Breaking News – Cyber Threats – 2026-09-07 03:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-07 03:00 PDT
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
The Hacker News • 2026-09-07 01:31 • thehackernews.com
Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able’s incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed.N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a
https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html - JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
The Hacker News • 2026-09-07 00:53 • thehackernews.com
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.“The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a
https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html - N-able patches max severity N-central flaw amid ongoing attacks
BleepingComputer • 2026-09-06 23:17 • www.bleepingcomputer.com
N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. […]
https://www.bleepingcomputer.com/news/security/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.