Zscalar ThreatLabz 2026 Phishing and initial Access report reveals managers are the prime targets
Zscaler’s new report suggests that attackers are using a combination of publicly available and stolen information to target specific employees on extortion and initial access. The report shows that ransomware gangs are moving away from targeting executives and are focusing social engineering efforts on managers in IT, admin with many of the targets specifically those in their 40s.
Reasons for this strategy seem to be:
- While a CEO has authority, a mid-level IT manager has potential to deploy malware across the network.
- Mid-level IT managers are often targeted because they are senior enough to have meaningful access, but junior enough to still be performing hands-on technical tasks.
- Employees may be overworked and manage high volumes of technical requests making them more likely to click on an appropriately themed phishing link.
This means that ransomware gangs are starting to realize that their most vulnerable technical staff are now the primary targets. Security experts recommend “privileged access management” (limiting what one person can do) and specific mental health support to reduce the burnout that makes these employees susceptible to lapses in judgment.
N-able Releases Second N-central Hotfix Amid Active Attacks
N-able has issued a second critical security hotfix for its N-central RMM platform, urging all MSP partners to upgrade immediately — even those who already applied the first patch.
The vulnerability, CVE-2026-18577, was discovered on July 31, 2026, when N-able’s Adlumin MDR solution detected active zero-day exploitation within a customer environment. Attackers bypass authentication to access managed endpoints, establishing persistence through CloudFlare tunnels and disabling security software.
Security researchers from Sophos and Huntress have confirmed widespread post-exploitation activity, including creation of rogue domain accounts, password resets, and lateral movement across compromised networks.
Microsoft attributes the attacks to Storm-1175, a financially motivated ransomware group now deploying a new strain called StormEncryptor. The group moves rapidly from initial access to ransomware deployment, often within days.
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
Delta Air Lines is investigating a suspected Wi-Fi deauthentication attack that reportedly occurred on a flight carrying attendees to DEF CON, one of the world’s largest cybersecurity conferences. The incident drew attention after passengers experienced disruptions to the aircraft’s onboard Wi-Fi service, raising concerns that the outage may have been caused by intentional interference rather than a routine technical fault.
A deauthentication attack is a technique used to disconnect devices from a wireless network by sending spoofed management frames, forcing users offline and potentially creating opportunities for further network manipulation. While there is currently no indication that any critical aircraft systems were affected, the event highlights the growing challenges of securing wireless communications in increasingly connected environments. Delta is continuing to investigate the circumstances surrounding the disruption to determine whether malicious activity was involved, and the case serves as a reminder of the importance of robust cybersecurity measures across all aspects of modern transportation technology.
Sandworm Campaign Uses Trojanised WireGuard Client to Target IT Professionals
A new cyberespionage campaign, linked to the state-sponsored hacking group Sandworm, is targeting IT professionals through a trojanised version of the popular WireGuard VPN client. According to researchers, attackers distributed a malicious installer that appeared legitimate but secretly deployed malware designed to establish persistence and provide remote access to compromised systems.
The campaign specifically focused on technology and infrastructure personnel who regularly use VPN software to manage networks and remote environments. By disguising the malware as trusted networking software, the attackers increased the likelihood of successful infections and credential theft.
Researchers warn that the operation reflects Sandworm’s continued use of supply chain and software impersonation tactics to gain access to high-value targets. The incident serves as a reminder that even widely trusted tools can be weaponized when obtained from unofficial sources. Organisations should ensure employees download software only from verified vendors, monitor endpoint activity for unusual behaviour, and maintain strong security controls to detect malicious installations before they lead to broader network compromise.
Analyst Insight
These incidents highlight how threat actors are increasingly targeting the people, platforms, and technologies that offer the most efficient path to organisational compromise. The Zscaler ThreatLabz report shows ransomware operators shifting their focus from executives to mid-level IT and administrative managers, whose combination of privileged access and day-to-day technical responsibilities makes them valuable targets for phishing and social engineering.
The active exploitation of N-able’s N-central vulnerability further demonstrates how quickly threat groups can weaponise newly discovered flaws to gain access, establish persistence, and deploy ransomware across multiple environments. Meanwhile, the suspected Wi-Fi deauthentication attack on a Delta flight carrying DEF CON attendees highlights the ongoing risks facing wireless communications in connected environments, even where critical systems remain unaffected. The Sandworm campaign using a trojanised WireGuard client also reinforces the effectiveness of software impersonation and supply chain-style tactics, particularly against IT professionals who rely on trusted administrative tools.
Collectively, these incidents emphasise the importance of strong privileged access management, timely patching, software verification controls, security awareness training, and continuous monitoring to defend against both financially motivated and state-sponsored threat actors.
