| ~7 MIN READ |
|
Government systems, home appliances, and AI chat tools all had a rough week for the same reason: too much trust, not enough verification. Here's who paid for it, and what's finally forcing accountability.
PS — Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
VULNERABILITY
🔓 One Broken Patch Turned Into a Backdoor for Every Company an MSP Touches
Intro
N-able's fix for one authentication bypass in its N-central remote monitoring platform turned out to have its own authentication bypass, and attackers found it before most customers even finished patching.
What Happened
N-able disclosed an authentication bypass (CVE-2026-18576) affecting all versions of N-central prior to 2026.3, then attackers found a second bypass (CVE-2026-18577) in the very fix meant to close it. N-able confirmed active exploitation on August 1, shipped an emergency hotfix (2026.3.1.7) on August 2, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the next day. Once inside, attackers used N-central's own "Take Control" feature to reach managed endpoints and deployed a Cloudflare Tunnel for persistent remote access.
Why It Matters
N-central is remote monitoring and management software, meaning MSPs and corporate IT teams use it to control other companies' systems. A compromised N-central server doesn't just hurt N-able's direct customer, it can cascade into every downstream client that customer manages.
The Other Side
Hosted N-central deployments were patched automatically by N-able. The risk falls specifically on on-premise deployments that haven't manually applied the hotfix yet.
TL;DR: A second authentication bypass in N-able's N-central RMM platform is under active exploitation, threatening every company an MSP manages through it.
Further reading: BleepingComputer
|
|
Tax Prep with Confidence
Tax season doesn't have to mean wondering if you have the right forms, second-guessing your deductions, or scrambling to pull everything together before the deadline.
With BELAY’s Tax Prep Checklist, you can start preparing for tax season with confidence.
|
|
|
Stop Paying for 10 Tools. One AI Does It All.
Most e-commerce sellers are running their store across 6 to 10 separate tools — and spending more time managing software than growing their business. StoreClaw replaces your entire stack with one autonomous AI engine that monitors competitors, optimizes listings, automates marketing, and tracks real profit across Shopify, Amazon, and beyond.
It doesn't wait for you to ask. It runs 24/7 in the background, so you wake up to a full dashboard instead of a list of things you forgot to check.
Connect your store, and StoreClaw gets to work — no prompts, no complex setup, no six-app stack.
Free to start. No credit card required.
Strange but real
🧹 Your Robot Vacuum Was One Certificate Away from Spying on the Whole Neighborhood
Intro
SharkNinja's cloud-connected robot vacuums had a security hole that turned "clean the living room" into "broadcast the living room," and the company knew for months before doing anything about it.
What Happened
A researcher found that Shark robot vacuums shared AWS certificates so loosely that one compromised device could reach into other vacuums' systems in the same AWS region, exposing live camera feeds, home floor plans, and WiFi passwords stored in plaintext. SharkNinja was warned in March, went quiet for months, and only shipped a fix after the researcher published the details in mid-July. A 24-hour scan turned up 673,000 exposed devices in a single region.
Why It Matters
A vacuum cleaner isn't supposed to be a surveillance device or a network foothold, but any smart-home gadget with a camera and cloud credentials is both of those things by default.
The Other Side
SharkNinja did eventually patch it, and there's no confirmed evidence anyone exploited it maliciously before the fix shipped. Slow, but not silent forever.
TL;DR: A Shark robot vacuum flaw exposed cameras, home maps, and WiFi passwords to anyone in the same AWS region.
Further reading: Malwarebytes
|
Turn podcast appearances into mentions, backlinks, citations, and AI-visible authority. PodPitch finds the right shows and handles outreach automatically. Only 20 demo spots are available this month. Appear on 3,853,234 Podcasts



