CVE-2026-18577: Critical authentication bypass vulnerability in N-Able N-Central remote management solution
A critical vulnerability was discovered by N-Able in it's product N-Central, a remote management appliance used for IT administration.
Our Managed Detection and Response Services provide continuous monitoring from a team who’ll neutralise any breaches at speed...
Gain access to malware experts to quickly contain threats and reduce future exposure to attacks...
Integrity360 has been recognised as a Gartner Representative Vendor.
Many organisations are choosing CyberFire MDR to strengthen their defences. Discover how it can protect your business in our brochure.
Cyber attacks often seem faceless, but hidden behind the headlines of financial loss and technical details there are very real human stories.
In 2025, we’re witnessing a shift in how ransomware operates, who it targets, and the consequences of falling victim.
Stay ahead of the latest cybersecurity industry developments, advancements and threats, and understand how you can best protect your organisation.
Do you know what your company’s network vulnerabilities are? Businesses that invest in penetration testing do.
If your business handles credit card data, PCI DSS compliance isn’t optional—it’s critical. From retailers and e-commerce platforms to service providers and financial institutions, securing credit card data is critical to customer trust and preventing fraud.
Stay informed with the latest cybersecurity news with our weekly threat roundups.
Confused about cybersecurity? Our A-Z Glossary of terms can help you navigate this complicated industry.
For many small and mid-sized businesses, cybersecurity can feel overwhelming.
SOC 2 certification reflects Integrity360’s continued investment in strengthening cyber resilience for clients across highly regulated and high-risk industries.
Leading Canadian cybersecurity services provider Advantus360 joins Integrity360 creating the group’s first hub in North America
Posts about:
A critical vulnerability was discovered by N-Able in it's product N-Central, a remote management appliance used for IT administration.
The "wp2shell" exploit chain represents a critical security event targeting the fundamental architecture of the WordPress ecosystem. This is a pre-authentication Remote Code Execution (RCE) vulnerability residing entirely within WordPress Core. It requires no third-party plugins, themes, or authenticated access to execute. A single crafted HTTP request against a default, "stock" installation can result in unauthenticated attacker gaining full system control.
Check Point has disclosed and patched a critical zero-day vulnerability, CVE-2026-16232, affecting its SmartConsole management platform. The flaw is an authentication bypass vulnerability that enables unauthenticated remote attackers to obtain a valid application login token and authenticate with administrator-level privileges under specific conditions. Check Point confirmed that the vulnerability is being actively exploited and has impacted a limited number of customers.
Security researchers have observed increased activity involving ACR Stealer, an information-stealing malware family associated with the Amatera Stealer ecosystem. The activity was particularly prevalent from late April through mid-June 2026 and has successfully compromised enterprise environments.
Ubiquiti has released security updates addressing seven critical vulnerabilities across multiple UniFi products. The flaws could allow attackers with network access to perform remote command execution (RCE), privilege escalation, unauthorised device modifications, and server-side request forgery (SSRF). Several vulnerabilities carry CVSS scores between 9.0 and 10.0, representing a significant risk to organisations using affected UniFi deployments.
Security researchers have identified an ongoing campaign operated by a threat actor known as Lurking Lizard, which distributes trojanized versions of the popular 7-Zip archiving software. Victims who download installers from the malicious domain 7zip[.]com instead of the legitimate 7-zip[.]org unknowingly install malware that converts their systems into residential proxy nodes.
Microsoft has disclosed CVE-2026-50656, a high-severity elevation of privilege vulnerability affecting the Microsoft Malware Protection Engine used by Microsoft Defender. The vulnerability, publicly referred to as "RoguePlanet," can allow a local attacker to obtain SYSTEM-level privileges on affected Windows systems.
Researchers have recently disclosed a large-scale campaign, referred to as “FortiBleed,” involving the compromise and exposure of credentials associated with Fortinet FortiGate firewalls and SSL VPN devices across global environments.
A critical vulnerability (CVE-2026-20253) has been identified in Splunk Enterprise that allows unauthenticated attackers to perform arbitrary file operations and achieve remote code execution (RCE). The flaw stems from missing authentication controls in a PostgreSQL sidecar service endpoint.
A recent security incident involving ServiceNow highlights a significant risk to enterprises relying on cloud workflow and IT service management platforms. ServiceNow disclosed that a software flaw affecting certain customer instances allowed unauthenticated access to data via a vulnerable API endpoint. This condition effectively bypassed authentication controls, enabling external parties to query stored data without valid credentials.