IT Security News Roundup: 2026-09-08

IT Security News: today roundup

  • N-able patched a critical N-central zero-day vulnerability after attackers created unrecognized user accounts on compromised systems.
  • A market review evaluated FWaaS providers, highlighting Cloudflare for affordability, Cato Networks for simplicity, and Prisma Access.
  • Palo Alto Cortex XDR topped a 2026 ranking of detection platforms, followed by CrowdStrike and Microsoft Defender.
  • Threat actors are actively exploiting critical RouterOS flaws to compromise internet-exposed MikroTik routers over SSH.
  • CrowdStrike Falcon Complete led a 2026 evaluation of MDR services, with Expel and Huntress also receiving top ratings.
  • Attackers breached Mathspace’s self-hosted Metabase database instance, compromising personal information belonging to over one million users.
  • Zscaler emerged as the top FWaaS vendor for 2026 on the strength of its massive dedicated cloud network.
  • ASUS patched a missing-authentication vulnerability in Control Center Express Agent that allowed unauthenticated nearby attackers host takeover.
  • Cloudflare earned the top WAF ranking for 2026 due to its threat visibility network and value per dollar.
  • Elastic Security Labs uncovered REVSTEALER malware using persistent helper programs to mine cryptocurrency and harvest wallet data.

Sources