Here are today’s top cybersecurity stories for Monday, September 7, 2026.
N-able Ships Fourth Emergency Hotfix in Five Weeks for Max-Severity N-central Flaw
N-able released Hotfix 4 for N-central 2026.3, addressing CVE-2026-86218, an unauthenticated remote code execution flaw rated 10.0 on the CVSS scale. The fix marks the fourth emergency patch to the remote monitoring and management platform in five weeks, and the company’s own release notes conflict on whether exploitation has reached production environments. Shadowserver tracks nearly 1,500 internet-exposed N-central servers, most located in the United States and Europe. BleepingComputer | The Hacker News
CISA Adds Seven Flaws to KEV Catalog as Attackers Deploy Reverse Shells and Crypto Miners
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, spanning SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and BerriAI LiteLLM. Threat actors are using the flaws to mint admin tokens, deploy reverse shells and cryptocurrency miners, and harvest credentials, with one exploitation chain tied to the Qilin ransomware group. The Hacker News
“MikroTrick” Attack Chain Hijacks MikroTik Routers Without Authentication
CERT Polska identified an attack chain combining CVE-2026-67276 and CVE-2026-86060, two critical SSH flaws in MikroTik RouterOS each rated 9.2 on the CVSS scale, granting full administrative control on devices with SSH exposed to the internet. Exploitation has been under way since at least September 2, and MikroTik shipped fixes across every release channel on September 3. The Hacker News | Help Net Security
Attackers Spread Malware Through ScreenConnect File Transfer Sessions
ConnectWise warned of an unpatched flaw in ScreenConnect’s guest file transfer feature affecting both cloud and on-premise deployments, with a CVE identifier and official fix expected within the week. Huntress researchers observed rogue ScreenConnect clients used in social-engineering attacks to spread VBScript payloads with worm-like propagation to newly connected machines. Help Net Security | BleepingComputer
Mathspace Discloses Breach Affecting More Than 1 Million Students, Staff, and Parents
Online learning platform Mathspace confirmed attackers accessed its self-hosted Metabase reporting system and exfiltrated data belonging to 1,079,819 students, staff, and parents. Attackers exploited a critical Metabase vulnerability four days after a patch became available, and Mathspace did not update its own installation until weeks later. BleepingComputer
Trezor Breach at Former Shipping Partner Widens to 67,000 More US Customers
Hardware wallet maker Trezor disclosed a breach at former shipping partner ShipMonk exposing names, emails, phone numbers, addresses, and order numbers for an additional 67,000 US customers from a partnership period between 2019 and 2021. ShipMonk’s Metabase installation was compromised through a zero-day SQL injection flaw, and researchers link the intrusion to the ShinyHunters extortion group. The Hacker News
JSCeal Malware Bypasses Google Authentication Using Stolen Session Cookies
Check Point Research detailed JSCeal, a credential-harvesting malware family compiled into V8 JavaScript bytecode to resist reverse engineering. The malware steals saved passwords and cookies from eight Chromium-based browsers, replays stolen Google session cookies to bypass authentication, and installs an attacker-controlled certificate to intercept HTTPS traffic. The Hacker News
Settra Ransomware Group Claims Canadian Safety-Supply Distributor
The Settra ransomware group listed Hansler Smith Limited, a 100% Canadian-owned distributor of PPE, workwear, and industrial supplies based in Brockville, Ontario, on its extortion leak site. The group claims roughly 37 GB of exfiltrated data taken in an intrusion estimated to have begun in late August. Hansler Smith has issued no public statement confirming the incident. DeXpose
CISA, FBI, and Canadian Centre for Cyber Security Issue Joint Outage Communications Guidance
CISA, the FBI, and cyber agencies from Canada, Australia, New Zealand, and the United Kingdom published joint guidance titled “Communicating Under Pressure: Best Practices for Service Providers.” The guidance directs organizations to build outage communications plans with predefined thresholds, named incident and communications leads, and tested backup channels ahead of a cyberattack or service disruption. CISA
Stay tuned for today’s in-depth analysis posts.






