Vendor
Critical RCE Vulnerability in N-able N-central
1 TTPA critical unauthenticated remote code execution vulnerability (CVE-2026-86218) in N-able N-central is under active exploitation, allowing attackers to gain full system control.
Exploitation of N-able N-central via CVE-2024-27429
3 TTPs 1 CVEThreat actors are exploiting a remote code execution vulnerability (CVE-2024-27429) in N-able N-central to gain unauthorized access and deploy RMM payloads on managed systems.
Detection of Novel RMM Software Usage
1 rule 1 TTPThis brief details a detection strategy for identifying the introduction of remote monitoring and management (RMM) software in Windows environments by monitoring for newly observed code-signing certificates.
N-able N-central Authentication Bypass Exploitation
3 TTPs 2 CVEs 6 IOCsThreat actors are actively exploiting a patch bypass vulnerability (CVE-2026-18577) in N-able N-central to gain administrative control and establish persistent remote access via Cloudflare tunnels.
IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)
1 rule 3 TTPs 11 CVEs 2 IOCsUnauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.
Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes
1 rule 193 IOCsThis brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.
PowerShell Script Block Logging Disabled via Registry Modification
2 rules 2 TTPsAttackers may disable PowerShell Script Block Logging by modifying the registry to conceal their activities on the host and evade detection by setting the `EnableScriptBlockLogging` registry value to 0, impacting security monitoring and incident response capabilities.
Suspicious DNS Queries to RMM Domains from Non-Browser Processes
2 rulesDetection of DNS queries to remote monitoring and management (RMM) domains from non-browser processes indicating potential misuse of legitimate remote access tools for command and control.
Detection of Windows RMM Tool Execution
3 rules 1 TTPDetects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.