By Nemuel Cruz, Incognito CyberSecurity™
Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to small businesses across Southern Arizona. Here is a plain-English roundup of the cybersecurity events that unfolded over the weekend, and what each one means for the businesses we protect.
1. Critical Progress LoadMaster flaw hits CISA’s must-patch list
CISA added a critical command-injection flaw in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) to its Known Exploited Vulnerabilities catalog after roughly 792 exploitation attempts were tracked from dozens of IP addresses worldwide. An unauthenticated attacker can run arbitrary commands on the appliance, and federal agencies were ordered to patch by August 10.
What to do: If your office runs a Kemp/Progress LoadMaster load balancer, apply the vendor patch now and restrict its management interface to trusted internal addresses only. Not sure whether one sits on your network? Our network solutions team can inventory your edge devices and confirm they are patched.
2. N-able N-central under active attack — an MSP-tool wake-up call
N-able warned that attackers are exploiting an authentication-bypass vulnerability (CVE-2026-18577) in its N-central remote monitoring and management platform. Hosted deployments were auto-patched, but on-premises customers must apply the emergency hotfix themselves. RMM tools are high-value targets because they reach into every managed machine at once.
What to do: Ask any IT provider that touches your systems whether their remote-management tools are patched and protected with multi-factor authentication. This is exactly the kind of exposure our server and workstation management service is built to close.
3. Helix ransomware gang claims a real-estate victim
The Helix ransomware group announced an attack on Morguard, a large Canadian real-estate firm, and threatened to leak stolen data after negotiations stalled. It is another reminder that ransomware crews now steal data first and encrypt second, so paying rarely makes the problem disappear.
What to do: Assume a breach will happen and prepare to recover without paying. Keep offline, secure data backups that are tested regularly, and make sure at least one copy is isolated from your everyday network.
4. Phishing campaign hijacks Microsoft 365 accounts
Researchers flagged a widespread email phishing campaign using adversary-in-the-middle techniques to steal login sessions and take over Microsoft 365 accounts. Because it captures the live session token, this method can slip past basic password protection.
What to do: Turn on phishing-resistant multi-factor authentication for every Microsoft 365 user and train staff to log in only from your real sign-in page. Layered spam and virus filtering stops most of these lures before they ever reach an inbox.
5. “ClickFix” fake-fix pages spread a credential-stealing malware
Attackers are using ClickFix-style prompts — fake error messages that tell you to paste a command to “fix” a problem — to deliver a Go-based infostealer that grabs cryptocurrency, browser-saved passwords, and cached credentials. One click by one employee can hand over the keys to your accounts.
What to do: Teach your team to never paste commands they did not write into a terminal or Run box, no matter how convincing the pop-up looks. Modern endpoint protection can catch and block this malware before it steals anything.
6. Voice-phishing crews target professional-services firms
An extortion group tracked as UNC6671 is running voice-phishing (vishing) calls against law firms, hedge funds, and private-equity firms, talking employees into granting access to corporate systems. Small professional offices are attractive because they hold sensitive client data but often lack a dedicated security team.
What to do: Set a simple rule: no one grants remote access or resets credentials based on a phone call alone — verify through a known internal channel first. Our small business cybersecurity solutions include the staff training and verification policies that shut these scams down.
The bottom line
Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to businesses across Southern Arizona. Weekends are when attackers count on nobody watching — we watch so you do not have to. Contact Incognito Cyber Security to get these protections in place before the next headline lands.


