N-able says attackers are actively exploiting an authentication-bypass flaw in N-central to seize administrative control of the RMM servers MSPs use to manage thousands of downstream customer networks — and the company’s first patch didn’t fully close it, forcing a second emergency hotfix (build 2026.3.1.7) on Saturday, August 2. The original flaw, CVE-2026-18556 (unauthenticated administrative account takeover), was supposedly fixed in the 2026.2 release; N-able and responders then found an alternate path around that fix, tracked as CVE-2026-18577, which re-opened the hole for every build before 2026.3.1.7.
Huntress reports that once inside an N-central server, the attackers used N-central’s own Take Control feature to pivot onto managed endpoints and registered Cloudflare tunnels as Windows services on those devices — outbound-only persistence that needs no inbound firewall rule or open port and survives a reboot. This is the RMM-supply-chain nightmare in its purest form: one compromised management server hands an attacker god-mode reach into every customer fleet it touches, and an incomplete first fix means some shops patched in good faith and are still exposed. Your blast radius is defined by the tools that hold privilege over everything else — and a management plane an attacker can reach unauthenticated isn’t a vulnerability to schedule, it’s a fire to put out.
Sources: N-able · Huntress · The Hacker News · GBHackers
Vulnerabilities & Exposure
Adobe patches a maximum-severity (CVSS 10.0) unauthenticated RCE in Campaign Classic (CVE-2026-48449). Bulletin APSB26-114 (July 29) fixes an incorrect-authorization flaw in Campaign Classic v7 that allows arbitrary code execution with no authentication and no user interaction, affecting on-prem build 9397 and earlier on both Windows and Linux; the fix is build 9398 (ACC 7.4.3). A companion high-severity SQL-injection bug (CVE-2026-48448, CVSS 8.6) allowing arbitrary file reads was patched in the same bulletin. Adobe reports no evidence of exploitation in the wild — but a no-login, no-click 10.0 on an internet-facing marketing server is exactly what gets scanned for fast.
So what: a CVSS 10.0 with no user interaction on an on-prem, often internet-exposed app is a patch-this-week item. Inventory any Campaign Classic instances, get them to build 9398, put the servers behind access controls, and watch them for anomalous process execution — “no known exploitation” has a short shelf life at this severity.
Carry-forward: Cisco Secure FMC static-credential zero-day (CVE-2026-20316) — CISA’s federal remediation deadline passed Friday, August 1. The actively exploited hard-coded-password flaw in Cisco Secure Firewall Management Center hit its federal deadline Friday; any FMC not yet on Cisco’s fixed software is now past the government’s own patch clock. Separately, eSentire reported threat actors exploiting a Fortinet FortiClient EMS flaw (CVE-2026-35616, CVSS 9.1) to deploy an information stealer against an energy/utilities target.
So what: management and security-tooling planes keep being the target — FMC governs your firewall policy, FortiClient EMS your endpoint agents. Confirm both are patched and that their admin interfaces aren’t reachable from anything that doesn’t strictly need them.
Cyberattacks & Breaches
FortiBleed: a credential haul from 70,000+ Fortinet firewalls is now tied to INC and Lynx ransomware. SOCRadar’s Threat Research Unit connected the “FortiBleed” campaign — an exposed server holding FortiGate configuration files and valid admin credentials harvested from tens of thousands of Fortinet devices (reports range from ~73,000 to ~86,000 firewalls across 194 countries) — to the INC Ransom and Lynx ransomware-as-a-service operations, after an operator tied to FortiBleed infrastructure was found working negotiation panels for both groups. The operation used a custom packet-sniffer planted on compromised firewalls to intercept VPN credentials straight off the wire; SOCRadar frames it as the first hard link between mass FortiGate credential theft and downstream ransomware.
So what: if you run FortiGate at the edge, assume any credential that ever traversed a compromised device is burned — rotate admin and VPN credentials, force MFA on the management and VPN planes, and pull configs to check for an unauthorized sniffer or rogue admin. Edge-device credential theft is no longer a nuisance; it’s the on-ramp to ransomware.
AI Impact on Security
Microsoft opens Project Perception and its in-house cyber model (MAI-Cyber-1-Flash) to public preview today. Microsoft’s agentic security system built for the AI era enters public preview August 3, alongside MAI-Cyber-1-Flash, its first purpose-built cybersecurity model, which Microsoft says does most of the work of much larger models at roughly half the cost (it cites a ~95.95% score on a security benchmark). The architecture is explicitly multi-model — routing to different capabilities based on quality, latency, and cost — and organizes work across three agent roles: RED (find exploitable paths), BLUE (investigate signal), and GREEN (take corrective/hardening action).
So what: the frontier is moving from “whose model is smartest” to how you route, govern, and trust a fleet of security agents that act. A model that takes corrective action is exactly where the trust-and-control question bites: what can it change, who approved it, and can you prove what it did. The defender’s edge is the harness of visibility and control you’ve built around agents that touch production.
Regulatory & Policy
EU AI Act enforcement powers over general-purpose AI went live Saturday, August 2. The European Commission’s AI Office now holds active enforcement authority over GPAI model providers: it can demand documentation, run technical evaluations, require risk-mitigation measures, restrict or withdraw a model from the EU market, and fine providers up to 3% of global annual turnover or €15M, whichever is higher. GPAI obligations have applied since August 2025; the one-year grace period held back only enforcement, and it has now ended. Models placed on the market before August 2025 must comply by August 2027.
So what: for anyone building on, fine-tuning, or reselling GPAI into the EU, the burden is now “produce, on demand, what your models do and how they’re governed” — with a percentage-of-revenue fine behind it. That provenance readiness is the same evidence discipline this week’s incidents keep demanding.
Sources & further reading (14)
- N-able — “N-central Security Update — August 2, 2026”
- Huntress — “Rapid Response: Critical N-able N-central Vulnerability and Active Exploitation”
- The Hacker News — “N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete”
- GBHackers — “Critical N-able N-central Flaw Actively Exploited to Gain God-Mode Access to MSP Networks”
- The Hacker News — “Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction”
- Security Affairs — “Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic”
- Tenable — CVE-2026-48449
- CISA — “CISA Adds One Known Exploited Vulnerability to Catalog” (Cisco FMC CVE-2026-20316)
- The Hacker News — “Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data”
- BleepingComputer — “FortiBleed credential-theft campaign linked to Lynx ransomware”
- Cybersecurity Dive — “FortiBleed campaign traced to INC and Lynx ransomware operations”
- Microsoft — “Rethinking security for the age of AI” (Project Perception)
- Axios — “Microsoft Project Perception launches AI agents, specialized model for cybersecurity”
- EU Artificial Intelligence Act — “Enforcement of Chapter V under the EU AI Act”