlin breach. This, and the jump in attacks on utility companies, healthcare providers, manufacturers, and tech and finance companies, highlight how critical infrastructure remains a key target for hackers. By targeting these sectors, hackers are not only causing mass disruption by encrypting systems but they’re also gaining access to highly sensitive data, including personal data and information about critical systems and infrastructure.”

The full research can be read here: https://www.comparitech.com/news/ransomware-roundup-august-2026/

Focal AI Launches Agentic AI Platform for Canadian Wealth Management

Posted in Commentary with tags on September 8, 2026 by itnerd

Focal AI, the agentic AI platform purpose-built for Canadian financial advisors, today launched a set of AI agents that complete administrative work beyond meeting automation. The new Focal AI platform introduces new agentic AI capabilities which autonomously read and fill forms, read and draft emails, build client deliverables, and update your client data across advisor CRMs.

The launch addresses a critical bottleneck in Canadian wealth management. Advisors spend more than half their working time, over 20 hours a week, on non-revenue-generating administrative manual tasks across too many tools.

Focal AI is already used by advisors across major Canadian wealth networks like Financial Horizons and integrates with CRMs they rely on, including Equisoft, Maximizer, Laylah, Cloven, and more. The new agentic capabilities extend those integrations from moving information between systems to helping complete the workflows themselves.

Scale Advisor Productivity through Agentic Workflow Automation

Focal AI now expands beyond AI note-taking and meeting prep with agentic AI that automates back-office processes. The Focal AI agentic platform can embed natively inside broker-dealer infrastructure and the modern wealth firm technology stack:

  • Core Platform: Delivers time savings for advisors through AI note-taking, meeting preparation briefs, automated CRM syncing, and performance coaching.
  • Agentic AI Workflows: The Focal AI agent processes documents, emails, creates deliverables, and completes admin work advisors currently handle by hand, both inside of Focal and across other websites.

Key Capabilities of Focal’s Agentic AI

The admin overhead that fills an advisor’s evenings are now generated from the conversation itself:

  • Client-facing documents. Personalized follow-up emails, meeting recaps, discovery summaries, and client proposals, drafted in the advisor’s own voice and tone.
  • Email drafts and replies. Draft emails directly in your inbox, contextually from your email history with your clients.
  • Onboarding and account paperwork. KYC documentation, account opening forms, and custodial transition packages, can be uploaded and filled from client conversations directly.
  • Financial planning updates. More than 400 Conquest fields auto-filled after every conversation, covering family details, income, accounts, liabilities, expenses, and planning goals across retirement, education funding, and major purchases.
  • CRM and compliance records. Contact and household records, activity notes, task assignment, and audit-ready documentation pushed into the firm’s existing systems.
  • Edit outputs through chat. Chat with the Focal AI Agent to let it make direct edits to client presentations, notes, draft emails, and more.

In practice, that means advisors walk into every meeting fully prepped, with client history and open tasks already pulled together. Notes get captured and CRM records update automatically as they move from call to call. Work to be completed across client materials like proposals, and paperwork to be filled with client information are instant, instead of buried across five different systems, freeing up hours for the work to grow a practice.

Built for Canadian Wealth Management & Institutional Security

Focal AI is built on Microsoft Azure infrastructure in Canada, with client data remaining within Canadian data residency boundaries. Focal uses stateless AI architecture and does not use consumer AI application models such as ChatGPT or Claude. Focal also uses visible meeting participation rather than hidden botless transcription, helping firms maintain clear consent practices and giving advisors and clients transparency when AI is present in a conversation. The platform is SOC 2 Type II compliant and designed for the privacy, security and compliance requirements of Canadian financial institutions.

Focal AI’s Agentic platform is available today across Canada. To learn more, visit www.meetwithfocal.com

Nikon is Developing Firmware Version 2.00 for the Nikon ZR Full-Frame Sensor Camera 

Posted in Commentary with tags on September 8, 2026 by itnerd

Nikon Canada Inc. is pleased to announce the development of firmware version 2.00 for the Nikon ZR (released in October 2025), a full-frame sensor camera in the Z CINEMA series.

The following features are planned for inclusion in this firmware update, with the aim of further advancing creative capabilities and workflows for a broad range of users, from high-end filmmakers to content creators.

  • Support for Log3G10 and REDWideGamutRGB when recording in H.265 format, delivering compact file sizes with high colour-grading latitude.
  • A new option for selecting the level of [High ISO NR] available during H.265 Log recording, enabling image rendering tailored to the creator’s intent and the tone of the work.
  • Support for focus peaking display during recording in the R3D NE* format, enabling more precise focus confirmation.

Firmware version 2.00 is scheduled for release in 2026.

Nikon is also developing new firmware to support frequently requested features, including open gate recording and a desqueeze display for use with anamorphic lenses, with the goal of incorporating them in ZR firmware in 2027.

Additionally, RED is updating its remote-control applications, RED CONTROL and RED CONTROL PRO which will enable remote control capabilities for ZR.

Nikon and RED will continue to enhance its products through firmware updates that address user needs, while also contributing to the development of imaging culture in the field of cinema.