Aug 3 · Industry News

God-Mode in the Management Plane: N-able’s First Patch Didn’t Hold

Monday’s through-line is the management plane — the boxes that run everyone else’s boxes. N-able confirmed attackers are actively exploiting an authentication bypass in N-central to take total control of the RMM servers MSPs use to run their customers’ fleets, and the first patch didn’t hold — a second emergency fix shipped Saturday. Around it: a CVSS 10.0 Adobe RCE, the FortiBleed credential haul tied to ransomware, Microsoft’s Project Perception preview, and the EU AI Act’s enforcement teeth coming online.

★ Top Read

N-able says attackers are actively exploiting an authentication-bypass flaw in N-central to seize administrative control of the RMM servers MSPs use to manage thousands of downstream customer networks — and the company’s first patch didn’t fully close it, forcing a second emergency hotfix (build 2026.3.1.7) on Saturday, August 2. The original flaw, CVE-2026-18556 (unauthenticated administrative account takeover), was supposedly fixed in the 2026.2 release; N-able and responders then found an alternate path around that fix, tracked as CVE-2026-18577, which re-opened the hole for every build before 2026.3.1.7.

Huntress reports that once inside an N-central server, the attackers used N-central’s own Take Control feature to pivot onto managed endpoints and registered Cloudflare tunnels as Windows services on those devices — outbound-only persistence that needs no inbound firewall rule or open port and survives a reboot. This is the RMM-supply-chain nightmare in its purest form: one compromised management server hands an attacker god-mode reach into every customer fleet it touches, and an incomplete first fix means some shops patched in good faith and are still exposed. Your blast radius is defined by the tools that hold privilege over everything else — and a management plane an attacker can reach unauthenticated isn’t a vulnerability to schedule, it’s a fire to put out.

Sources: N-able · Huntress · The Hacker News · GBHackers

Vulnerabilities & Exposure

Adobe patches a maximum-severity (CVSS 10.0) unauthenticated RCE in Campaign Classic (CVE-2026-48449). Bulletin APSB26-114 (July 29) fixes an incorrect-authorization flaw in Campaign Classic v7 that allows arbitrary code execution with no authentication and no user interaction, affecting on-prem build 9397 and earlier on both Windows and Linux; the fix is build 9398 (ACC 7.4.3). A companion high-severity SQL-injection bug (CVE-2026-48448, CVSS 8.6) allowing arbitrary file reads was patched in the same bulletin. Adobe reports no evidence of exploitation in the wild — but a no-login, no-click 10.0 on an internet-facing marketing server is exactly what gets scanned for fast.

So what: a CVSS 10.0 with no user interaction on an on-prem, often internet-exposed app is a patch-this-week item. Inventory any Campaign Classic instances, get them to build 9398, put the servers behind access controls, and watch them for anomalous process execution — “no known exploitation” has a short shelf life at this severity.

Carry-forward: Cisco Secure FMC static-credential zero-day (CVE-2026-20316) — CISA’s federal remediation deadline passed Friday, August 1. The actively exploited hard-coded-password flaw in Cisco Secure Firewall Management Center hit its federal deadline Friday; any FMC not yet on Cisco’s fixed software is now past the government’s own patch clock. Separately, eSentire reported threat actors exploiting a Fortinet FortiClient EMS flaw (CVE-2026-35616, CVSS 9.1) to deploy an information stealer against an energy/utilities target.

So what: management and security-tooling planes keep being the target — FMC governs your firewall policy, FortiClient EMS your endpoint agents. Confirm both are patched and that their admin interfaces aren’t reachable from anything that doesn’t strictly need them.

Cyberattacks & Breaches

FortiBleed: a credential haul from 70,000+ Fortinet firewalls is now tied to INC and Lynx ransomware. SOCRadar’s Threat Research Unit connected the “FortiBleed” campaign — an exposed server holding FortiGate configuration files and valid admin credentials harvested from tens of thousands of Fortinet devices (reports range from ~73,000 to ~86,000 firewalls across 194 countries) — to the INC Ransom and Lynx ransomware-as-a-service operations, after an operator tied to FortiBleed infrastructure was found working negotiation panels for both groups. The operation used a custom packet-sniffer planted on compromised firewalls to intercept VPN credentials straight off the wire; SOCRadar frames it as the first hard link between mass FortiGate credential theft and downstream ransomware.

So what: if you run FortiGate at the edge, assume any credential that ever traversed a compromised device is burned — rotate admin and VPN credentials, force MFA on the management and VPN planes, and pull configs to check for an unauthorized sniffer or rogue admin. Edge-device credential theft is no longer a nuisance; it’s the on-ramp to ransomware.

AI Impact on Security

Microsoft opens Project Perception and its in-house cyber model (MAI-Cyber-1-Flash) to public preview today. Microsoft’s agentic security system built for the AI era enters public preview August 3, alongside MAI-Cyber-1-Flash, its first purpose-built cybersecurity model, which Microsoft says does most of the work of much larger models at roughly half the cost (it cites a ~95.95% score on a security benchmark). The architecture is explicitly multi-model — routing to different capabilities based on quality, latency, and cost — and organizes work across three agent roles: RED (find exploitable paths), BLUE (investigate signal), and GREEN (take corrective/hardening action).

So what: the frontier is moving from “whose model is smartest” to how you route, govern, and trust a fleet of security agents that act. A model that takes corrective action is exactly where the trust-and-control question bites: what can it change, who approved it, and can you prove what it did. The defender’s edge is the harness of visibility and control you’ve built around agents that touch production.

Regulatory & Policy

EU AI Act enforcement powers over general-purpose AI went live Saturday, August 2. The European Commission’s AI Office now holds active enforcement authority over GPAI model providers: it can demand documentation, run technical evaluations, require risk-mitigation measures, restrict or withdraw a model from the EU market, and fine providers up to 3% of global annual turnover or €15M, whichever is higher. GPAI obligations have applied since August 2025; the one-year grace period held back only enforcement, and it has now ended. Models placed on the market before August 2025 must comply by August 2027.

So what: for anyone building on, fine-tuning, or reselling GPAI into the EU, the burden is now “produce, on demand, what your models do and how they’re governed” — with a percentage-of-revenue fine behind it. That provenance readiness is the same evidence discipline this week’s incidents keep demanding.

Sources & further reading (14)

← All Industry News