Cybersecurity Intelligence Report — 2026-08-04

CRITICAL SECTION

[10]
[CISA KEV] CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability - N-able N-central (CISA KEV)
CVEs: CVE-2026-18577

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability - N-able N-central. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-06

[10]
[RANSOMWARE] dragonforce leaked TUI China (ransomware.live/dragonforce)

Victim: TUI China | Group: dragonforce | Website: tui.cn | Country: CN | Details: An affiliate of TUI Group, the world's number one leisure tourism business, TUI China was established in late 2003 as the first joint venture with foreign majority share in the Chinese tourism industry. Passports, visas, internal documentation, legal and financial documents, etc.

CISA KEV (last 14 days)

CVEVendor/ProductScoreRequired Action
CVE-2026-18577[CISA KEV] CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability - N-able N-central10N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability - N-able N-central. Required action: Apply mitigations in accordance with vendor instruction

RANSOMWARE VICTIMS (today)

dragonforce: [RANSOMWARE] dragonforce leaked TUI China, [RANSOMWARE] dragonforce leaked Baicizhan
incransom: [RANSOMWARE] incransom leaked clintonhealthaccess.org, [RANSOMWARE] incransom leaked Oleoductos del Valle
qilin: [RANSOMWARE] qilin leaked Universitatea De Vest Vasile Goldi Din Arad, [RANSOMWARE] qilin leaked Service Electric, [RANSOMWARE] qilin leaked Freedom Claims Management
safepay: [RANSOMWARE] safepay leaked pradotuylaw.com, [RANSOMWARE] safepay leaked naskdoorinc.com, [RANSOMWARE] safepay leaked new-point.it, [RANSOMWARE] safepay leaked simonrack.com, [RANSOMWARE] safepay leaked hanan-hov.co.il, [RANSOMWARE] safepay leaked azn.co.jp, [RANSOMWARE] safepay leaked southshorerecycling.com, [RANSOMWARE] safepay leaked cpu-ag.com, [RANSOMWARE] safepay leaked multiaqua.com
anubis: [RANSOMWARE] anubis leaked BLACKBURN'S, [RANSOMWARE] anubis leaked Cameron Regional Medical Center, [RANSOMWARE] anubis leaked Winn-Dixie
ransomhouse: [RANSOMWARE] ransomhouse leaked PCL Holding
akira: [RANSOMWARE] akira leaked Albers Mechanical Contractors, [RANSOMWARE] akira leaked Belasco Electric
lockbit5: [RANSOMWARE] lockbit5 leaked sirsa.it, [RANSOMWARE] lockbit5 leaked sms-sme.com, [RANSOMWARE] lockbit5 leaked adventusasia.com, [RANSOMWARE] lockbit5 leaked pcclimitedindia.com, [RANSOMWARE] lockbit5 leaked delkartindustries.com, [RANSOMWARE] lockbit5 leaked micropack.com.ar, [RANSOMWARE] lockbit5 leaked setic-pourtier.com, [RANSOMWARE] lockbit5 leaked microphase.com, [RANSOMWARE] lockbit5 leaked rai.com.br
payload: [RANSOMWARE] payload leaked Hans & Jos. Kronenberg GmbH

NEWS

[8]
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code (TheHackerNews)

Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. "These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the

[7]
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users (TheHackerNews)

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package

[7]
N‑able Patches Vulnerability Exploited to Hack N-central Servers (SecurityWeek)

<p>The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.</p> <p>The post <a href="https://www.securityweek.com/n-able-patches-vulnerability-exploited-to-hack-n-central-servers/">N‑able Patches Vulnerability Exploited to Hack N-central Servers</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

[7]
[RANSOMWARE] dragonforce leaked Baicizhan (ransomware.live/dragonforce)

Victim: Baicizhan | Group: dragonforce | Website: www.baicizhan.com | Country: CN | Details: Baicizhan is a language learning platform specializing in English instruction. It offers a wide range of tools and resources designed to help users overcome the challenges of learning English.

[5]
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts (BleepingComputer)

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]

[5]
N-able warns of N-central auth bypass flaw exploited in attacks (BleepingComputer)

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]

[5]
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws (TheHackerNews)

The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per

[5]
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete (TheHackerNews)

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform

[5]
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking (SecurityWeek)

<p>Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.</p> <p>The post <a href="https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/">Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

[5]
Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) (HelpNetSecurity)

<p>Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered &#8220;On July 31, 2026, N‑able saw an increase in licensing issues for our on-premises N‑central customers. Licensing issues are not uncommon, but the volume was high and the engineering and security teams were engaged,&#8221; N-able sha

[5]
[RANSOMWARE] incransom leaked clintonhealthaccess.org (ransomware.live/incransom)

Victim: clintonhealthaccess.org | Group: incransom | Website: clintonhealthaccess.org | Country: US | Details: This Clinton foundation sponsors the sterilization of women in Africa and South America. With the help of this foundation, organs harvested criminally by transplant surgeons from people in Third World countries are legalized to improve the quality of life of the rich in capitalist countries, includ

[5]
[RANSOMWARE] incransom leaked Oleoductos del Valle (ransomware.live/incransom)

Victim: Oleoductos del Valle | Group: incransom | Country: AR | Details: During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include: 1.HR documentation: full payroll data, bank account details (CBU), employee health insurance records (OSDE, SWISS MEDICAL), as well as severanc

[5]
[RANSOMWARE] qilin leaked Universitatea De Vest Vasile Goldi Din Arad (ransomware.live/qilin)

Victim: Universitatea De Vest Vasile Goldi Din Arad | Group: qilin | Website: www.uvvg.ro | Country: RO | Details: N/A

[5]
[RANSOMWARE] safepay leaked pradotuylaw.com (ransomware.live/safepay)

Victim: pradotuylaw.com | Group: safepay | Website: pradotuylaw.com | Country: US | Details: The firm focuses on practice areas including personal injury, wrongful death, workplace harassment, business litigation, civil settlements, and environmental litigation. …

[5]
[RANSOMWARE] safepay leaked naskdoorinc.com (ransomware.live/safepay)

Victim: naskdoorinc.com | Group: safepay | Website: naskdoorinc.com | Country: US | Details: Headquartered in West Chester, Pennsylvania, the company has served customers throughout southeastern Pennsylvania and northern Delaware for several decades. Although …

[5]
[RANSOMWARE] safepay leaked new-point.it (ransomware.live/safepay)

Victim: new-point.it | Group: safepay | Website: new-point.it | Country: IT | Details: Headquartered in Signa, Florence, Italy, the company was founded in 2006 and has grown into one of Italy's established suppliers …

[5]
[RANSOMWARE] safepay leaked simonrack.com (ransomware.live/safepay)

Victim: simonrack.com | Group: safepay | Website: simonrack.com | Country: ES | Details: Headquartered in Alfamén, Zaragoza, Spain, the company has been manufacturing metal shelving since 1964 and has become one of Europe's …

[5]
[RANSOMWARE] safepay leaked hanan-hov.co.il (ransomware.live/safepay)

Victim: hanan-hov.co.il | Group: safepay | Website: hanan-hov.co.il | Country: IL | Details: Headquartered in Neve Yamin, Israel, the company provides comprehensive logistics support for construction, infrastructure, industrial, and commercial projects throughout the …

[5]
[RANSOMWARE] anubis leaked BLACKBURN'S (ransomware.live/anubis)

Victim: BLACKBURN'S | Group: anubis | Website: blackburnsmed.com | Country: US | Details: Major home healthcare provider data breach.

[5]
[RANSOMWARE] anubis leaked Cameron Regional Medical Center (ransomware.live/anubis)

Victim: Cameron Regional Medical Center | Group: anubis | Website: cameronregional.org | Country: US | Details: Patient and employee data breach at a healthcare provider.

[5]
[RANSOMWARE] safepay leaked azn.co.jp (ransomware.live/safepay)

Victim: azn.co.jp | Group: safepay | Website: azn.co.jp | Country: JP | Details: Founded in 1991, the company specializes in comprehensive asset management, inheritance planning, business succession consulting, real estate advisory services, and …

[5]
[RANSOMWARE] safepay leaked southshorerecycling.com (ransomware.live/safepay)

Victim: southshorerecycling.com | Group: safepay | Website: southshorerecycling.com | Country: US | Details: The company specializes in metal recycling, concrete and asphalt recycling, aggregate production, and construction waste processing for commercial, industrial, and …

[5]
[RANSOMWARE] safepay leaked cpu-ag.com (ransomware.live/safepay)

Victim: cpu-ag.com | Group: safepay | Website: cpu-ag.com | Country: DE | Details: Founded in 1981 and headquartered in Friedberg, Bavaria, the company has more than four decades of experience developing specialized software …

[5]
[RANSOMWARE] safepay leaked multiaqua.com (ransomware.live/safepay)

Victim: multiaqua.com | Group: safepay | Website: multiaqua.com | Country: US | Details: Founded in 1999, the company specializes in the design, engineering, and production of air-cooled water chillers, heat pump chillers, hydronic …

[5]
[RANSOMWARE] anubis leaked Winn-Dixie (ransomware.live/anubis)

Victim: Winn-Dixie | Group: anubis | Website: winndixie.com | Country: US | Details: Inside a multibillion-dollar retail giant.

