AI Stories on SHORT INFO are generated & curated with AI
unverified 09 Aug, 08:10

N-able N-central Zero-Day Lets Hackers Bypass Login, CISA Adds Flaw to Active-Exploit List

A newly disclosed authentication-bypass flaw in N-able's $NABL N-central remote management platform is being actively exploited, letting hackers seize administrative control and reach into every client computer the software manages. N-able confirmed a limited number of customers

A newly disclosed authentication-bypass flaw in N-able's $NABL N-central remote monitoring and management platform is being actively exploited by hackers, letting them skip login entirely and seize full administrative control of the server. From there, attackers can pivot into every client computer the platform manages using its own remote-access feature. N-able confirmed a limited number of customers were compromised before releasing an emergency hotfix, and the security firm Huntress has tracked attackers scouting domain controllers inside victim networks. The US Cybersecurity and Infrastructure Security Agency has added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies days to patch. Remote management software sits on thousands of networks at once, meaning this single flaw can ripple out to every small business that outsources its IT.

#cyber
Published on
YouTubeBlueskyX