Feds get 3 days to patch N-able God mode flaw under active exploit


The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies three days to patch a flaw that could let attackers reach managed service provider (MSP) customers.

Attackers exploiting the flaw can gain “full administrative access to an N-central console,”

Tracked as CVE-2026-18577 (8.2 CVSSv4), N-able disclosed the vulnerability affecting N-central on Sunday, noting that it was exploited as of July 31.

MSPs use N-central to manage customer systems from a single dashboard, and successful exploitation can hand an attacker administrative access to the console.

Read more…
Source:  The Register


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Cyber Security & Cloud Congress North America Unveils Esteemed Speaker Lineup

    February 26, 2024

    The Cyber Security & Cloud Congress North America has revealed the newest additions to its speakers’ line up for its forthcoming conference, slated to be held at the Santa Clara Convention Center on June 5-6, 2024. Among the notable speakers set to take the stage are: Alissa “Dr Jay” Abdullah, Deputy Chief Security Officer – Mastercard Benjamin Benhan, ...

  • Lockbit cybercrime gang says it is back online following global police bust

    February 26, 2024

    Lockbit, the cybercrime gang that was knocked offline by a comprehensive international police operation earlier this month, says it has restored its servers and is back in business. The group, notorious on the internet’s criminal underground for using malicious software called ransomware to digitally extort its victims, was the target of an unprecedented international law enforcement ...

  • The Building Resilience to Cognitive Warfare Technical Exchange Meeting

    February 23, 2024

    In September 2023, MITRE hosted a Technical Exchange Meeting (TEM) titled Building Resilience to Cognitive Warfare with participants from MITRE, the Department of Defense, and the Australian Defense Force, whic h focused on securing the cognitive domain, including identifying national-level partnerships and innovation opportunities. This paper explores the emerging importance of cognitive security in the face ...

  • AT&T, T-Mobile and Verizon users hit by massive cellular outage in US

    February 22, 2024

    Mmajor cellphone outage affected users across the US early Thursday — even stopping some police departments from being able to receive 911 calls. AT&T seemed to have experienced the largest number of issues, with nearly 32,000 reports at around 4:30 a.m., according to data from DownDetector, which tracks outages by collating status reports from sources including ...

  • FBI issues warning against using Chinese manufactured drones

    February 21, 2024

    Chinese-manufactured unmanned aircraft systems (UAS), more commonly known as drones, continue to pose a significant risk to critical infrastructure and U.S. national security, according to an FBI advisory. While any UAS could have vulnerabilities that enable data theft or facilitate network compromises, the People’s Republic of China (PRC) has enacted laws that provide the government with ...

  • Law enforcement disrupt world’s biggest ransomware operation

    February 20, 2024

    In a significant breakthrough in the fight against cybercrime, law enforcement from 10 countries have disrupted the criminal operation of the LockBit ransomware group at every level, severely damaging their capability and credibility. LockBit is widely recognised as the world’s most prolific and harmful ransomware, causing billions of euros worth of damage. This international sweep follows ...