Skip to content

Adam Field

Breaches

N-able N-central auth-bypass flaw is under active exploitation; customers told to verify 2026.3.1.7

N-able’s N-central RMM platform is under active exploitation through an authentication-bypass flaw, with Huntress reporting multiple affected organizations and observed follow-on activity including reconnaissance, process-list requests, and abuse of the Take Control remote-access feature on downstream hosts. N-central is a remote monitoring

By Adam Field Source: Badtech.org
Breaches · Vulnerabilities · Radar

Breaches

Water utility cyber incidents across at least seven U.S. states disrupted monitoring and control across at least seven U.S. states

CBS News, NBC News, and CNN Newsource via KEYT reported that the FBI and EPA said water and wastewater utilities in at least seven U.S. states experienced malicious cyber incidents, with some activity degrading operations. The reporting says the activity targeted internet-facing programmable logic controllers, or PLCs, which

By Adam Field Source: Badtech.org
Breaches · Radar

Radar

Broadcom patches critical VMware vCenter and ESXi flaws including auth bypass, RCE, and VM escape

Security Affairs, Mallory.ai, and Field Effect reported that Broadcom released patches on July 29 for five VMware vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion, including three rated critical. They said the most severe issue, CVE-2026-59309, is a critical vCenter authentication bypass rated CVSS 9.8, and that

By Adam Field Source: Badtech.org
Radar · Vulnerabilities