Cybersecurity Weekly Briefing, 5-11 september
N-able issues an emergency hotfix for a critical RCE vulnerability in N-central that is currently being exploited
N-able has released an emergency hotfix for CVE-2026-86218 (CVSSv4.0 10.0 according to N-able), a static code injection vulnerability in N-central, its remote monitoring and management (RMM) platform widely used by managed service providers (MSPs), which allows an unprivileged attacker to execute malicious code on unpatched instances exposed to the internet, with low attack complexity.
Shadowserver has identified around 1,500 exposed N-central servers, mainly in the United States and Europe. The company recommends updating immediately to N-central 2026.3 Hotfix 4, as systems that have only applied the previous hotfix (HF3) remain vulnerable.
N-central’s history as a recurring target for exploitation (as was the case a year ago with two other CVEs) underscores the urgency of this update for any MSP with on-premises instances.
The PREY-0058 campaign steals data from senior executives through vishing and session hijacking
Arctic Wolf has uncovered a data theft and extortion campaign, PREY-0058, which impersonates an internal IT support service through vishing calls specifically targeting executives in the construction, healthcare, property, finance and professional services sectors. The operators direct victims to malicious domains that lead to an adversary-in-the-middle attack against Microsoft 365, capturing credentials and MFA approvals to steal authenticated session tokens, which are then replicated via residential proxy infrastructure (NodeMaven) geolocated near the victim.
Arctic Wolf notes significant overlaps with the actor UNC6671. Following initial access, systematic reconnaissance takes place on SharePoint and Entra ID, followed by mass data exfiltration from SharePoint, OneDrive, Exchange and Box prior to the extortion demand, without deploying malware on the endpoint. It is recommended to implement phishing-resistant MFA, conditional access policies and specific helpdesk training to counter vishing.
BYOTC: a new technique for exploiting trusted drivers in Windows
Researchers at Xusheng have documented ‘Bring Your Own Trusted Caller’ (BYOTC), a technique that extends the well-known ‘Bring Your Own Vulnerable Driver’ (BYOVD) without requiring a memory corruption vulnerability in the driver itself. Instead of loading a signed, vulnerable driver, the attacker compromises or manipulates the legitimate user-mode application that the privileged driver already trusts, turning it into a ‘confused deputy’ at the user/kernel boundary.
The documented case against Malwarebytes Chameleon’s driver ‘mbamchameleon.sys’ demonstrates how an attacker with administrator privileges can inject code into the legitimate signed process, register it as a trusted client, and instruct the driver to terminate security processes such as Microsoft Defender. This technique is particularly relevant for EDR, antivirus and endpoint management products that expose privileged kernel operations by relying solely on the signature of the invoking binary.
It is recommended to anchor the chain of trust in Windows-hardened protections (Protected Process Light) rather than relying solely on signature check.
Microsoft patches 974 vulnerabilities in its biggest ever Patch Tuesday, including two actively exploited 0-day
Microsoft has patched 974 vulnerabilities in its September update, the largest batch of patches released by the company to date. Among them are two 0-day vulnerabilities that were actively exploited prior to their disclosure:CVE-2026-81963 and CVE-2026-85880, both rated CVSSv3 7.8 by Microsoft, which allow privilege escalation on Windows. The first affects the Windows Update Stack (a critical component for installing updates), whilst the second affects Windows Advanced Local Procedure Call, and both have been added to CISA’s KEV catalogue of exploited vulnerabilities.
The exceptional volume of patches brings the total number of vulnerabilities published by Microsoft in 2026 to over 2,600 and reflects the widespread adoption of AI-assisted code analysis tools.
ShieldCrash: new PoC bypasses the patch for the ShieldBreak vulnerability in Microsoft Defender
The researcher known as Nightmare Eclipse has published a new proof-of-concept, called ShieldCrash, which bypasses the patch applied to ShieldBreak (CVE-2026-69414, CVSSv3 7.8 according to Microsoft), the Microsoft Defender vulnerability that he himself reported last month. According to the researcher, Microsoft closed several attack vectors to prevent ShieldBreak from being re-exploited, but left open a specific condition that allows the same issue to be reproduced: an arbitrary file read with SYSTEM privileges, confirmed on the latest version of Windows with all updates applied.
The original flaw was patched in version 1.1.26080.3 of the Microsoft Malware Protection Engine, which is distributed via automatic updates and requires no user intervention unless this feature is disabled. In recent weeks, Nightmare Eclipse has published similar proof-of-concepts (PoCs) targeting CrowdStrike Falcon (FalconFlank), Kaspersky (HardBreacher) and Avast (PrettyPrague); only the latter two have been fixed by their manufacturers so far.
It is recommended to check that automatic updates for the protection engine are enabled and to monitor for the release of an official patch for ShieldCrash.
◾ This newsletter is one of the deliverables of our Operational and Strategic Intelligence service. If you are interested in knowing the rest of the Operational and Strategic Intelligence contents included in the service, please contact us →
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities