N-central Takeover, Passkey Bypass & Water Attacks Spread (08/03/2026)
- › Attackers took administrative control of N-able N-central servers through an authentication bypass, then planted Cloudflare tunnels on managed endpoints that survive losing the server.
- › Unit 42 demonstrated three ways malware already on a Windows machine can sign into passkey-protected Google accounts with no fingerprint, PIN, or prompt.
- › Water system attacks reached Georgia and Michigan, with at least seven states now reporting incidents to the FBI, though no utility has reported a drinking water safety impact.
- › INC Ransomware became the dominant actor exploiting two SonicWall SMA 1000 flaws, harvesting session databases and one-time password seeds along with credentials.
- › CrowdStrike found that 88% of publicly disclosed exploits in the first half of 2026 saw intrusion within 48 hours of the disclosure.
Two stories today share a shape worth naming: the fix that did not hold, and the control that was never protecting what you thought. N-able patched an authentication bypass in June and attackers found a second door into the same room, then left tunnels behind on customer endpoints where revoking the server does nothing. Unit 42 spent the weekend proving that a passkey stops phishing and does not stop malware sitting on the machine. Water attacks reached two more states while nobody has publicly attributed them.
Top 5 Critical Security Alerts
1. Attackers Own N-central Servers, and the First Patch Did Not Hold
N-able is warning that attackers exploited an authentication bypass to gain remote administrative access to N-central servers, both hosted and on-premises, then reached the customer systems managed through them. The original flaw, CVE-2026-18556, was fixed in build 2026.2, but attackers found an alternate path to the same outcome, tracked as CVE-2026-18577. Both score CVSS 8.2. N-able noticed an unusual volume of licensing errors from on-premises customers on July 31 and shipped emergency build 2026.3.1.7 on August 2. The Hacker News
Operator Note: Upgrading the server does not finish this. Attackers deployed Cloudflare tunnels as persistent services on managed endpoints, so those survive after you revoke server access. Hunt the endpoints, not just the console.
2. Unit 42 Signed Into Passkey Accounts With Nobody at the Keyboard
Palo Alto’s Unit 42 published three attack paths against Chrome’s Google Password Manager cloud authenticator on Windows machines with a TPM. In the first, malware lifts Chrome’s wrapped device identity key and forges an authentication assertion; the only thing distinguishing it from a real one is a single unset User Verified bit, which some relying parties including eBay were not checking. The second substitutes an attacker’s user-verification key during a forced re-enrollment, because the service does not check whether a new key came from secure hardware. The third reads the 32-byte Security Domain Secret out of Chrome’s process memory while it briefly sits there in plaintext. Every path starts with malware already running as an ordinary user. The Hacker News
Operator Note: If you deploy passkeys, set userVerification to required on your own relying parties and actually validate the UV bit rather than trusting what the request claims. Passkeys were sold as the end of credential theft, and they end phishing, which is a different problem than endpoint compromise.
3. Water System Attacks Reach Georgia and Michigan
Georgia confirmed cyberattacks on water systems without detailing damage, and nine Michigan water systems reported hostile activity to the state environment department. Michigan’s communications director said all systems continued to operate safely and no known impacts posed a public health concern. At least seven states have now reported incidents to the FBI, following the more than thirty Minnesota facilities hit July 26 and 27. The targeting centers on Rockwell Automation and Allen-Bradley programmable logic controllers. Tenable researchers have publicly suspected the IRGC-linked CyberAv3ngers group, while the FBI has not attributed the activity. The Register
Operator Note: This is the same PLC exposure CISA flagged on August 1, now confirmed across more states. If you run any Allen-Bradley controller reachable from the internet, that is the whole finding, and the fix is an afternoon of network work rather than a capital project. We covered why the small operators get picked in why they went after the small water systems.
4. INC Ransomware Takes Over the SonicWall SMA 1000 Wave
Resecurity reports INC Ransomware has become the dominant actor exploiting CVE-2026-15409 and CVE-2026-15410, two SonicWall Secure Mobile Access 1000 flaws that chain into arbitrary command execution and device takeover. SonicWall patched in mid-July. The group claims 885 victims to date across Australia, the United States, the UAE, Colombia, and Switzerland, and added multiple organizations to its leak site between July 17 and August 1. The Hacker News
Operator Note: They are pulling session databases and time-based one-time password seed configurations, not just passwords. A seed is a long-lived secret, so rotating user passwords after this leaves the second factor in the adversary’s hands. Re-enroll the tokens.
5. Eighty-Eight Percent of Exploits Landed Within 48 Hours
CrowdStrike’s 2026 Threat Hunting Report found that in 88% of publicly disclosed vulnerability exploits in the first half of 2026, the intrusion happened within 48 hours of release. Two Chinese-nexus groups, Vault Panda and Genesis Panda, exploited the React2Shell flaw in React Server Components and Next.js inside a day of its December 2025 disclosure, deploying remote access trojans for credential harvesting. The report also notes a 42% year-over-year rise in zero-day exploitation from 2024 to 2025. Infosecurity Magazine
Additional Security Alerts
Threat Intelligence
- DOUBLECUP hides payloads in cached images: A Russian loader-as-a-service uses ClickFix lures to stash malicious code inside PNG files cached by the victim’s browser, delivering CountLoader to Windows and macOS and a new remote access trojan to Windows. BleepingComputer
- A Chinese actor pointed a Deepseek agent at a security firm: Researchers at Jesta intercepted an AI agent attempting to compromise more than 1,200 hosts for proxyjacking and follow-on attacks. Dark Reading
Security Breaches & Incidents
- UK police contact data leaked after the PNLD breach: ExfilSquad published names, organizations, and work email addresses for more than 100,000 police officers, police staff, and criminal justice professionals. BleepingComputer
- 31,000 Liechtenstein ownership records stolen: Attackers took records identifying the people behind companies, foundations, and trusts, and the government formed a crisis unit in response. The Record
Emerging Security Technologies
- Hugging Face Diffusers flaws allow repository code execution: Three high-severity bugs let a crafted model repository run arbitrary code on any machine that loads it, bypassing earlier fixes. The Hacker News
- IBM puts AI breach blame on access control: 92% of companies that had an AI security incident had inadequate access controls around their AI systems, and the model itself was rarely the problem. The Decoder
- AI-generated reports are clogging the CVE pipeline: Fake vulnerability submissions are adding load to a system already behind on its backlog. The Register
Security Tools & Best Practices
- 18 malicious npm packages target Alibaba developer tools: The packages deliver a cross-platform remote access trojan in a targeted supply chain attack aimed at Chinese-speaking development environments. The Hacker News
- Thermo Fisher patches a DNA file tampering flaw: Select Applied Biosystems human identification software allowed nearly undetectable changes to .fsa and .hid files before analysis software loaded them. The Hacker News
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.