Daily cybersecurity intelligence digest from CyberNetSec.io - September 7, 2026
📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Zero-Days in CrowdStrike, Avast, Nvidia Disclosed
A security researcher known as 'Nightmare Eclipse' has publicly released proof-of-concept exploits for three unpatched local privilege escalation (LPE) zero-day vulnerabilities. The flaws, named 'FalconFlank', 'PrettyPrague', and 'GreenSection', affect CrowdStrike Falcon Sensor, Avast Antivirus, and Nvidia components, respectively. Each exploit allows a local attacker to gain SYSTEM-level privileges. CrowdStrike has issued interim guidance, while Avast's parent company reports a fix has been deployed.
2. N-able N-central CVSS 10.0 RCE (CVE-2026-86218)
N-able is urging on-premises customers to immediately apply an emergency hotfix for its N-central RMM platform to address a critical, actively exploited zero-day. The vulnerability, CVE-2026-86218, is a pre-authentication RCE with a 10.0 CVSS score. It allows unauthenticated attackers to gain full control of N-central servers, creating a severe supply chain risk for MSPs and their clients. This is the fourth emergency patch N-able has issued in five weeks for its RMM product.
3. StyleSmuggler RCE Hits Magento, Adobe Commerce
An unpatched, unauthenticated RCE zero-day vulnerability named 'StyleSmuggler' is being actively exploited to compromise e-commerce sites running Magento Open Source and Adobe Commerce. Discovered by Sansec, the attack leverages the GraphQL endpoint and the template system to inject a backdoor. The flaw affects all current versions, including fully patched instances. With no official patch available, administrators are urged to disable GraphQL if unused and scan for compromise.
4. Research Details New Lazarus Group Structure
New joint research from Sekoia and Kudelski Security reveals that North Korea's state-sponsored cyber operations, broadly attributed to the Lazarus Group, are organized into six distinct clusters. These specialized units, mostly operating under the GRIB intelligence bureau, focus on separate missions including espionage, financial theft, and sanctions evasion. The report highlights the division of the former APT38 into clusters like CryptoCore and Jade Sleet, which now target the cryptocurrency and Web3 sectors.
5. MikroTik Routers Under Attack via SSH Flaws
Attackers are actively exploiting an unauthenticated exploit chain called 'MikroTrick' to gain full administrative control of MikroTik routers with SSH exposed to the internet. The attack, observed by CERT Polska since at least September 2, combines an SSH authentication bypass (CVE-2026-67276) and a privilege escalation flaw (CVE-2026-86060). MikroTik has released patches for RouterOS, and administrators are urged to update immediately and check for signs of compromise, such as a user named 'ops'.
6. CISA Retires Six Critical Infrastructure Assessments
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is retiring six of its free, hands-on cybersecurity assessment services for critical infrastructure operators. The move, which CISA attributes to reducing redundancy and improving efficiency, will shift organizations towards self-service tools like the Cybersecurity Performance Goals (CPGs). Critics express concern that this removes a vital resource for under-resourced entities like water utilities and hospitals, especially as new mandatory reporting rules under CIRCIA are finalized.
7. Vishing Campaign Targets M365 Executive Accounts
A data theft and extortion campaign, tracked as PREY-0058, is targeting corporate executives using a sophisticated attack chain. Attackers use voice phishing (vishing) to impersonate IT help desks, directing victims to an adversary-in-the-middle (AitM) phishing site to steal Microsoft 365 session tokens. The group then uses residential proxies to access cloud accounts (SharePoint, OneDrive) and exfiltrate data for extortion. The campaign shows overlaps with the threat actor UNC6671.
8. Check Point Details Multiple Data Breaches
Check Point's latest intelligence report highlights several major security incidents. Thomson Reuters disclosed a breach of its C-Track court management platform, affecting courts in the U.S. and Canada. Separately, Baylor Genetics revealed a breach impacting 2.8 million individuals, exposing sensitive medical and personal data. The report also covers a cyberattack that shut down Slovenian casino operator Hit and an AI-assisted ransomware attack that compromised an enterprise in under 10 hours.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)