惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
Y
Y Combinator Blog
月光博客
月光博客
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
有赞技术团队
有赞技术团队
博客园 - 司徒正美
V
Visual Studio Blog
小众软件
小众软件
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
The Cloudflare Blog

Sophos Blogs

Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation 2026 MSP Perspectives Report: How MSPs Are Scaling Cybersecurity Leadership Sophos Next-Gen SIEM Unifies Security Operations and Compliance Messageboards Are All They Need ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split Devil’s advocate? Uncensored Luciferus AI service advertised underground “Eye” spy: Cyclops Blink returns with extended capabilities Ransomware in Education 2026: Key Findings Sophos Joins OpenAI’s Call for Collective Cyber Defense Sophos Ranked #1 Overall Across Endpoint, XDR, MDR, and Firewall in G2 Fall 2026 Reports Fake AI, real malware: Attackers impersonating AI brands A heap of overflow in August’s Patch Tuesday haul Accelerating NetNTLMv1 Lookups Without GPUs Abuse of alternative runtime environments Deno-tes defender headaches ClickFix campaign abuses Deno runtime for infostealer delivery Sophos Working with OpenAI on security from AI, with AI, and for AI Interlock ransomware gang creates volatile situation When AI doesn’t know the target is real Chaos in Teams vishing Why Sophos Has Become Its Own AI Test Lab July Patch Tuesday only feels endless SonicWall SMA1000 vulnerabilities in active exploitation When AI agents look like attackers: what behavioral telemetry tells us Sophos and the Cybersecurity Poverty Line You do surprise me.exe: An unexpected executable in Hola Browser You do surprise me.exe: An unexpected executable in Hola Browser Pointing a Cursor at evading detection Pointing a Cursor at evading detection Pointing a Cursor at evading detection Canvas attack aftermath: What risks come next
N-able N-central exploitation results in RMM tool deployment
About the Author(s) · 2026-08-04 · via Sophos Blogs

On August 1, 2026, N-able released an advisory disclosing active exploitation of a vulnerability affecting the N-central remote monitoring and management (RMM) platform. The vulnerability (CVE-2026-18577) is characterized as an authentication bypass that allows privileged access to the management interface of the platform in both hosted and on-premises implementations. An incomplete fix for CVE-2026-18556 published on August 1 has been reported as the underlying cause, though N-able has not directly confirmed the assertion. N-able published a hotfix to address CVE-2026-18577 on August 2 and included details about observed exploitation activity. On August 4, N-able published an additional advisory indicating that exploitation began on July 31 as a zero-day vulnerability.

Sophos Counter Threat Unit™ (CTU) researchers identified a single compromised organization in Sophos customer telemetry and have observed no evidence that compromises are widespread. The victim was compromised at approximately 08:00 UTC on August 3, and the threat actor used the compromised N-central server to access high-value endpoints such as a backup server, domain controllers, and application servers.

Attack details

During the intrusion, the threat actor created a new domain account named “veeam” and reset the passwords of several existing domain administrator accounts. Several “net user” commands were executed to enumerate existing accounts within the network. Additionally, two network reconnaissance commands were executed:

  • nltest /dclist:
  • net group “domain admins” /domain

With the remote control ability granted through exploitation of N-central, the threat actor deployed numerous RMM tools to accessible endpoints. These tools included AnyDesk (AnyDesk.exe), TacticalRMM (installed via a install_server.ps1 PowerShell script and package tacticalagent-v2.11.0-windows-amd64.exe), TeamViewer (team.msi and TeamViewer_Setup.exe), RustDesk (rustdesk.exe), SimpleHelp (service64off.exe), and HopToDesk. Cloudflare Tunnel (cloudflared.exe) was installed on several hosts but was renamed as MicrosoftEdgeUpdate64.exe or msmp.exe to masquerade as a benign file. The threat actor used this tunnel to obtain persistent remote access to the environment.

N-able indicated that a file named svchost.exe in a user’s Documents directory (i.e., %USERPROFILE%\Documents) can reveal that the system has been compromised, but CTU researchers did not observe this filename in the victimized Sophos customer’s environment. It is possible that svchost.exe is one of the legitimate Windows filenames used by the threat actors to obscure cloudflared.exe.

The threat actor used the “tasklist” command with output piped to “findstr ms” and “findstr soph” to identify hosts running Microsoft Defender or Sophos agents, respectively. When a security product was identified, the PhantomKiller endpoint detection and response (EDR) evasion tool loaded a driver named k.sys, which was located in C:\ProgramData\AnyDesk. In one instance, PhantomKiller (named 9.exe) terminated the Sophos File Scanner process (sophosfilescanner.exe).

Recommendations, countermeasures, and indicators

CTU™ researchers advise organizations that use N-central to apply the hotfix as appropriate in their environments as soon as possible. Organizations should also search their environment for evidence that could indicate a compromise and respond accordingly.

The following Sophos countermeasure relates to this threat:

  • CXmal/KillAV-BR

The threat indicators in Table 1 can be used to detect activity related to this threat. Note that IP addresses can be reallocated. The domains and IP addresses may contain malicious content, so consider the risks before opening them in a browser.

IndicatorTypeContext
173[.]249[.]252[.]200IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
172[.]249[.]252[.]176IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
87[.]249[.]138[.]34IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577) (Note that this suspected NordVPN egress node will likely be associated with unrelated traffic)
37[.]19[.]210[.]32IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577) (Note that this suspected Mullvad VPN egress node will likely be associated with unrelated traffic)
68[.]235[.]46[.]214IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
68[.]235[.]46[.]235IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
37[.]153[.]90[.]88IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
92[.]118[.]112[.]181IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
23[.]234[.]94[.]43IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
185[.]156[.]46[.]150IP addressUsed to identify and exploit N-able N-central vulnerability (CVE-2026-18577)
who-ripped-one[.]direct[.]quickconnect[.]toDomain nameC2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577)
mousears[.]synology[.]meDomain nameC2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577)
wagoosh[.]direct[.]quickconnect[.]toDomain nameC2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577)
api[.]mendoratech[.]healthDomain nameTacticalRMM server used during exploitation of N-able N-central vulnerability (CVE-2026-18577)

Table 1: Indicators for this threat