Huntress' Security Operations Center reports that over the past nine months, attackers have been abusing legitimate sharing features on AI platforms—like Claude Artifacts, claude.ai/share links, and indexable ChatGPT and Grok conversations—to distribute malware. These campaigns exploit the trust users place in familiar AI branding, often surviving only hours or days before the platforms take the content down.
N-able released N-central 2026.3 Hotfix 4 on Saturday to fix CVE-2026-86218, a maximum-severity remote code execution bug that lets unauthenticated attackers run code on unpatched, internet-exposed servers. Shadowserver counts nearly 1,500 exposed N-central instances, mostly in the US and Europe, while security firm Huntress suspects the flaw, along with two related authentication-bypass bugs, may already have been exploited as a zero-day in at least one customer breach.
Huntress researchers found phishing campaigns that trick victims into running a disguised but legitimate Faronics Deploy installer, often labeled as an Adobe file, which secretly enrolls their machine into an attacker-controlled management console. From there, attackers run PowerShell scripts to fetch additional tools and install ConnectWise ScreenConnect, giving them persistent remote access. Over 457 endpoints were targeted between July 21 and August 20 using fake invoice and tax-document lures.
Security firm Huntress published findings from investigations conducted throughout 2026 in which it helped organizations confirm they had unknowingly hired North Korean operatives posing as IT staff. Cases included an Australian healthcare firm that flagged three employees suspected of impersonating Chinese nationals, plus two separate incidents in the financial services sector uncovered in August. Huntress noted these DPRK-linked workers have grown more skilled and active, blending into IT teams while funneling wages back to the regime and potentially planting malware or stealing data.