Aussie Cyber Guard LTD
ššš“ššš š®š¬š®š²: š”-š®šÆš¹š² š”-š°š²š»ššæš®š¹ ššæš²š®š°šµš²š±. š§šµš² šš¶šæšš š£š®šš°šµ šš¶š± š”š¼š šŖš¼šæšø. šš»š± š¬š¼ššæ š š¦š£ š š®š šš² šš³š³š²š°šš²š±. You have probably never heard...
ššš“ššš š®š¬š®š²: š”-š®šÆš¹š² š”-š°š²š»ššæš®š¹ ššæš²š®š°šµš²š±. š§šµš² šš¶šæšš š£š®šš°šµ šš¶š± š”š¼š šŖš¼šæšø. šš»š± š¬š¼ššæ š š¦š£ š š®š šš² šš³š³š²š°šš²š±. You have probably never heard of N-able N-central. But your IT provider has. And uses it every day. N-central is the platform MSPs use to manage thousands of client systems simultaneously. One server ā access to hundreds of companies. Today it emerged that attackers exploited a critical vulnerability in N-central to gain remote administrative access ā and through it reached client systems. CVE-2026-18577. Authentication bypass. Full administrative access without a single password. N-able released a patch. Attacks continued. The first patch was incomplete. A second was released on August 2. That means companies that applied the first patch and believed they were protected remained vulnerable for several more days. But the most alarming part is not that. Attackers used N-central to register Cloudflare tunnels as services on client devices. A Cloudflare tunnel is a persistent encrypted connection between a device and the attacker's server. It stays active even after the vulnerability is patched and the fix is applied. That means even if your MSP has updated N-central ā some client devices may still have a hidden access channel that nobody noticed. For Australian small and medium businesses this matters. Most companies under 200 people do not have an internal IT team. They depend entirely on their MSP. If the MSP is compromised ā every one of its clients is compromised. And those clients may not know for a very long time.
š§šµšæš²š² ššµš¶š»š“š šš¼ š±š¼ šæš¶š“šµš š»š¼š
- If you use an MSP ā ask them today for confirmation that N-central has been updated to version 2 026.3.1.7 or higher
- Ask your provider to check for unregistered Cloudflare tunnels on your devices
- If your MSP cannot answer these questions clearly ā that is already a signal worth acting on
At Aussie Cyber Guard we help Australian businesses assess their MSP risks and understand the real security posture of the infrastructure being managed on their behalf. Contact us here or on LinkedIn. #CyberSecurity #Australia #MSP #Nable #RMM #SupplyChain #CyberRisk #AussieCyberGuard