惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
M
MIT News - Artificial intelligence
D
Docker
S
SegmentFault 最新的问题
B
Blog
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
U
Unit 42
C
Check Point Blog
GbyAI
GbyAI
美团技术团队
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
Visual Studio Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog

N-able

Why CVSS alone isn't prioritization anymore - N-able N-central Security Hotfix – September 5, 2026 - N-able Firewall Configuration Guide for Cove’s Move to Mutual TLS - N-able Vulnerability Remediation for IT Teams - N-able AI changed how attackers operate - N-able Cutting Dwell Time in Cybersecurity: A Practical Guide - N-able MSP Pricing Guide: Security-Inclusive Tiers That Scale - N-able Mail Assure: Homograph Detection & Sharper Email Reporting VoluNteer Spotlight: Magdalena Jasinska - N-able EDR vs Antivirus: A Comparison for Modern Endpoint Security - N-able SOC Compliance Explained: Types, Requirements, Steps - N-able Threat Hunting as a Service for MSPs and IT Teams - N-able Smishing in Cybersecurity: Spot and Stop SMS Scams - N-able Outsourced SOC: Costs, Benefits, and How to Choose - N-able Security Incident Response Metrics: Measure What Matters - N-able Disaster Recovery Test: Methods, Steps, and Cadence - N-able When exploits move in hours, patching must move faster - N-able Security Operations Management for MSPs and IT Teams - N-able Proactive Threat Hunting Framework: Step-by-Step Guide - N-able BCDR Essentials: Build Resilient Continuity Plans - N-able Cove Data Protection wins Omdia BDR Champion award - N-able MTTD vs MTTR: Cut Downtime with Faster Detection - N-able AI Governance and Accountability: How to Prove What Your AI Is Doing A Solid IT Disaster Recovery Plan Guide How MDR Fits Into Ransomware Defense Why backup belongs in the service desk The Hard Part of Mac Patching Is Not the Patch, It’s the Workflow AI Risk Management: When AI Moves from Suggestion to Action Spear Phishing vs. Phishing: Where the Real Damage Comes From Threat Actors in 2026: Types, Targets, and Defense
N-central Security Update – August 10, 2026 - N-able
N-able · 2026-08-10 · via N-able

We know the last week and a half hasn’t been easy. Patch notifications, urgent emails, and open questions take a real toll on your team, your customers, and your confidence in the tools you rely on. In moments like this, everyone wants the same thing: real information, fast. That’s what we’re focused on, giving you as much detail as we can, as rapidly, transparently, and safely as possible, so you always have a clear picture of where things stand.

If you have not yet applied Hotfix 2 (2026.3.1.10), please do so immediately. Download here.

What happened: how we found it

On July 31, our Adlumin MDR solution detected unusual activity inside a customer environment and identified a threat actor actively exploiting a previously unknown vulnerability in N‑central. We want to be straightforward about this: we detected this ourselves, in real time. That matters, not because we want recognition for it, but because it is evidence that layered, continuous security monitoring works. It is also the reason we were able to respond as quickly as we did.

Once identified, our engineering and security teams mobilized immediately. We published guidance the same day, registered CVE-2026-18556, and released Hotfix 1 (2026.3.1.7) on August 2, and registered CVE-2026-18577. When continued monitoring on August 6 surfaced a related attack path, we released Hotfix 2 (2026.3.1.10) the same day with additional hardening measures that build on and supersede Hotfix 1.

Our support team is prioritizing upgrade assistance. If you need help, please reach out at me.n-able.com and we will be there.

The attack

A threat actor exploited a vulnerability in N‑central that allowed remote administrative access without authentication. Once inside, they used N‑central’s Take Control feature to connect to managed devices, and registered Cloudflare tunnel services on those devices to maintain persistence even after their access to N‑central was revoked. Hotfix 1 addressed the original access point. Continued monitoring identified a related attack path, which Hotfix 2 addresses with additional hardening.

The impact

A limited number of customers have been identified as impacted, and our team has directly engaged with each of them. If you have heard from us, you have a dedicated point of contact and we are with you. Our investigation remains active and ongoing and we are not calling this closed until we are fully confident in that conclusion.

On transparency: what we can and can’t share right now

We hear you. The desire for more detail, especially technical specifics, is completely understandable, and you deserve a straight answer about why we haven’t shared more.

