Bulletins //

NormCyber Threat Bulletin: September 2026

Cyber Threat Intelligence Roundup: Four Emerging Threats Organisations Should Know

Cyber attackers continue to find new ways into organisations, from exploiting known vulnerabilities to abusing trusted authentication and security tools. This month, the NormCyber Threat Intelligence team examines four developments that highlight the importance of keeping exposed systems patched, monitoring identity activity and maintaining visibility across the security environment.

CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalogue

CISA has added six vulnerabilities to its Known Exploited Vulnerabilities catalogue after evidence of active exploitation. The vulnerabilities affect technologies including Citrix NetScaler, Microsoft SQL Server, the Linux Kernel, Red Hat components and Ajax.NET Professional, with some dating back more than a decade.

Why does this matter?

The inclusion of these vulnerabilities in CISA’s KEV catalogue provides a clear signal that affected systems should be prioritised for investigation and remediation. Exposed systems should also be checked for signs of compromise, particularly where attackers have already been observed deploying web shells and conducting reconnaissance.

Russian Threat Actors Abuse Legitimate Authentication

Google researchers have identified targeted campaigns in which suspected Russian threat actors are abusing legitimate Google OAuth, Microsoft device-code authentication and WhatsApp device linking. Rather than simply stealing passwords, attackers are manipulating genuine authentication processes to obtain sessions, tokens and linked devices.

Why does this matter?

A successful authentication does not always mean the legitimate user is in control of the resulting session. Security teams need visibility around OAuth activity, device linking, authentication events and active sessions, particularly for users with access to sensitive information.

Attackers Could Turn EDR Defences Against the Endpoint

Security researchers at Akamai have demonstrated a technique known as Bring Your Own EDR, showing how attackers with local administrator access could abuse trusted SentinelOne components to interfere with security controls and potentially protect malicious code. SentinelOne has addressed the reported issue in Agent version 26.1.1.

Why does this matter?

EDR platforms require elevated privileges to protect endpoints, making those same privileges valuable to an attacker who already has administrator access. The research also highlights why security teams should verify that endpoint protection is operating as expected, rather than relying solely on an agent appearing healthy.

Critical N-able N-central Vulnerability Exploited in Active Attacks

N-able has issued an urgent update for CVE-2026-18577, a critical authentication bypass affecting its N-central Remote Monitoring and Management platform. The flaw allows remote attackers to obtain administrative access without valid credentials, potentially giving them control of managed devices and access to multiple customer environments.

Why does this matter?

For Managed Service Providers, compromising one N-central instance could provide a route into multiple customer environments. Organisations using N-central directly or relying on an MSP that uses it should confirm that the required update has been applied and review activity for signs of unauthorised access.

 

What These Emerging Cyber Threats Mean for Organisations

These incidents show how attackers are targeting more than traditional software vulnerabilities. From unpatched infrastructure and authentication tokens to trusted security tools and remote management platforms, organisations need visibility across the technologies and services they rely on.

The priority is clear: patch actively exploited vulnerabilities, monitor authentication and privileged activity, and make sure security controls are working as expected. For organisations that rely on third-party platforms or managed services, understanding how those systems connect to the wider environment is equally important.

Stay Informed About the Latest Cyber Security Threats

The cyber threat landscape changes quickly. New vulnerabilities, ransomware campaigns and attack techniques can create risks for organisations with little warning.
NormCyber’s Threat Intelligence team regularly analyses emerging cyber threats and vulnerabilities to help organisations understand their potential exposure and take appropriate action

Subscribe to the Threat Bulletin Here: