This Week in Cybersecurity: N-able's CVSS 10.0 RMM Flaw, a Cisco Email Gateway Root Exploit, and an AI Coding Hijack Spreading Shai-Hulud
By Mollie Horne
Two platforms built to be trusted with the most access — an MSP management console and an email gateway — both had maximum-severity flaws under active exploitation this week, while AI reshaped the attack surface in two more directions.
N-able's N-central, the remote monitoring and management (RMM) platform managed service providers use to oversee thousands of client networks from one console, disclosed a pre-authentication remote code execution flaw carrying a maximum CVSS score of 10.0 — its second critical, actively exploited incident in six weeks. Almost as urgently, Cisco confirmed that a single crafted email can hand an unauthenticated attacker root access on Secure Email Gateway, a flaw rated CVSS 9.8 with a federal patch deadline landing today.
AI kept expanding the attack surface in its own directions this week: an attacker hijacked a live AI coding-assistant session to spread the self-propagating Shai-Hulud worm across roughly 100 internal code repositories, and Anthropic disclosed that seven China-based AI labs ran industrial-scale campaigns to illicitly extract Claude's capabilities. None of that displaced the fundamentals — Texas utility CenterPoint Energy confirmed that an unsecured customer API let an attacker walk off with 7.49 million records. Here's what you need to know.
Explore this content with AI:
ChatGPT | Perplexity | Claude | Google AI Mode
N-able N-central's CVSS 10.0 flaw is under active exploitation — its second critical incident in six weeks
A pre-authentication remote code execution flaw in N-able's N-central RMM platform, tracked as CVE-2026-86218 and rated a maximum CVSS 10.0, is being actively exploited in the wild. N-able confirmed exploitation in an urgent customer notice, and watchTowr security researchers independently reproduced the exploit. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 8 with a federal remediation deadline of September 11 — already passed. N-able shipped the fix in N-central 2026.3 Hotfix 4 on September 5, alongside two related authentication-bypass flaws (CVE-2026-86206 and CVE-2026-86207) discovered by Rapid7's Stephen Fewer.
This isn't N-central's first brush with active exploitation this year: a separate authentication-bypass flaw, CVE-2026-18577, was exploited in the wild beginning in late July and disclosed in early August, with attackers using the platform's own Take Control feature and Cloudflare tunnels for persistence. Two critical, actively exploited N-central incidents within six weeks is a pattern, not a one-off.
Why it matters: N-central's blast radius is what makes this dangerous — as one researcher put it, compromising N-central hands an attacker access to every connected computer and downstream system it manages. If your organization is an MSP running N-central, or a client of one, confirm Hotfix 4 is applied today and audit administrative activity on the platform dating back to early September, not just check for the patch banner.
Read more at Help Net Security
A Cisco Secure Email Gateway zero-day gives root access from a single crafted email, and today is the federal patch deadline
Cisco confirmed active exploitation of CVE-2026-76461, a flaw in the email-parsing logic of its AsyncOS software for Secure Email Gateway that lets an unauthenticated attacker achieve root-level command execution simply by sending a crafted email containing malicious SQL statements — no credentials and no user interaction required. Cisco's PSIRT said it "became aware of active exploitation" of the flaw this month and has directly contacted cloud-hosted customers where malicious activity was detected. CISA rated the flaw CVSS 9.8, added it to its KEV catalog on September 14, and set a three-day federal remediation deadline of September 17 — today. Cisco has shipped fixes in the 15.5, 16.0, and 16.5 branches (15.5.5-0141, 16.0.4-302, and 16.5.0-780).
A three-day KEV deadline is aggressive even by CISA's own standards, and it signals how seriously the agency is treating exploitation already observed in the wild.
Why it matters: Email gateways sit directly in the path of every message an organization receives, and root access on one gives an attacker visibility into internal mail flow and often a pivot point deeper into the network. If you run Secure Email Gateway, confirm today — not this week — that you're on 15.5.5-0141, 16.0.4-302, or 16.5.0-780, and check whether Cisco has already reached out about your instance.
Read more at The Hacker News
An attacker hijacked a live AI coding-assistant session to spread Shai-Hulud across 100 repositories
A Mandiant report published September 16 describes an attacker who hijacked a developer's active AI coding-assistant session at an unnamed SaaS provider and used it to recommend a poisoned PyPI package. The developer accepted the recommendation, which installed an infostealer, stole the developer's GitHub OAuth tokens, and deployed the self-propagating Shai-Hulud worm across roughly 100 internal code repositories. A second infection followed when another employee separately pulled a compromised package from the company's own official namespace.
