AI Stories on SHORT INFO are generated & curated with AI
unverified 13 Aug, 20:11

Storm-1175 deploys new StormEncryptor ransomware exploiting N-able flaw

Microsoft says the ransomware group it tracks as Storm-1175, previously linked to Medusa attacks, is deploying a new strain called StormEncryptor by exploiting an authentication-bypass flaw in N-able $NABL's N-central product. The bug was disclosed August 2 and added to CISA's kn

Microsoft Threat Intelligence is tracking a new ransomware campaign from Storm-1175, a financially motivated group previously associated with Medusa ransomware deployments. The actor has begun deploying a custom C++-based strain called StormEncryptor, marking its first observed activity since April. The attacks appear to exploit CVE-2026-18577, an authentication-bypass vulnerability in N-able's $NABL N-central remote monitoring and management product. The flaw was publicly disclosed on August 2 and added to CISA's Known Exploited Vulnerabilities catalog the following day. StormEncryptor appends the extension .encrypted to files it locks and leaves a ransom note titled !!!README_FIRST!!! in every directory it scans. The rapid turnaround between disclosure and exploitation fits Storm-1175's established pattern of weaponizing newly disclosed vulnerabilities before organizations can patch. Remote monitoring and management tools like N-central sit deep inside IT departments' infrastructure, meaning a single unpatched flaw can give an attacker a foothold across every client network a managed service provider touches, not just one company.

#cyber
Published on
FacebookBlueskyXThreads