Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
N-central Hotfix 2 Released Amid Security Concerns

N-central Hotfix 2 Released Amid Security Concerns

Posted on August 8, 2026 By CWS

N-able has introduced a new hotfix for its N-central platform in response to ongoing security threats exploiting a vulnerability in their Remote Monitoring and Management (RMM) system. This release aims to bolster defenses against evolving cyber attack strategies.

Proactive Security Measures

The company has emphasized the necessity of deploying Hotfix 2, even for those who have previously installed the initial update. This latest fix builds upon previous efforts by integrating additional security measures to protect both service providers and their clients effectively.

On July 31, 2026, N-able identified unusual activity within a client’s system, leading to the discovery of a zero-day vulnerability in the N-central server, designated as CVE-2026-18577. This vulnerability, which affects all versions before 2026.3.1.7, allows attackers to bypass authentication and take over accounts.

Impact and Exploitation Details

The identified vulnerability was initially linked to an attempt to rectify a prior flaw, CVE-2026-18556. Both issues have been highlighted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as actively being exploited. Attackers have used these vulnerabilities to gain remote administrative access, leveraging the Take Control feature to infiltrate systems managed by N-central.

After gaining entry, threat actors established a new service using a Cloudflare Tunnel, ensuring persistent access even if their initial entry point was closed. N-able has confirmed that only a small number of customers have been directly impacted by these incidents.

Recommended Actions for Users

Users operating on-premise versions of the affected software are urged to upgrade to version 026.3.1.10 immediately. To assist in identifying potential security breaches, N-able has also provided a list of IP addresses associated with these attacks as indicators of compromise (IoCs).

Furthermore, a custom service template has been made available to help customers automate the process of checking Windows device endpoints for known IoCs within the N-central environment. While a clean scan does not guarantee security, it serves as a vital component of a comprehensive security assessment.

The company stresses the importance of conducting a thorough review of system logs and account activities as part of an ongoing security protocol. As investigations continue, additional indicators may emerge, requiring further vigilance and proactive measures.

The Hacker News Tags:CISA, Cloudflare Tunnel, CVE-2026-18556, CVE-2026-18577, Cybersecurity, enterprise security, Hotfix, IOC, N-able, N-central, remote monitoring, RMM, Security, Vulnerability

Post navigation

Previous Post: Revival of Bugtraq: Original Cybersecurity Forum Returns
Next Post: Atlassian Rovo AI Vulnerability Exposes Sensitive Data

Related Posts

Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access The Hacker News
FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware The Hacker News
Microsoft Fixes Entra ID Flaw Allowing Identity Takeover Microsoft Fixes Entra ID Flaw Allowing Identity Takeover The Hacker News
Cisco Patches Actively Exploited SD-WAN Vulnerability Cisco Patches Actively Exploited SD-WAN Vulnerability The Hacker News
Langflow Vulnerability Exploited Within Hours of Revelation Langflow Vulnerability Exploited Within Hours of Revelation The Hacker News
Ex-Developer Jailed Four Years for Sabotaging Ohio Employer with Kill-Switch Malware Ex-Developer Jailed Four Years for Sabotaging Ohio Employer with Kill-Switch Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens
  • Cisco Talos Unveils CAIRN to Combat Autonomous AI Malware
  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens
  • Cisco Talos Unveils CAIRN to Combat Autonomous AI Malware
  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark