Security news.
Today's cybersecurity landscape is marked by active exploitation and significant data breaches. N-able has issued a critical patch for a vulnerability actively exploited in N-central servers, while several high-profile organizations, including Brinks Home and the UK's PNLD, have disclosed data breaches. Furthermore, critical infrastructure in the US, specifically water utilities, continues to be a target for cyberattacks.
N-able Patches Exploited N-central Vulnerability
N-able released a patch for CVE-2026-18577, an authentication bypass vulnerability in N-central that has been actively exploited to gain remote administrative access to customer systems after a patch bypass was discovered.
Brinks Home Discloses Data Breach
The physical security firm Brinks Home has announced a data breach, with hackers leaking files, though the company states its alarm monitoring and system functionality were not affected.
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese threat actor is targeting Apple iOS devices using a leaked DarkSword exploit kit, observed running over 100 fake AWS sign-in pages to deliver GHOSTBLADE.
SonicWall Vulnerabilities Exploited in Ransomware Attacks
The INC Ransomware gang has been exploiting recent SonicWall SMA1000 appliance vulnerabilities to gain root access and perform lateral movement within victim networks.
PNLD Breach Exposes U.K. Police and Government Contact Details
The Police National Legal Database (PNLD) in the UK has confirmed a data breach, leading to the publication of police, government, and customer contact information, including names, organizations, and work email addresses, on the dark web.
US Water Cyberattacks Extend Beyond Minnesota
Cyberattacks on US water systems, attributed to Iran-linked hackers, are no longer limited to Minnesota but have reportedly extended to at least six other states, including Michigan, South Dakota, and Georgia.
Thermo Fisher Patches DNA File Tampering Flaw
Thermo Fisher Scientific has patched CVE-2026-17583, a flaw in Applied Biosystems human identification software that could allow nearly undetectable alterations to DNA data files if laboratory controls are bypassed.
Hugging Face Diffusers Flaws Allow Arbitrary Code Execution
Three high-severity vulnerabilities in Hugging Face's Diffusers library could enable crafted model repositories to execute arbitrary code, bypassing the `trust_remote_code` safeguard and posing a risk to the AI supply chain.