🔴 Critical | Source: The Hacker News
N-able has issued a second hotfix for its N-central Remote Monitoring and Management (RMM) platform following active exploitation of a recently disclosed vulnerability. Attackers are moving beyond initial access to reach managed endpoints and establish persistence, meaning the blast radius extends to every device managed through affected N-central instances. This is a live, evolving incident requiring urgent action from Managed Service Providers (MSPs) and their customers.
Security Architect’s Take: If your organisation uses N-able N-central — either as an MSP or as a managed customer — apply Hotfix 2 immediately and audit managed endpoints for signs of persistence such as new scheduled tasks, unknown agents, or lateral movement indicators. Consider isolating N-central from the internet while patching and reviewing agent-level access controls across the managed estate.
Original advisory: N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist