<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>News Agent — Professional &amp; Business Services</title><link>/industries/professional-services/</link><description>Cyber threat intelligence for the Professional &amp; Business Services industry — daily-brief items tagged to this slice.</description><item><title>SAP discloses &quot;OVERPASS,&quot; a CVSS 10.0 buffer overflow in SAP Kernel&#x27;s Extended Passport Protocol library</title><link>/briefings/2026/09/09/2026-09-09/</link><guid isPermaLink="false">2026-09-09-SAP discloses &quot;OVERPASS,&quot; a CVSS 10.0 buffer overflow in SAP</guid><pubDate>Wed, 09 Sep 2026 06:00:00 +0000</pubDate><description>SAP discloses &quot;OVERPASS,&quot; a CVSS 10.0 buffer overflow in SAP Kernel&#x27;s Extended Passport Protocol library — Onapsis estimates 10,000+ internet-facing SAP systems are exposed. CVE-2026-44756 lets an unprivileged attacker run arbitrary OS commands with administrative privileges, fully compromising the SAP host and the business data on it. No in-the-wild exploitation confirmed yet, but the flaw affects a wide kernel-version range (7.22 through 9.20) and internet exposure at this scale makes it a KEV-catalog candidate the moment PoC code surfaces. Patch immediately rather than wait for that signal. BleepingComputer · cybersecuritynews.com [🔓 CRITICAL VULNERABILITIES]</description></item><item><title>N-able N-central CVE-2026-86218 (CVSS 10.0)</title><link>/briefings/2026/09/08/2026-09-08/</link><guid isPermaLink="false">2026-09-08-N-able N-central CVE-2026-86218 (CVSS 10.0)</guid><pubDate>Tue, 08 Sep 2026 06:00:00 +0000</pubDate><description>N-able N-central CVE-2026-86218 (CVSS 10.0) — pre-auth RCE in RMM platform, exploited before the Sep 5 hotfix shipped — A static code-injection flaw lets an unauthenticated attacker execute arbitrary code with root-level control on the N-central server. N-able&#x27;s customer notice said the flaw &quot;has been observed being exploited in the wild,&quot; and it is the vendor&#x27;s third zero-day in six weeks. Shadowserver counted roughly 1,500 internet-facing N-central servers, concentrated in the US and Europe. Because a single MSP typically manages hundreds of client networks from one N-central console, a breach here is a supply-chain event, not an isolated incident — on-premises deployments still on Hotfix 3 must apply Hotfix 4 (build 2026.3.1.14) immediately. Help Net Security · Huntress [🔓 CRITICAL VULNERABILITIES]</description></item><item><title>ConnectWise ScreenConnect file-transfer flaw enables worm-like malware spread across MSP client networks</title><link>/briefings/2026/09/08/2026-09-08/</link><guid isPermaLink="false">2026-09-08-ConnectWise ScreenConnect file-transfer flaw enables worm-li</guid><pubDate>Tue, 08 Sep 2026 06:00:00 +0000</pubDate><description>ConnectWise ScreenConnect file-transfer flaw enables worm-like malware spread across MSP client networks — CVE and fix due this week — Huntress documented three unrelated incidents (Quick Assist tech-support scam, phishing MSI installer, fake Geek Squad refund lure) all converging on the same four-stage VBScript chain that installs rogue ScreenConnect clients and propagates to newly connected hosts — cryptomining, tunneling, and security-control tampering payloads observed. ConnectWise confirmed the file-transfer flaw affects both Cloud and On-Premise deployments in a Sep 3 advisory and recommends disabling technician file transfers until a fix ships. Help Net Security · The Hacker News [🔓 CRITICAL VULNERABILITIES]</description></item><item><title>Additional DLS claims Sep 7: Lightcast (US, HR/labor-market software) claimed by Direwolf; United Group (India, diversified conglomerate) cl</title><link>/briefings/2026/09/08/2026-09-08/</link><guid isPermaLink="false">2026-09-08-Additional DLS claims Sep 7: Lightcast (US, HR/labor-market </guid><pubDate>Tue, 08 Sep 2026 06:00:00 +0000</pubDate><description>Additional DLS claims Sep 7: Lightcast (US, HR/labor-market software) claimed by Direwolf; United Group (India, diversified conglomerate) claimed by newly-emerged group Vexy; Master Manufacturing (US, metal stamping) claimed by Dark Project with 36GB allegedly exfiltrated. 