Shai-Hulud itself isn't new — Wiz has tracked the self-propagating npm/PyPI worm family through several waves since May 2026 — but this is a distinct incident, not a rehash: the entry point here was a hijacked AI assistant session rather than a compromised maintainer account or a typosquatted package.
Why it matters: An AI coding assistant session now carries the same blast radius as a hijacked developer laptop — anything it recommends, your CI/CD pipeline may trust by default. Review whether your organization logs and can revoke AI-assistant sessions independently of the developer's own credentials, treat AI-recommended package installs as requiring the same scrutiny as a manual dependency bump, and rotate GitHub OAuth tokens for any account that touched an affected repository.
Read more at CSO Online
Anthropic says seven China-based AI labs ran industrial-scale campaigns to distill Claude's capabilities
Anthropic disclosed on September 11 that it had identified and disrupted seven industrial-scale illicit distillation campaigns targeting Claude, run by China-based AI labs Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai), MiniMax, Xiaomi, and SenseTime. Distillation — training a smaller model to replicate a larger one's capabilities — is a legitimate technique; Anthropic's complaint is that these campaigns extracted Claude's outputs at scale without authorization, using fake accounts, stolen credit cards, and harvested API keys to get around normal usage limits. The largest campaign, which Anthropic tracked as GTG-16005 and attributed to Alibaba, involved 151 million exchanges and peaked at roughly 3 million exchanges a day from more than 3,500 fraudulent accounts.
CNBC reported that the extracted exchanges included reasoning transcripts that could meaningfully shortcut a competing lab's own model training. In response, Anthropic said it now bans accounts from regions including China, Iran, and Russia when identity verification fails, and has updated Claude to summarize and encrypt its internal reasoning and block system-prompt manipulation on new API accounts.
Why it matters: The techniques used against Anthropic — fake accounts, stolen payment credentials, harvested API keys, and traffic rerouted through proxy networks — are the same techniques that can be pointed at any organization's own hosted LLM deployment. Audit your API key issuance and usage patterns for a small number of accounts generating unusually large or steady request volumes, and treat anomalous LLM API consumption as a security signal, not just a billing one.
Read more at U.S. News
CenterPoint Energy confirms a breach of 7.49 million customer records through an unsecured API
Texas utility CenterPoint Energy confirmed in a September 14 SEC filing that an unauthorized party extracted approximately 7.49 million customer records through an external-facing API that The Register reported lacked a web application firewall, rate limiting, and authentication tokens. CenterPoint learned of the incident after a hacker using the alias "4d722e4d656f77" posted the claim to a cybercrime forum on September 12, stating the attacker could have pulled 17.44 million records had a CAPTCHA not interrupted the extraction partway through.
The exposed data includes names, phone numbers, service and billing addresses, account and premise IDs, billing amounts, autopay status, driver's license numbers, and the last four digits of Social Security numbers. CenterPoint serves roughly 7 million customer accounts across Texas, Indiana, Minnesota, and Ohio; the company says electric and gas delivery service was not affected, and it now faces multiple class-action lawsuits.
Why it matters: This wasn't a zero-day or a sophisticated intrusion — it was a customer-facing API missing baseline controls, at a company serving 7 million utility accounts. If your organization runs public APIs for billing, account management, or self-service, confirm WAF coverage, rate limiting, and token-based authentication are actually enforced in production, not just documented in a design spec.
Read more at SecurityAffairs
Final thoughts
The throughline this week is blast radius: the platforms attackers targeted most — an RMM console, an email gateway, an AI coding assistant, a model provider's API — are exactly the ones built to be trusted with access to everything downstream. Compromise one, and the damage isn't contained to a single organization. None of that displaced the fundamentals, though — an unsecured customer API did just as much damage this week as any zero-day. If your vendor risk register still treats "critical infrastructure software" as a single line item, this week is a good prompt to split it into the specific platforms — RMM tooling, email security, AI assistants — that carry outsized blast radius in your environment.
Check back next Thursday for the latest in cybersecurity news and analysis.
Ready to see how OpenVPN can help protect your organization from attacks?
Try the self-hosted Access Server solution or managed CloudConnexa service for free — no credit card required.
See Which One is Right for You