惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
H
Help Net Security
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
D
Docker
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
博客园 - Franky
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
L
LangChain Blog
量子位
V
Visual Studio Blog
Y
Y Combinator Blog
小众软件
小众软件
N
Netflix TechBlog - Medium
博客园 - 三生石上(FineUI控件)
Microsoft Security Blog
Microsoft Security Blog
雷峰网
雷峰网

Sophos Blogs

Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation 2026 MSP Perspectives Report: How MSPs Are Scaling Cybersecurity Leadership Sophos Next-Gen SIEM Unifies Security Operations and Compliance Messageboards Are All They Need ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split Devil’s advocate? Uncensored Luciferus AI service advertised underground “Eye” spy: Cyclops Blink returns with extended capabilities Ransomware in Education 2026: Key Findings Sophos Joins OpenAI’s Call for Collective Cyber Defense Sophos Ranked #1 Overall Across Endpoint, XDR, MDR, and Firewall in G2 Fall 2026 Reports Fake AI, real malware: Attackers impersonating AI brands A heap of overflow in August’s Patch Tuesday haul Accelerating NetNTLMv1 Lookups Without GPUs Abuse of alternative runtime environments Deno-tes defender headaches ClickFix campaign abuses Deno runtime for infostealer delivery Sophos Working with OpenAI on security from AI, with AI, and for AI Interlock ransomware gang creates volatile situation When AI doesn’t know the target is real Chaos in Teams vishing Why Sophos Has Become Its Own AI Test Lab July Patch Tuesday only feels endless SonicWall SMA1000 vulnerabilities in active exploitation When AI agents look like attackers: what behavioral telemetry tells us Sophos and the Cybersecurity Poverty Line You do surprise me.exe: An unexpected executable in Hola Browser You do surprise me.exe: An unexpected executable in Hola Browser Pointing a Cursor at evading detection Pointing a Cursor at evading detection Pointing a Cursor at evading detection Canvas attack aftermath: What risks come next
N-able N-central exploitation results in RMM tool deployment
About the Author(s) · 2026-08-04 · via Sophos Blogs

On August 1, 2026, N-able released an advisory disclosing active exploitation of a vulnerability affecting the N-central remote monitoring and management (RMM) platform. The vulnerability (CVE-2026-18577) is characterized as an authentication bypass that allows privileged access to the management interface of the platform in both hosted and on-premises implementations. An incomplete fix for CVE-2026-18556 published on August 1 has been reported as the underlying cause, though N-able has not directly confirmed the assertion. N-able published a hotfix to address CVE-2026-18577 on August 2 and included details about observed exploitation activity. On August 4, N-able published an additional advisory indicating that exploitation began on July 31 as a zero-day vulnerability.

Sophos Counter Threat Unit™ (CTU) researchers identified a single compromised organization in Sophos customer telemetry and have observed no evidence that compromises are widespread. The victim was compromised at approximately 08:00 UTC on August 3, and the threat actor used the compromised N-central server to access high-value endpoints such as a backup server, domain controllers, and application servers.

Attack details

During the intrusion, the threat actor created a new domain account named “veeam” and reset the passwords of several existing domain administrator accounts. Several “net user” commands were executed to enumerate existing accounts within the network. Additionally, two network reconnaissance commands were executed:

  • nltest /dclist:
  • net group “domain admins” /domain

With the remote control ability granted through exploitation of N-central, the threat actor deployed numerous RMM tools to accessible endpoints. These tools included AnyDesk (AnyDesk.exe), TacticalRMM (installed via a install_server.ps1 PowerShell script and package tacticalagent-v2.11.0-windows-amd64.exe), TeamViewer (team.msi and TeamViewer_Setup.exe), RustDesk (rustdesk.exe), SimpleHelp (service64off.exe), and HopToDesk. Cloudflare Tunnel (cloudflared.exe) was installed on several hosts but was renamed as MicrosoftEdgeUpdate64.exe or msmp.exe to masquerade as a benign file. The threat actor used this tunnel to obtain persistent remote access to the environment.

N-able indicated that a file named svchost.exe in a user’s Documents directory (i.e., %USERPROFILE%\Documents) can reveal that the system has been compromised, but CTU researchers did not observe this filename in the victimized Sophos customer’s environment. It is possible that svchost.exe is one of the legitimate Windows filenames used by the threat actors to obscure cloudflared.exe.

The threat actor used the “tasklist” command with output piped to “findstr ms” and “findstr soph” to identify hosts running Microsoft Defender or Sophos agents, respectively. When a security product was identified, the PhantomKiller endpoint detection and response (EDR) evasion tool loaded a driver named k.sys, which was located in C:\ProgramData\AnyDesk. In one instance, PhantomKiller (named 9.exe) terminated the Sophos File Scanner process (sophosfilescanner.exe).

Recommendations, countermeasures, and indicators

CTU™ researchers advise organizations that use N-central to apply the hotfix as appropriate in their environments as soon as possible. Organizations should also search their environment for evidence that could indicate a compromise and respond accordingly.

The following Sophos countermeasure relates to this threat:

  • CXmal/KillAV-BR

The threat indicators in Table 1 can be used to detect activity related to this threat. Note that IP addresses can be reallocated. The domains and IP addresses may contain malicious content, so consider the risks before opening them in a browser.

IndicatorTypeContext
173[.]249[.]252[.]200IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
172[.]249[.]252[.]176IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
87[.]249[.]138[.]34IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577) (Note that this suspected NordVPN egress node will likely be associated with unrelated traffic)
37[.]19[.]210[.]32IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577) (Note that this suspected Mullvad VPN egress node will likely be associated with unrelated traffic)
68[.]235[.]46[.]214IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
68[.]235[.]46[.]235IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
37[.]153[.]90[.]88IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
92[.]118[.]112[.]181IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
23[.]234[.]94[.]43IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
185[.]156[.]46[.]150IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
who-ripped-one[.]direct[.]quickconnect[.]toDomain nameC2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577)
mousears[.]synology[.]meDomain nameC2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577)
wagoosh[.]direct[.]quickconnect[.]toDomain nameC2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577)
api[.]mendoratech[.]healthDomain nameTacticalRMM server used during exploitation of N-able N-central vulnerability (CVE-2026-18577)

Table 1: Indicators for this threat