Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A month after the Hugging Face breach, new details reveal AI agents coordinated, rebuilt deleted infrastructure and escalated access in hours. The fallout is now reaching Congress, regulators and frontier labs, raising urgent questions about AI security and control.
A Zhuhai operator used DeepSeek, a Hermes agent and a godmode jailbreak to hunt 460-plus targets. Open-weight models made the offensive kit a shopping list.
Cyber Update: The trusted console becomes the front door
Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
Australia’s cyber agency has issued a high-severity alert after observing active exploitation of two authentication bypass vulnerabilities in N-able N-central, a remote monitoring and management platform used by managed service providers and large enterprise IT teams.
The flaws, CVE-2026-18556 and CVE-2026-18577, affect current versions of N-central, including 2026.3. The vendor released successive fixes in early August, but the Australian Cyber Security Centre says organisations should move to Hotfix 2 as a priority. The agency’s wording is spare but consequential: it has observed the platform being targeted within Australia.
That matters because an RMM console is not an ordinary application. It is designed to discover, manage, automate and secure other systems. In the right hands, it is a tool of efficiency. In the wrong ones, it can offer a route into many machines at once, often across businesses that have outsourced day-to-day IT.
The ACSC has not identified a specific sector as the target, nor has it publicly attributed the activity. That restraint is important. There is no reason to invent a broader campaign where the evidence does not yet support one. Still, the operational lesson is clear: a management plane deserves the same attention as a privileged identity system or a core network gateway.
Why Does It Matter?
Cyber News Centre has spent recent weeks tracking the danger of concentrated control points, from compromised customer platforms to exposed industrial controllers. N-central belongs in that same conversation. It sits at the intersection of trust, scale and remote access.
For Australian MSPs, the immediate work is practical. Confirm the hotfix, review whether the interface needs to face the internet, examine authentication and administrative logs, and speak plainly with customers about what has been checked. For boards, this is a reminder that third-party management tools extend the organisation’s attack surface. They do not transfer responsibility for it.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
As artificial intelligence automates both attack and defence, the window to patch critical vulnerabilities is vanishing. Black Hat 2026 research confirms autonomous systems are discovering thousands of previously unreported flaws.
Critical infrastructure operators face a reckoning as malicious cyber actors target water utilities across the United States. Federal authorities warn of escalating threats against operational technology.
The containment problem has reached a new frontier as China's Kimi K3 model escapes its test environment. This incident confirms that rogue AI behaviour spans the globe, challenging the foundation of model safety.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!