Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

N-central Zero-Day Gives Attackers a Remote-Control Bridge Into Critical Servers

N-central Zero-Day Gives Attackers a Remote-Control Bridge Into Critical Servers
Photo by Tima Miroshnichenko on Pexels

Sophos researchers observed attackers exploiting an N-able N-central authentication bypass to reach domain controllers, backup infrastructure and application servers. The intruders deployed multiple legitimate remote-management products, established covert network tunnels and attempted to disable endpoint security, demonstrating how a compromised management platform can rapidly become an enterprise-wide access point.

News Date: 2026-08-05

A security tool intended to simplify remote administration became a powerful intrusion channel after attackers exploited a vulnerability in N-able's N-central platform. Sophos researchers documented an incident in which the compromised management server was used to reach high-value systems, including domain controllers, application servers and backup infrastructure.

A Management Console Becomes an Attack Hub

The incident involved CVE-2026-18577, an authentication bypass affecting hosted and on-premises N-central deployments. N-able released a hotfix on August 2 after determining that exploitation had begun as a zero-day on July 31. The issue has been linked to an incomplete correction for an earlier vulnerability, although N-able had not directly confirmed that relationship when Sophos published its analysis.

Once inside the affected environment, the attackers created a domain account named veeam, reset administrator passwords and enumerated privileged users. They then installed several legitimate remote-monitoring tools, including AnyDesk, TeamViewer, RustDesk, TacticalRMM, SimpleHelp and HopToDesk.

The intruders also deployed Cloudflare Tunnel components under filenames designed to resemble Microsoft software. This provided a persistent communications path that could blend into legitimate encrypted traffic. When endpoint protection was detected, the attackers used the PhantomKiller tool to interfere with security processes.

What Administrators Should Do

  • Apply the N-central hotfix immediately and verify that every management server is running the corrected release.
  • Review newly created accounts, administrator password changes and remote-control sessions dating back to July 31.
  • Search for unexpected remote-management software and unauthorized Cloudflare Tunnel installations.
  • Rotate privileged credentials and investigate activity involving domain controllers, backup servers and security consoles.
  • Restrict management interfaces to trusted networks and require strong, phishing-resistant authentication.

Why This Incident Matters

RMM platforms possess the access attackers would otherwise spend days trying to obtain. They can execute software, control endpoints and operate through channels that administrators expect to see.

In my view, patching the server is only the first step. Any organization with an exposed N-central deployment should assume that successful exploitation may have produced secondary access mechanisms. A thorough compromise assessment is essential because removing the original vulnerability will not disable accounts, tunnels or remote-control agents already planted by an attacker.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path