🔴 Critical | Source: The Register — Security
N-able has confirmed that attackers exploited a critical privilege escalation flaw in its N-central remote monitoring and management platform, using administrative access to pivot downstream into customer networks. A second hotfix has been issued after the first proved insufficient. The incident highlights the severe supply chain risk posed by RMM tools, which by design hold broad access to managed environments.
Security Architect’s Take: If your organisation uses N-central, apply the latest hotfix immediately and audit downstream access logs for lateral movement or unusual admin activity originating from N-able infrastructure. Consider temporarily restricting N-central’s network reach to only essential endpoints until you can confirm your environment was not traversed.
Original advisory: N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands