Select a theme from the list.
Insights

From our experts

Latest
Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development Platform
Security Insight

N-central Zero-Day Gives Attackers a Remote-Control Bridge Into Critical Servers

N-central Zero-Day Gives Attackers a Remote-Control Bridge Into Critical Servers
Photo by Tima Miroshnichenko on Pexels

Sophos researchers observed attackers exploiting an N-able N-central authentication bypass to reach domain controllers, backup infrastructure and application servers. The intruders deployed multiple legitimate remote-management products, established covert network tunnels and attempted to disable endpoint security, demonstrating how a compromised management platform can rapidly become an enterprise-wide access point.

News Date: 2026-08-05

A security tool intended to simplify remote administration became a powerful intrusion channel after attackers exploited a vulnerability in N-able's N-central platform. Sophos researchers documented an incident in which the compromised management server was used to reach high-value systems, including domain controllers, application servers and backup infrastructure.

A Management Console Becomes an Attack Hub

The incident involved CVE-2026-18577, an authentication bypass affecting hosted and on-premises N-central deployments. N-able released a hotfix on August 2 after determining that exploitation had begun as a zero-day on July 31. The issue has been linked to an incomplete correction for an earlier vulnerability, although N-able had not directly confirmed that relationship when Sophos published its analysis.

Once inside the affected environment, the attackers created a domain account named veeam, reset administrator passwords and enumerated privileged users. They then installed several legitimate remote-monitoring tools, including AnyDesk, TeamViewer, RustDesk, TacticalRMM, SimpleHelp and HopToDesk.

The intruders also deployed Cloudflare Tunnel components under filenames designed to resemble Microsoft software. This provided a persistent communications path that could blend into legitimate encrypted traffic. When endpoint protection was detected, the attackers used the PhantomKiller tool to interfere with security processes.

What Administrators Should Do

  • Apply the N-central hotfix immediately and verify that every management server is running the corrected release.
  • Review newly created accounts, administrator password changes and remote-control sessions dating back to July 31.
  • Search for unexpected remote-management software and unauthorized Cloudflare Tunnel installations.
  • Rotate privileged credentials and investigate activity involving domain controllers, backup servers and security consoles.
  • Restrict management interfaces to trusted networks and require strong, phishing-resistant authentication.

Why This Incident Matters

RMM platforms possess the access attackers would otherwise spend days trying to obtain. They can execute software, control endpoints and operate through channels that administrators expect to see.

In my view, patching the server is only the first step. Any organization with an exposed N-central deployment should assume that successful exploitation may have produced secondary access mechanisms. A thorough compromise assessment is essential because removing the original vulnerability will not disable accounts, tunnels or remote-control agents already planted by an attacker.

Talk to our team →

Latest

Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesSep 10, 2026Unpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemSep 10, 2026Passkey Reset Scams Turn Strong Authentication Into Cloud PersistenceSep 10, 2026Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3IDScan Lawsuits Put Mass Identity Collection Under the Microscope4French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning5Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching6Scattered Spider's Cyberattack on Marks & Spencer Exposes Retail Vulnerabilities