We are also aware that some of you have seen technical details and commentary circulating from third parties. We understand that can be frustrating when it feels like others are saying more than we are. Our deliberate focus throughout this incident has been on providing the facts our customers need to protect their environments—not speculating on attack vectors or amplifying information that we cannot fully verify. Sharing unconfirmed technical details, even with good intentions, can give threat actors useful information and create confusion that makes it harder, not easier, for you to respond.

Releasing specific technical details while threat actors are still active also gives them information they can use. We made a deliberate decision to protect our customers first and explain later. A full root cause analysis is coming, and we will share it as soon as it is safe to do so.

What we can commit to in the meantime: regular updates, even when the news is simply that our investigation is continuing. A gap in communication should never be mistaken for a gap in effort. Our teams are working around the clock.

You are part of this

Many of you acted quickly: applying patches, reviewing your environments, flagging concerns, and holding us accountable. That matters more than you know. You are not just our customers; you are part of our extended security team. The businesses you protect depend on both of us, and we do not take that lightly.

This kind of security event tests partnerships. We believe transparency, speed, and standing behind our customers when it is hard are what define our partnership with you. We intend to keep earning that trust.

Timeline: what happened

  • Jul 31 Adlumin MDR detects unusual activity; threat actor identified. Response team engaged immediately.
  • Aug 1 First public guidance issued; upgrade recommendation posted. First CVE registered.
  • Aug 2 Second CVE registered. Hotfix 1 (2026.3.1.7) released and mitigation deployed to hosted environments. Customers notified directly.
  • Aug 6 Related attack path identified through continued monitoring. Hotfix 2 (2026.3.1.10) released same day and mitigation deployed to hosted environments. Customers notified directly.
  • Ongoing Investigation, hardening, and direct customer support continues.

If you delayed upgrading, please read this carefully

Applying Hotfix 2 closes the vulnerability that allowed attackers in, but it does not remove a threat actor who may already be present in your environment. For customers who have waited to patch, it is critical to understand that during that window, attackers have been observed creating new accounts and resetting existing ones to maintain persistence. Upgrading is an essential first step, but it is not the last one. If you applied either hotfix more than a few days after it was released, you should treat your environment as potentially compromised and conduct a thorough review of all user accounts, access privileges, and activity—regardless of what our IOC scanning tool returns. If you find anything unusual or need assistance with that review, please contact our support team immediately at me.n-able.com.

Indicators of compromise

  • A file named “svchost.exe” in a user’s Documents directory
  • A registered service named “Cloudflared”
  • Unusual Take Control activity or unauthorized actions on managed endpoints
  • Suspicious logins to your N‑central server
  • Unexpected creation of new users
  • Unexplained user password resets
  • Traffic from the following IP addresses:
    73[.]249[.]252[.]200
    185[.]156[.]46[.]150
    23[.]234[.]94[.]43
    37[.]153[.]90[.]88
    37[.]19[.]210[.]32
    68[.]235[.]46[.]214
    68[.]235[.]46[.]235
    87[.]249[.]138[.]34
    92[.]118[.]112[.]181

Additional indicators will be shared as they become available. CVE: CVE-2026-18577

A custom service template is available to scan for known indicators of compromise across Windows endpoints in N‑central. Download here: https://developer.n-able.com/n-central/recipes/cve-2026-18577-detection

Please note this tool checks only for currently known indicators. A clean result is not a guarantee that your environment was not impacted. Use it as one layer of your assessment alongside a thorough review of logs, accounts, and activity in your environment.

What we ask of you

  • Stay current. Apply Hotfix 2 (2026.3.1.10) if you haven’t. Download here.
  • Enforce MFA across all accounts.
  • Unless required for an open support issue, disable your in-product support account as a best practice.
  • Audit user access and look for anything unfamiliar.
  • Monitor your environment and treat our published indicators (above) as a starting point, not a complete picture.

No software is immune to vulnerabilities. That is the reality of the world we all operate in. What separates organizations that weather these moments from those that don’t is preparation, speed, and the strength of the partnerships around them. We are committed to being that partner for you.

Resources

© N‑able Solutions ULC and N‑able Technologies Ltd. All rights reserved.

This document is provided for informational purposes only and should not be relied upon as legal advice. N‑able makes no warranty, express or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information contained herein.

The N-ABLE, N-CENTRAL, and other N‑able trademarks and logos are the exclusive property of N‑able Solutions ULC and N‑able Technologies Ltd. and may be common law marks, are registered, or are pending registration with the U.S. Patent and Trademark Office and with other countries. All other trademarks mentioned herein are used for identification purposes only and are trademarks (and may be registered trademarks) of their respective companies.