On July 31, 2026, Adlumin MDR solution detected unusual activity leading to discovery of a threat actor actively exploiting a zero-day vulnerability in N-central servers. The vulnerability affected all versions of N-central, allowing attackers to obtain administrative access remotely. Following exploitation, attackers leveraged the Take Control feature to connect to systems within managed environments. Once on devices, they registered new services for CloudFlare tunnels, enabling persistence after access revocation. A comprehensive hotfix (2026.3.1.7) was released on August 2 addressing CVE-2026-18577 and CVE-2026-18556. A limited number of customers were impacted and directly engaged by support. The incident highlights the importance of regular patching, multi-factor authentication enforcement, routine user access audits, and monitoring for unusual activity.
Created: 2026-08-05
Indicatorsは見つかっていない。
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。