NoName057(16), a pro-Russian hacktivist collective active since 2022, has (re)launched #OpJapan, calling for a DDoS campaign targeting Japanese entities. The stated motive is Japan’s continued support for Ukraine and NATO amid the Russia-Ukraine war. For defenders, the key concern is predictability: this group has repeatedly run #OpJapan waves, suggesting organizations should watch for recurring targeting patterns and prepare DDoS response and resilience testing.
Source: Checkpoint Blog
N-able patches critical N-central pre-auth RCE actively exploited (CVE-2026-86218)
N-able released an emergency hotfix for CVE-2026-86218, a critical remote code execution vulnerability in N-central, its remote monitoring and management (RMM) platform. The flaw is described as pre-authenticated RCE and was addressed via Hotfix 4 for N-central 2026.3 (bringing affected builds to 2026.3.1.14). Since the issue is reported as exploited in the wild, MSPs and N-central operators should prioritize patching and also audit for suspicious accounts and post-exploitation indicators.
Source: Help Net Security
Attackers hijack MikroTik devices via RouterOS SSH exploit chain “MikroTrick”
CERT Polska reports an active exploitation campaign targeting MikroTik RouterOS via internet-exposed SSH, involving a chain of six vulnerabilities disclosed in coordination with MikroTik. Two of the issues can combine to allow full device control without authentication when SSH is reachable. The immediate takeaway is that “exposed management services” remain a top risk category—network teams should urgently restrict inbound access to SSH (or block it) and validate whether vulnerable paths are present.
Source: Help Net Security
Worm-like ScreenConnect campaign spreads via modified clients and backdoored instances
Recent reporting describes a worm-like attack pattern using modified ScreenConnect clients and backdoored ScreenConnect instances to transfer and execute payloads on newly connected systems. This shifts the risk profile from “single-victim compromise” to a fast lateral spread mechanism leveraging legitimate remote access tooling. Organizations running ConnectWise ScreenConnect should check for unauthorized modifications, validate instance integrity, and tighten remote-support access controls and monitoring for anomalous client behavior.
Source: SecurityWeek
Magento/Adobe Commerce zero-day StyleSmuggler exploited to run code and backdoors
Sansec-linked research and follow-on coverage point to StyleSmuggler, a Magento and Adobe Commerce zero-day being actively exploited to execute code and install stealth backdoors. The attacks can involve unauthenticated paths to compromise, meaning even partially exposed e-commerce platforms can become entry points. For merchants, this is a “patch-and-hunt” event: apply the vendor updates, rotate potentially exposed credentials, and scan for indicators of web shell/backdoor installation.
Source: SecurityWeek
Ransomware negotiation turns into a repeatable “business process” with measurable targets
Reporting and analysis highlight how ransomware groups operationalize negotiations by researching victim revenue, insurance coverage, and feasibility of decryption—then using testing to confirm working keys. Demand-setting is often framed as a percentage of annual revenue and supported with structured escalation tactics and deadline management. The security relevance: incident response teams should treat negotiation artifacts as part of the threat model, ensuring legal/communications processes and technical recovery plans are ready before attackers force time pressure.
Source: Help Net Security
Berlin investigates data leak after hackers publish stolen credentials tied to city agencies
Berlin authorities are investigating another public leak involving stolen login credentials from city entities, while separately warning about the Rhysida cybercrime group. The incident underscores how credential dumps can quickly translate into further compromise attempts through stuffing and targeted phishing. Key lesson for defenders: treat leaked credentials as an active exploitation opportunity—accelerate password resets, session revocations, and detect anomalous logins across exposed services.
Source: RecordedFuture
You May Also Be Interested In... OpenAI reaches “automated research intern” milestone on the road to self-improving AI
Ransomware negotiation tactics explained (Lock and Code podcast)
N-able patches critical N-central zero-day exploited in the wild