decrypted · 9 august 2026 · ransomware and cybercrime · vulnerabilities and patching · supply chain

N-central's second hotfix, and the compromises the first one didn't stop

The N-central story flagged on 5 August, when N-able's own patch for a remote-management flaw failed to close the hole it was meant to fix, has now produced the outcome that warning pointed towards. N-able has confirmed that a "limited number of customers" were compromised before a second hotfix shipped this week, and the security firm Huntress says it traced one attack through a single compromised partner account into nine separate downstream organisations. For any UK business that outsources IT to a managed service provider, which is most small and medium ones, this is the week the risk stopped being theoretical.

A patch that needed a patch that needed a patch

N-central is remote monitoring and management software: MSPs use it to reach into every client's servers and endpoints from one console. On 31 July, N-able's own detection tooling spotted a customer environment behaving oddly and traced it to a zero-day, CVE-2026-18556, an authentication bypass letting an unauthenticated attacker log in as an administrator. N-able patched it on 2 August. That patch missed an alternative route into the same flaw, tracked as CVE-2026-18577, which the US Cybersecurity and Infrastructure Security Agency added to its known-exploited list within a day of the first fix shipping. N-able's advisory this week does not mince words: "This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix."

Once inside, attackers used N-central's built-in Take Control feature, the same tool a technician uses to remote into a client's PC, to reach managed endpoints directly. They then registered Cloudflare Tunnel connections on compromised machines: these dial out to Cloudflare's infrastructure rather than accepting inbound connections, so they need no firewall hole and survive a reboot. Huntress found one case where a single hijacked partner login gave an attacker a foothold in nine unrelated organisations, each reachable through the same console.

The Secure by Design lesson

The design failure here is not that a bug existed. It is that the authentication layer protecting a tool built for privileged, one-to-many access was allowed to be the single point of failure for every downstream client at once. A login bypass in ordinary software is bad. A login bypass in the console that legitimately controls thousands of other companies' machines is a multiplier, and the blast radius scales with how many clients the MSP serves, not with how the vulnerability was found. That is the reasoning behind the Cyber Security and Resilience Bill now before the House of Lords, which would bring MSPs into the UK's critical infrastructure regime for the first time. UK organisations should not wait for that Bill's committee stage in September: if a supplier can remotely administer your systems, ask this week how their own admin access is authenticated, and whether "hotfix 2" is a phrase that could ever apply to them twice.

Also this week

Microsoft closed three maximum-severity holes in its own cloud, and nobody had to patch anything. On 6 August, Microsoft fixed CVE-2026-63508 (Planetary Computer Pro), CVE-2026-56162 (Azure SQL Database) and CVE-2026-65667 (Microsoft Teams), each scoring a perfect 10.0 for allowing an unauthenticated attacker to gain elevated access over the network. Because these are hosted services, Microsoft patched them centrally with no customer action required, a reminder that handing infrastructure to a hyperscaler trades patching control for patching burden. Whether that trade suits a given UK organisation depends entirely on how much it trusts the vendor's own detection, which is the harder question to answer.

A charity CRM breach shows how thin the UK third sector's security margin is. Beacon CRM, used by more than 1,000 UK charities including English National Ballet, confirmed that an intruder used compromised credentials on 29 July to copy customer database backups. Anyone with an account created before 27 July should assume their data was taken, Beacon says, though there is no evidence yet of the data being sold or leaked. The Charity Commission published guidance for trustees this week, a rare case of a regulator moving faster than the news cycle. Charities running on lean budgets and shared platforms carry the same concentration risk as MSP clients: one vendor's credential hygiene becomes everyone's problem.

Sources

If this raises questions about how your own suppliers authenticate their access to your systems, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.