This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Microsoft Threat Intelligence
threatintel.microsoft.com
did:plc:ezrjx3qddwj4azn373c2ipdg
While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the CISA KEV catalog on August 3, 2026.
2026-08-07T21:40:03.469Z