Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Four privileged platforms under live attack

5 min read
12:09UTC

Four vendor chains that sit above the estate came under confirmed attack in August: N-able N-central, PaperCut, Zimbra and Microsoft SharePoint. The first alerts came from NHS England, Australia's ACSC, CERT Polska and Singapore's CSA. Ransomware leak-site claims rose 11 per cent, Europol announced the sinkholing of a two-decade-old botnet, and the share of KEV entries carrying three-day deadlines fell from 87 per cent to 65.

TechnologyASDCCCS
Key takeaway

Standing privilege made ordinary infrastructure flaws estate-wide access risks; the national agencies naming them first were mostly not American.

This briefing mapped
Infrastructure
Legal
Domestic
Regulatory
Economic

PaperCut confirmed on 27 August that attackers were chaining two flaws in its print servers to run code without logging in. Huntress reproduced the chain and found it running in two customer environments.

Sources profile:This story draws on neutral-leaning sources

PaperCut confirmed on 27 August that attackers were chaining two flaws in its NG and MF print servers to run code without logging in first. Huntress found the attack working in two customer networks; PaperCut shipped a fix on 1 September.

It is the same weak point PaperCut had in 2023, when a similar chain drew ransomware affiliates within days of disclosure. Whether this stays contained now depends on how fast unpatched servers get the new update. 

N-able shipped a second hotfix for N-central on 6 August after watching attacker techniques change. Huntress saw intruders using the console's own remote-control feature to reach the endpoints it manages.

Sources profile:This story draws on neutral-leaning sources

N-able shipped a hardening update for its N-central software on 6 August. Huntress found attackers abusing its Take Control feature to reach managed networks, hiding their traffic inside Cloudflare's own services. Australia reported separate targeting on 19 August.

Remote-management platforms sit inside thousands of client networks at once. One working exploit can reach every customer a managed provider serves. 

Poland's national CERT reported on 17 August that attackers were exploiting a command-injection flaw in Zimbra Collaboration Suite. The way in is a monitoring feature, not the webmail.

Sources profile:This story draws on neutral-leaning sources

Poland's cybersecurity response team reported on 17 August that attackers were exploiting a Zimbra Collaboration Suite flaw. It let them run commands on the mail server without a password, wherever two monitoring features were switched on. Zimbra rated the bug 8.9 and fixed it in version 10.1.20.

Zimbra mail servers are typically run by the organisation itself, not a cloud provider like Gmail or Outlook. That leaves smaller institutions running their own infrastructure as the ones exposed. 

Singapore's Cyber Security Agency warned on 28 August that two Microsoft SharePoint Server flaws were under active exploitation and told organisations to patch immediately.

Sources profile:This story draws on neutral-leaning sources

Singapore's Cyber Security Agency warned on 28 August that two SharePoint Server flaws, CVE-2026-55040 and CVE-2026-63520, scoring 9.1 and 8.1, were under active attack. It told organisations to patch immediately rather than wait.

On-premises SharePoint has produced this pattern before: a July 2025 chain called ToolShell was exploited worldwide before a fix existed. Organisations still running the software on their own servers stay the recurring target. 

Europol announced on 2 September that an operation led by US authorities had sinkholed Sality, a peer-to-peer botnet active for two decades. CrowdStrike and the Shadowserver Foundation did the technical work.

Sources profile:This story draws on neutral-leaning sources

Europol announced on 2 September that a US-led operation with Bulgaria, Hungary and Romania sinkholed Sality, a peer-to-peer botnet running for two decades. It linked more than 11 million IP addresses to the infrastructure, against a peak of about one million infected machines at once.

Sality has no central server to seize. Its survival depends on whether operators can rebuild without one, the same test Emotet passed in 2021 after a similar takedown. 

Sources:Europol

Beacon published its final incident report on 3 September, concluding that an intruder had probably taken everything in its customer database in 87 minutes on 27 July. The suspected route was an AWS key exposed in public build files.

