Weekly Threat Recap: Trusted Software Turned Malicious, Critical N-central Flaws Under Attack
Security firm Huntress has found evidence that attackers are actively exploiting critical vulnerabilities in N-able's N-central platform, a tool used by IT service providers to manage client networks. N-able has issued hotfixes for two authentication bypass flaws and a maximum severity remote code execution bug, but Huntress uncovered signs of compromise in a fully patched customer environment, suggesting attackers found a way in before or shortly after the patches were released. Limited logging on the affected appliance meant investigators could not confirm exactly which flaw was used.
This week's wider recap also highlights a supply chain attack in which a trusted software source was used to distribute code designed to steal credentials, and a network management protocol flaw that leaked useful information to outsiders before login was even required. Separately, researchers noted a workaround that lets malicious QR codes appear in emails even when image loading is blocked, undermining a common security precaution. Ongoing attacks targeting browsers, routers, and online stores round out a busy week for defenders.
Taken together, these incidents show that even organisations following good patching practices can be caught out by fast moving exploits and creative attacker techniques that sidestep standard defences.