[5]
[RANSOMWARE] ransomhouse leaked PCL Holding (ransomware.live/ransomhouse)

Victim: PCL Holding | Group: ransomhouse | Website: www.pclholding.com | Country: CA | Details: PCL Holding Public Company Limited is a Thai-based holding entity operating as a premier importer and distributor of diagnostic instruments, reagents, and consumables for medical and research laboratories. The company manages a comprehensive portfolio of products across hematology, chemistry, immuno

[5]
[RANSOMWARE] qilin leaked Service Electric (ransomware.live/qilin)

Victim: Service Electric | Group: qilin | Website: www.secv.com | Country: US | Details: N/A

[5]
[RANSOMWARE] akira leaked Albers Mechanical Contractors (ransomware.live/akira)

Victim: Albers Mechanical Contractors | Group: akira | Website: albersmechanicalcontractors.com | Country: US | Details: Albers Mechanical Contractors specializes in custom fabrication, welding, stainless steel fabri cation, and dust collection HVAC solutions. With over 54 years of experience, they provide desi gn and on-site consultations, positioning themselves as leaders in facility solutions. We will upload 30gb

[5]
[RANSOMWARE] akira leaked Belasco Electric (ransomware.live/akira)

Victim: Belasco Electric | Group: akira | Website: belascoelectric.com | Country: US | Details: Belasco Electric is a reliable electrical service provider based in Muskegon, Michigan, caterin g to both residential and commercial clients. They offer a wide range of services including eme rgency generator systems, fire alarm security systems, HVAC wiring, and EV installation. We will upload 16g

[5]
[RANSOMWARE] lockbit5 leaked sirsa.it (ransomware.live/lockbit5)

Victim: sirsa.it | Group: lockbit5 | Website: sirsa.it | Country: IT | Details: SIRSA operates in the field of processing and molding plastic materials, offering concrete, safe, an...

[5]
[RANSOMWARE] lockbit5 leaked sms-sme.com (ransomware.live/lockbit5)

Victim: sms-sme.com | Group: lockbit5 | Website: sms-sme.com | Country: RO | Details: SMS-SME is a global leader in marine cargo access and securing equipment, specializing in RORO equip...

[5]
[RANSOMWARE] lockbit5 leaked adventusasia.com (ransomware.live/lockbit5)

Victim: adventusasia.com | Group: lockbit5 | Website: adventusasia.com | Country: SG | Details: Adventus is a Top-Rated Information and Communications Technology (ICT) Solutions and Services Provi...

[5]
[RANSOMWARE] lockbit5 leaked pcclimitedindia.com (ransomware.live/lockbit5)

Victim: pcclimitedindia.com | Group: lockbit5 | Website: pcclimitedindia.com | Country: IN | Details: PIONEER COLDSTORE & CLADDING PVT. LTD. (PCC) is Leading Manufactures of insulated Panels for Coldsto...

[5]
[RANSOMWARE] lockbit5 leaked delkartindustries.com (ransomware.live/lockbit5)

Victim: delkartindustries.com | Group: lockbit5 | Website: delkartindustries.com | Details: Delkart Industries Limited specializes in manufacturing high-quality custom felts, automobile carpet...

[5]
[RANSOMWARE] lockbit5 leaked micropack.com.ar (ransomware.live/lockbit5)

Victim: micropack.com.ar | Group: lockbit5 | Website: micropack.com.ar | Country: AR | Details: Micropack is a well-known food and household goods distributor that has been serving businesses and...

[5]
[RANSOMWARE] lockbit5 leaked setic-pourtier.com (ransomware.live/lockbit5)

Victim: setic-pourtier.com | Group: lockbit5 | Website: setic-pourtier.com | Country: FR | Details: Consolidating gains and preparing the future, Setic, Pourtier C2S help you to stay ahead of the prod...

[5]
[RANSOMWARE] lockbit5 leaked microphase.com (ransomware.live/lockbit5)

Victim: microphase.com | Group: lockbit5 | Website: microphase.com | Country: US | Details: Microphase Corporation is an innovative and trusted customer-driven supplier of advanced electronic...

[5]
[RANSOMWARE] lockbit5 leaked rai.com.br (ransomware.live/lockbit5)

Victim: rai.com.br | Group: lockbit5 | Website: rai.com.br | Country: BR | Details: Grupo Rái is one of the largest independent communication groups in Brazil, consisting of six specia...

[5]
[RANSOMWARE] payload leaked Hans & Jos. Kronenberg GmbH (ransomware.live/payload)

Victim: Hans & Jos. Kronenberg GmbH | Group: payload | Website: kronenberg-gmbh.de | Country: DE | Details: Hans & Jos. Kronenberg GmbH is a German company founded in 1932 and based in Bergisch Gladbach. It specializes in the development and manufacturing of high-quality components for the elevator industry and mechanical engineering, including door locks, switches, control panels, and LED lighting.

[5]
[RANSOMWARE] qilin leaked Freedom Claims Management (ransomware.live/qilin)

Victim: Freedom Claims Management | Group: qilin | Website: www.freedomclaimsinc.com | Country: US | Details: N/A

SUMMARY

Summary

Total new items: 70
Critical items: 2
CISA KEV count: 1
Ransomware victim groups today: 9