Daily Recap, Attackers are actively leveraging multiple critical vulnerabilities, including N-able N-central CVE-2026-86218, an Adobe Commerce zero-day, and new MikroTik RouterOS bugs, to achieve RCE, plant backdoors, and hijack routers. Meanwhile, ConnectWise ScreenConnect is facing a worm-like file-transfer campaign, researchers revealed Nightmare Eclipse targeting CrowdStrike, Nvidia, and Avast, and Trezor reported breach impact affecting 81,000 customers.
#CVE-2026-86218 #N-able #N-central #AdobeCommerce #MikroTik #RouterOS #ConnectWise #ScreenConnect #NightmareEclipse #CrowdStrike #Nvidia #Avast #Trezor #CCQ #SEP-2026
#CVE-2026-86218 #N-able #N-central #AdobeCommerce #MikroTik #RouterOS #ConnectWise #ScreenConnect #NightmareEclipse #CrowdStrike #Nvidia #Avast #Trezor #CCQ #SEP-2026
Critical Exploits
- Attackers are actively exploiting multiple high-severity flaws, including N-able N-central CVE-2026-86218, Adobe Commerce zero-day, and new MikroTik RouterOS bugs to gain RCE, backdoor online stores, and hijack routers. – N-central Zero-Day, RouterOS Flaws, Commerce Zero-Day
- ConnectWise ScreenConnect is facing fresh security issues, with a new unpatched flaw and reports of malware spread through file transfers and modified clients in a worm-like campaign. – ScreenConnect Flaw, File Transfer Malware, Worm-Like Campaign
- N-able released yet another hotfix for N-central, marking the fourth patch in five weeks as the max-severity flaw continues to be abused in the wild. – Fourth Hotfix, Ongoing Attacks
Threat Actors & Malware
- North Korean hackers deployed a new Linux espionage toolkit, adding to a broader wave of advanced intrusion tooling. – Linux Toolkit
- Researchers exposed Nightmare Eclipse, which is dropping zero-day exploits targeting CrowdStrike, Nvidia, and Avast. – Nightmare Eclipse
- Attackers are hiding phishing lures with invisible Unicode characters to make malicious messages harder to spot. – Unicode Phishing
Identity, Data & Fraud
- Trezor disclosed a data breach impact reaching 81,000 customers, widening the scope of the incident. – Trezor Breach
- UK account-hack losses are surging as new reporting rules reveal previously hidden cases and increase visibility into fraud. – UK Fraud Losses
Regional & Policy
- Russia is imposing new security requirements on data centers amid Ukraine-linked drone threats, reflecting rising infrastructure risk. – Russia Data Centers
Ransomware
- Commission de la construction du Quebec (CCQ) appears on a new ransomware incident tracker for SEP-2026. – CCQ Ransomware
AI & Security Tools
- OpenAI reached a new milestone toward self-improving AI by advancing research automation. – OpenAI Milestone
- ToolHive launched as an open-source way to run any MCP server more securely. – ToolHive