Speak naturally. Send without fixing.
Wispr Flow turns your voice into clean, professional text you can send the moment you stop talking. Not rough transcription you have to clean up. Actual polished text — ready for email, Slack, or any app.
Speak the way you think. Go on tangents. Change your mind mid-sentence. Flow strips the filler, fixes the grammar, and gives you text that reads like you spent five minutes writing it.
89% of messages sent with zero edits. Millions of professionals use Flow daily, including teams at OpenAI, Vercel, and Clay. Works on Mac, Windows, and iPhone.
Preview: N-central's patch didn't hold and CISA's deadline lands today, a fresh CVSS 10.0 credential bug ships across three platforms at once, and DragonForce and Qilin keep the ransomware pace up.
Black Hat week keeps handing out AI-security headlines, but the story that actually needs action today is closer to home: the N-central fix you applied last week didn't stick, and the federal deadline to remediate is today. Add a perfect-10 credential-reuse bug spanning three widely used platforms, two ransomware crews working two days apart, and a threat report that puts hard numbers on how far defenders have fallen behind — here's what actually matters before your next client call.
N-central's Patch Didn't Hold — and CISA's Deadline Is Today
CVE-2026-18577, an authentication bypass in N-able N-central, turned out to be an incomplete fix for the CVE-2026-18556 bypass CISA flagged just days earlier. Exploitation has been observed in the wild since August 1, CISA added it to the Known Exploited Vulnerabilities catalog on August 3, and the mitigation deadline for federal agencies lands today, August 6. Attackers who get in are using N-central's own Take Control feature to pivot into managed endpoints, then deploying Cloudflare Tunnel for persistent remote access. It's fixed in version 2026.3 HF1.
Why it matters: if you or a client run N-central, this isn't homework you can defer — attackers are already inside via this exact bypass, weaponizing the platform's own remote-control feature against you. Patch to 2026.3 HF1 and hunt for unexpected Cloudflare Tunnel installs today, not this week.
The Hacker News: CISA Adds Exploited N-able N-central Flaw to KEV · Rapid7: CVE-2026-18577 Exploited in the Wild
A Perfect-10 Credential Bug Ships Alongside Veeam and Django Patches
HashiCorp's Terraform MCP Server, Veeam Service Provider Console, and Django all pushed critical fixes this week, but the one to lose sleep over is CVE-2026-16498 (CVSS 10.0) — a cross-tenant credential-reuse flaw in Terraform MCP Server's stateless HTTP mode that could let one user's Terraform token get replayed to run tool calls on someone else's behalf. Veeam's VSPC, the multi-tenant console MSPs use to run customer backups, picked up four fixes of its own led by CVE-2026-58073 (9.5), letting an unauthenticated attacker impersonate a managed agent and steal its credentials. Django's Active Storage bug (CVE-2026-66066) lets unauthenticated attackers read arbitrary files on the server, a potential stepping stone to RCE.
Why it matters: anyone running Terraform MCP Server in multi-user HTTP mode or VSPC below 9.3.0.35057 needs to patch now — this is exactly the shared-infrastructure bug class that turns one compromised tenant into every tenant. It's also a preview of the growing pains coming for anyone centralizing AI-agent tool access across multiple clients via MCP.
DragonForce and Qilin Keep the Ransomware Pace Up
DragonForce claimed TUI China on August 3, threatening to leak passports, visas, and financial and legal documents if the tourism giant doesn't pay — the group has now claimed 631 victims total, 43 of them in the last 30 days alone. A day later, Qilin claimed Freedom Claims Management, a U.S. insurance servicer, with its own data-exposure threats.
Why it matters: two different RaaS crews, two days apart, both hitting mid-market targets in sectors — travel, insurance — that hold exactly the passport, financial, and health data clients like to assume is "somebody else's problem." Good reminder for any client who still thinks ransomware only goes after the Fortune 500.
DeXpose: DragonForce Compromises TUI China · DeXpose: Qilin Ransomware Attack on Freedom Claims Management
Attackers Now Break Out in 29 Minutes. Patching Still Takes 43 Days.
Dataminr's 2026 Cyber Threat Landscape Report finds the median time to patch a vulnerability climbed from 32 to 43 days in the first half of 2026, while average attacker breakout time — first access to lateral movement — fell to just 29 minutes. AI is cutting both ways: it's surfacing more vulnerabilities than ever, but that's overwhelming the same teams still triaging them by hand.
Why it matters: that gap is the entire pitch for managed detection and faster patch cycles, in one stat. Steal it for your next QBR.
SOCRadar Tries to Make Sense of the Credential-Leak Firehose
SOCRadar launched Human Identity Exposure at Black Hat this week, folding breach repositories, stealer-log infections, PII leaks, and attacker telemetry into a single scored record per identity — complete with modeled attack paths (credential stuffing, SIM swap, BEC) and a one-click exposure report.
Why it matters: any MSSP drowning analysts in disconnected "here's another leaked password" alerts should take a look. Turning that noise into an actual attack path is the difference between an alert nobody reads and a service you can sell.
MSSP Alert: SOCRadar Connects the Dots on Credential Leaks · CIO Influence: SOCRadar Launches Human Identity Exposure
That's the stack for today: patch N-central before end of day, check your Terraform MCP Server and VSPC versions, and remind clients that ransomware crews don't check revenue before they knock. See you tomorrow.
— The ChannelBytes Team





