Skip to content

Category: Software Supply Chain Security

N-central takeover: fix not enough

Attackers exploited an authentication bypass to take over N-central servers and reach managed endpoints. N-able’s initial fix didn’t fully close the gap, so every customer must upgrade to 2026.3.1.7.

Rails Critical Vulnerability: RCE Risk Patched

A new Rails critical vulnerability (CVE-2026-66066) was patched after reports that unauthenticated attackers could read arbitrary server files. In some setups, that exposure could lead to remote code execution.

HollowFrame and Matryoshka: Spear-Phishing Toolkit

Researchers describe how HollowFrame Matryoshka operates as a multi-stage spear-phishing intrusion. It chains DLL side-loading, privilege escalation, and Rust-based backdoors for remote command execution and deeper domain activity.