🟥 All unverified DLS claims; verify before treating as breaches. RedPacket Security [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>The N-able N-central zero-day is a reminder that RMM platforms are now systemic infrastructure, and the market has not priced that risk corr</title><link>/briefings/2026/09/08/2026-09-08/</link><guid isPermaLink="false">2026-09-08-The N-able N-central zero-day is a reminder that RMM platfor</guid><pubDate>Tue, 08 Sep 2026 06:00:00 +0000</pubDate><description>The N-able N-central zero-day is a reminder that RMM platforms are now systemic infrastructure, and the market has not priced that risk correctly. A single compromised console reaching hundreds of downstream client networks is functionally identical to a nation-state&#x27;s preferred &quot;one access point, many targets&quot; playbook — except here the access point is a commercial product with 1,500 internet-facing instances and no operator-level segmentation requirement. This is the same structural weakness that made SolarWinds and, more recently, ConnectWise attractive footholds: the MSP model concentrates trust in a small number of vendors that most portfolio companies never audit directly. Insurers and PE diligence teams underwriting companies that outsource IT management should be asking which RMM platform their vendor runs and how quickly it patches, not just whether the vendor itself has a security program. Help Net Security [🌍 GEOPOLITICS]</description></item><item><title>SilentRansomGroup</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-SilentRansomGroup</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>SilentRansomGroup — three US AmLaw law firms claimed in three days; attorney-client privilege data at risk — SilentRansomGroup posted Holland &amp; Knight (Sep 1), Greenberg Traurig (Sep 2), and Katten Muchin Rosenman (Sep 3) on its DLS in rapid succession. All three are major US-headquartered Am Law 100 or Am Law 200 firms with significant M&amp;A, IP, regulatory, and litigation practices. The group has threatened data publication unless contact is made. 🟥 All three DLS claims; data scope and authenticity unverified. Contact with sensitive corporate, litigation, and government-facing client data is the primary risk. DeXpose / Greenberg Traurig · RedPacket / Katten Muchin · HookPhish / Holland &amp; Knight [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>SilentRansomGroup</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-SilentRansomGroup</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>SilentRansomGroup — confirmed as active US law firm extortion actor; three Am Law claims Sep 1–3 — SilentRansomGroup appears to operate a targeted law-firm vertical, systematically posting large US firms with complex client data. The three-claim cluster in 72 hours is consistent with a coordinated campaign against a specific sector, not opportunistic individual attacks. The group&#x27;s MO (DLS listing + contact-or-publish ultimatum) mirrors established RaaS playbooks. No CISA advisory yet. [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>SilentRansomGroup&#x27;s coordinated targeting of three Am Law firms in 72 hours is the clearest indication yet that a ransomware operator has ex</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-SilentRansomGroup&#x27;s coordinated targeting of three Am Law fi</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>SilentRansomGroup&#x27;s coordinated targeting of three Am Law firms in 72 hours is the clearest indication yet that a ransomware operator has explicitly prioritised attorney-client privileged data as a separate, higher-value extortion commodity. Greenberg Traurig, Holland &amp; Knight, and Katten Muchin Rosenman collectively hold privileged communications, litigation strategy, M&amp;A deal documents, and regulatory filings for hundreds of Fortune 500 and government clients. A group that publishes this data does not merely breach a law firm — it potentially pierces attorney-client privilege for every client whose matter is in the exfiltrated files. The reputational and legal-liability exposure for affected firms is structurally different from a healthcare or retail breach. Law firm clients with active litigation, ongoing M&amp;A transactions, or pending regulatory proceedings should be assessing whether their counsel&#x27;s matter files are in scope. DeXpose · HookPhish [🌍 GEOPOLITICS]</description></item><item><title>Qilin</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-Qilin</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>Qilin — continues rank 1; Complete Packaging Solutions (UK) added to DLS Sep 3; YTD pace unchanged at 546 — Qilin posted Complete Packaging Solutions, a UK business services provider, on September 3. The group maintains approximately 140 victims/month pace. YTD: 546 victims; L3M: 335. The ATF major-incident claim (Aug 26) remains under DOJ investigation. 🟥 DLS claim for Complete Packaging Solutions; verify before treating as a breach. DeXpose [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item></channel></rss>