Sources profile:This story draws on neutral-leaning sources

Beacon, a UK charity donor-database provider, published its final incident report on 3 September. It concluded an intruder exported its entire customer database in about 87 minutes on 27 July. The likely route in was a stolen Amazon Web Services access key, probably exposed in public code.

Beacon says a credential left visible in code, not a break-in, let the intruder in. Anyone browsing the site's own code could have found it. Beacon has reset every Amazon-linked credential since. 

ThreatVectr counted 1,088 ransomware leak-site claims in August against 976 in July, with the number of groups posting a victim up from 68 to 83. Italy climbed faster than any other country.

Sources profile:This story draws on neutral-leaning sources

ThreatVectr recorded 1,088 ransomware leak-site claims in August against 976 in July, an 11 per cent rise. Active posting groups rose from 68 to 83. Qilin took first place with 165 claims. Italy jumped from 27 claims and seventh place to 50 claims and third.

More active groups, not one bigger gang, drove the rise. It points to a fragmenting ransomware-as-a-service market, where affiliates move between brands rather than one crew's capacity growing. 

CISA added 37 entries to its Known Exploited Vulnerabilities catalogue between 3 August and 2 September, and 24 of them carried a three-day remediation deadline. The previous stretch ran at 87 per cent.

Sources profile:This story draws on neutral-leaning sources

America's cyber-defence agency added 37 vulnerabilities to its Known Exploited Vulnerabilities catalogue between 3 August and 2 September. Of those, 24, or 65 per cent, carried a three-day fix deadline for federal agencies, down from 87 per cent in the prior stretch.

The typical deadline held at three days either way, but this batch spread urgency more unevenly across entries. The figures came from a GitHub mirror after the catalogue's own page and feed refused requests. 

Google Threat Intelligence Group named BREEZE COMET on 1 September, an actor it says it previously tracked as UNC5669 and now assesses as working against Brazilian payment infrastructure.

Sources profile:This story draws on neutral-leaning sources

Google's threat-intelligence team named a financially motivated hacking group BREEZE COMET on 1 September, saying it had tracked the group before under a different name. It targets Brazil's payment systems, including the instant-transfer network Pix, using a Rust-based tunnelling tool built to hide its traffic.

Google says the same activity overlaps with clusters other security firms track under separate names of their own. Different vendors often label the same or related hacking crews differently, complicating cross-industry attribution. 

JPCERT/CC published an alert on 15 August about a pre-authentication flaw in NetScaler ADC and Gateway, stating it had confirmed no information indicating exploitation. A proof of concept had appeared the day before.

Sources profile:This story draws on neutral-leaning sources

Security researchers at WatchTowr Labs published technical analysis and a working exploit on 14 August for CVE-2026-8452, a flaw in NetScaler network appliances. It let an attacker run code without logging in first, on appliances set up to handle single sign-on.

Japan's cyber-alert body said the next day it had confirmed no information indicating exploitation so far, not that none exists. Cloud Software Group has published no workaround; only the fixed versions close the flaw. 

Britain's data protection regulator reprimanded ACRO Criminal Records Office on 12 August after a website and CMS compromise put data on up to 10,920 people at risk. Remedial work spared it a fine.

Sources profile:This story draws on neutral-leaning sources

Britain's data regulator reprimanded the national criminal-records agency on 12 August. A compromise of its website and back-end software had put data on up to 10,920 people at risk. The regulator found unclear ownership of software updates and weak patch management.

The agency avoided a fine because network segmentation had limited the breach's reach, and it had since done remedial work. The regulator's finding points to a basic gap: nobody clearly owned keeping the website's software current. 

INTERPOL published results from Operation Jackal IV on 25 August: 58 arrests and 263 suspects identified across 23 countries. South Africa carried most of the enforcement.

Sources profile:This story draws on neutral-leaning sources

Interpol published results from Operation Jackal IV on 25 August. The operation ran from November 2025 to June 2026 against West African organised-crime groups running romance and investment scams. Across 23 countries it identified 263 suspects and made 58 arrests.

South Africa carried most of the enforcement, raiding seven Johannesburg locations and arresting 39 people. It seized $2.67 million and blocked 257 bank accounts, underlining Johannesburg's role moving scam proceeds through the banking system. 

Sources:INTERPOL

JPCERT/CC told Japanese organisations on 12 August to apply Microsoft's August updates, relaying Microsoft's confirmation that an elevation-of-privilege flaw in the Windows WinSock driver was being exploited in the wild.

Sources profile:This story draws on neutral-leaning sources

Japan's cyber-alert body told organisations on 12 August to apply Microsoft's August security updates. It was relaying Microsoft's own confirmation that CVE-2026-68820, a flaw in the Windows network driver WinSock uses, was already being exploited.

Privilege-escalation flaws like this one do not give an attacker initial access on their own. They matter because they let an attacker who is already on a machine, through some other route, gain full control of it. 

The UAE Cyber Security Council said on 10 August that national teams had detected and contained coordinated attacks on aviation, energy and education before the attackers reached their objectives. It named no actor, victim or technology.

Sources profile:This story draws on neutral-leaning sources

The United Arab Emirates' Cyber Security Council said on 10 August that national Teams had detected and contained coordinated attacks on aviation, energy and education. It said the attackers were stopped before reaching their goals, describing phishing attempts and efforts to use staff as an entry point.

It named no actor, victim or technology. This was its second such monthly disclosure, after a financial-sector one on 3 July, a cadence of public reassurance, not detail outside researchers can check. 

DSIT and DCMS opened a call for evidence on 17 August covering sections 1 to 13 of the Telecommunications (Security) Act 2021, the regulations made under it and the accompanying code of practice.

Sources profile:This story draws on neutral-leaning sources

Two UK government departments opened a call for evidence on 17 August. It covers sections 1 to 13 of the Telecommunications (Security) Act 2021, testing whether the UK's five-year-old telecoms security rules still fit.

France's national cyber agency separately published a Wi-Fi security guide on 31 August. It was pitched as accessible good practice, not detailed technical recommendation, part of a broader push toward baseline security guidance. 

ENISA updated its FAQ for the Cyber Resilience Act Single Reporting Platform on 31 August, the mechanism through which a manufacturer reports an actively exploited vulnerability once instead of notifying every national authority.

Sources profile:This story draws on neutral-leaning sources

The EU's cybersecurity agency updated its guidance on 31 August for the Cyber Resilience Act's Single Reporting Platform. That mechanism lets a manufacturer or open-source steward report one actively exploited vulnerability once, rather than notifying every EU national authority separately.

The same agency also published a Cyber Resilience Maturity Assessment Model for small and medium businesses on 6 August. It is a no-obligation self-assessment tool aimed at smaller firms least likely to run one otherwise. 

Closing comments

Europol's 2 September 2026 Sality announcement describes a public-private operation in which CrowdStrike and the Shadowserver Foundation supported sinkholing against infrastructure linked to more than 11m IP addresses. INTERPOL's 25 August Operation Jackal IV paired 58 arrests across 23 countries with 257 blocked accounts in South Africa, showing that distributed criminal infrastructure is being contested through coordinated access disruption rather than by individual victims alone.

Different Perspectives
ASD's ACSC
ASD's ACSC
On 19 August, ASD's ACSC reported targeting within Australia of N-able N-central vulnerabilities and named no sector. That gives managed service providers a dated national warning that a console compromise can reach the endpoints they administer.
CERT Polska
CERT Polska
On 17 August, CERT Polska reported active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite. Its finding identifies a mail-platform exposure in an optional monitoring configuration, so administrators must test the affected path rather than treat webmail updates as routine.
Singapore CSA
Singapore CSA
On 28 August, Singapore CSA said CVE-2026-55040 and CVE-2026-63520 in Microsoft SharePoint Server were under active exploitation and told organisations to patch. The 9.1 and 8.1 scores make its notice a direct priority signal for collaboration-platform owners.
JPCERT/CC
JPCERT/CC
On 15 August, JPCERT/CC alerted organisations to CVE-2026-8452 in NetScaler ADC and Gateway, while saying it had no information indicating exploitation. That preserves the alert as a warning ahead of exploitation, not proof that an attack had occurred.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.