Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
N-central Hotfix 2 Released Amid Security Concerns

N-central Hotfix 2 Released Amid Security Concerns

Posted on August 8, 2026 By CWS

N-able has introduced a new hotfix for its N-central platform in response to ongoing security threats exploiting a vulnerability in their Remote Monitoring and Management (RMM) system. This release aims to bolster defenses against evolving cyber attack strategies.

Proactive Security Measures

The company has emphasized the necessity of deploying Hotfix 2, even for those who have previously installed the initial update. This latest fix builds upon previous efforts by integrating additional security measures to protect both service providers and their clients effectively.

On July 31, 2026, N-able identified unusual activity within a client’s system, leading to the discovery of a zero-day vulnerability in the N-central server, designated as CVE-2026-18577. This vulnerability, which affects all versions before 2026.3.1.7, allows attackers to bypass authentication and take over accounts.

Impact and Exploitation Details

The identified vulnerability was initially linked to an attempt to rectify a prior flaw, CVE-2026-18556. Both issues have been highlighted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as actively being exploited. Attackers have used these vulnerabilities to gain remote administrative access, leveraging the Take Control feature to infiltrate systems managed by N-central.

After gaining entry, threat actors established a new service using a Cloudflare Tunnel, ensuring persistent access even if their initial entry point was closed. N-able has confirmed that only a small number of customers have been directly impacted by these incidents.

Recommended Actions for Users

Users operating on-premise versions of the affected software are urged to upgrade to version 026.3.1.10 immediately. To assist in identifying potential security breaches, N-able has also provided a list of IP addresses associated with these attacks as indicators of compromise (IoCs).

Furthermore, a custom service template has been made available to help customers automate the process of checking Windows device endpoints for known IoCs within the N-central environment. While a clean scan does not guarantee security, it serves as a vital component of a comprehensive security assessment.

The company stresses the importance of conducting a thorough review of system logs and account activities as part of an ongoing security protocol. As investigations continue, additional indicators may emerge, requiring further vigilance and proactive measures.

The Hacker News Tags:CISA, Cloudflare Tunnel, CVE-2026-18556, CVE-2026-18577, Cybersecurity, enterprise security, Hotfix, IOC, N-able, N-central, remote monitoring, RMM, Security, Vulnerability

Post navigation

Previous Post: Revival of Bugtraq: Original Cybersecurity Forum Returns
Next Post: Atlassian Rovo AI Vulnerability Exposes Sensitive Data

Related Posts

North Korean Hackers Exploit AI for Enhanced Cyber Attacks North Korean Hackers Exploit AI for Enhanced Cyber Attacks The Hacker News
Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers The Hacker News
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution The Hacker News
Cryptojacking Campaign Exploits Vulnerabilities with XMRig Miner Cryptojacking Campaign Exploits Vulnerabilities with XMRig Miner The Hacker News
Addressing Third-Party Risks: A Key Security Challenge Addressing Third-Party Risks: A Key Security Challenge The Hacker News
251 Amazon-Hosted IPs Used in Exploit Scan Targeting ColdFusion, Struts, and Elasticsearch 251 Amazon-Hosted IPs Used in Exploit Scan Targeting ColdFusion, Struts, and Elasticsearch The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Talos Unveils CAIRN to Combat Autonomous AI Malware
  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Talos Unveils CAIRN to Combat Autonomous AI Malware
  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark