AI Stories on SHORT INFO are generated & curated with AI
unverified 10 Aug, 16:11

Hacked remote-IT tool reached nine companies through one compromised account

N-able is warning customers that hackers exploited an authentication bypass, CVE-2026-18577, in its N-central remote management platform after an earlier patch proved incomplete, according to BleepingComputer and The Hacker News. Huntress found that on one compromised self-hosted

N-able is warning customers that hackers exploited an authentication bypass tracked as CVE-2026-18577, scored 8.2 in severity, in its N-central remote monitoring and management platform. The flaw was the result of an incomplete fix for an earlier bypass, CVE-2026-18556, that N-able had patched in version 2026.2. N-able began investigating on July 31 after an unusual volume of licensing errors from on-premises customers, and shipped hotfix build 2026.3.1.7 on August 2. After compromising an N-central server, attackers used the platform's built-in Take Control feature to reach managed endpoints downstream, then registered Cloudflare tunnels as persistent services on those devices, allowing access to survive a reboot without needing an open inbound firewall port. Incident responder Huntress said the activity it observed involved one self-hosted N-central instance within a single partner account, through which attackers accessed nine organizations, reaching one endpoint in each. Source: BleepingComputer, The Hacker News.

#cyber
Published on
YouTubeTikTokBlueskyX