Fake IT Calls and a Fourth Hotfix in Five Weeks (09/07/2026)
- › A data theft and extortion cluster is reaching Microsoft 365 and other SaaS tenants through IT help desk vishing aimed at executives.
- › N-able shipped a fourth N-central hotfix in five weeks, and its incident notice and release notes disagree on whether the flaw is exploited.
- › A TantoSec proof of concept turns a Telerik UI padding oracle into unauthenticated remote code execution against a non-default configuration.
- › Huntress documented worm-like abuse of ConnectWise ScreenConnect pushing a four-stage VBScript payload to newly connected hosts.
- › JSCeal is compiled V8 JavaScript malware that harvests credentials and can bypass Google authentication using stolen session cookies.
Two of today’s stories are about the tools your organization uses to fix itself, and one is about the phone call that starts the whole thing. The remote monitoring platform, the remote support client, and the help desk are all trusted by design, and all three showed up in incident reporting inside the same twenty-four hours. That is a category, and it is worth treating as one.
Top 5 Critical Security Alerts
1. Attackers Are Calling Executives While Posing as the Help Desk
Threat hunters disclosed a widespread data theft and extortion cluster reaching Microsoft 365 and other software-as-a-service tenants through information technology help desk vishing, with executives as the target. Voice remains the channel with the least verification attached to it, and an executive under time pressure taking a call from somebody who knows the internal ticketing vocabulary is a very high success rate for a very low cost. Every technical control behind that account was working exactly as configured while it happened. The Hacker News has the cluster detail.
Operator Note: Your help desk’s identity verification script is now a security control, so read it and check whether anything on it can be answered from a public profile or a leaked directory.
2. N-able Ships a Fourth N-central Hotfix in Five Weeks
Every on-premises N-central build below 2026.3.1.14 needs Hotfix 4, including servers that took Hotfix 3 a day earlier, and N-able’s incident notice says the flaw has been exploited in the wild while its own release notes call that unconfirmed. A remote monitoring and management platform reaches every endpoint it manages with administrative rights, which is why this product class keeps appearing here. When a vendor’s two documents disagree about exploitation, plan against the more serious of the two. The Hacker News has the version detail.
Operator Note: Four hotfixes in five weeks means your patch cadence for this product has to be measured in days, so put someone’s name against it rather than leaving it in the monthly cycle.
3. A Public Exploit Turns a Telerik Padding Oracle Into Remote Code Execution
A TantoSec proof of concept chains an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution, though only against applications running a specific non-default configuration, and Progress has patched it. The configuration caveat is the part that decides whether this is your problem, and it is also the part most organizations cannot answer without checking. Component-level flaws like this live inside applications nobody thinks of as Telerik deployments. The Hacker News has the technical write-up.
4. Rogue ScreenConnect Clients Push a Payload to Newly Connected Hosts
Huntress documented worm-like activity abusing ConnectWise ScreenConnect to distribute a four-stage Visual Basic Script payload to systems as they connect. Remote support software is built to run code on a machine without the user agreeing each time, so an attacker holding the console inherits exactly that capability against every host that checks in. The spread pattern here follows your support relationships rather than your network topology. The Hacker News has the Huntress findings.
5. JSCeal Bypasses Google Authentication With Stolen Session Cookies
Researchers unpacked JSCeal, compiled V8 JavaScript malware with credential harvesting, surveillance, and traffic interception built in, capable of bypassing Google authentication using stolen session cookies. A stolen session cookie sidesteps the password and the second factor together, because the authentication already happened and the token is the proof. This is why session lifetime and device binding matter more than another factor on the login page. The Hacker News has the analysis.
Additional Security Alerts
Emerging Security Technologies
- The NCSC warns that shadow AI is creating new exposure: Unapproved AI tools can move corporate data outside sanctioned systems and introduce risks nobody has assessed, which is the same shape as shadow IT with a faster adoption curve. Infosecurity Magazine
Security Breaches and Incidents
- $320 million in Bitcoin drained from Liquid Network: Self-described white hats took roughly 4,000 BTC and say they will return most of it once the vulnerability is fixed, which is theft with a press release attached. The Register
- A Welsh regulator’s records release exposed staff diversity data: Natural Resources Wales published a spreadsheet in error five years ago exposing diversity information on 2,000 staff, and says it has found no evidence of misuse. A five-year gap between publication and discovery is the finding. The Register
Cloud and Network Security
- UK food supply chain named as exposed to hostile attack: A report identifies cyber defense costs among the factors feeding food price inflation, which puts security spending inside an economic argument rather than a risk one. The Register
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.