ENKVA #016 — N-able N-central auth bypass exploited, attackers pivot to managed endpoints
If you run N-able N-central, patch it before you read the rest of this. Attackers have been taking over N-central servers without credentials since August 1, and once in, they used the platform's own remote-control feature to reach the endpoints it manages. CISA added CVE-2026-18577 to the Known Exploited Vulnerabilities catalog on August 3 with a due date of today, and CVE-2026-18556 the next day, due tomorrow. The fix is N-central 2026.3.1 Hotfix 1, build 2026.3.1.7.
The two CVEs are one bug fixed twice. NVD describes CVE-2026-18577 as "an incomplete patch for CVE-2026-18556" that "allows for authentication bypass and account takeover in N-central Versions through 2026.3.1." Per Rapid7, it lets a remote unauthenticated attacker "obtain administrative control of vulnerable N-central servers," and the affected set is "all versions of N-able N-central up to and including version 2026.3.1, prior to Hotfix 1." N-able rates it 8.2 on CVSS v4.0, NIST 8.1 on v3.1 — but the score is not the story. The blast radius is.
The post-exploitation steps decide how far you have to scope. Rapid7 reports that "following successful exploitation, attackers leveraged the platform's Take Control functionality to remotely access managed endpoints, and deployed Cloudflare Tunnel (cloudflared) to establish persistent remote access." Huntress saw the same shape from the other end: Take Control sessions opened with the default MSP Support account, process enumeration on the target, then lateral movement across downstream endpoints. N-able confirms attackers "leveraged the Take Control feature and connected to systems within the N-central managed environment," and says "a limited number of customers" were affected.
A compromised N-central is not one server to rebuild. It is every endpoint that server could touch, reached over an authorized channel that leaves normal-looking remote-support logs. We covered the same pattern with SimpleHelp in #012 — an RMM is not just infrastructure you patch, it is a credential to every client you manage.
Both KEV entries cite BOD 26-04, the risk-based directive from #010, whose shortest tier covers bugs that are internet-exposed, on KEV, automatable, and grant total control. An internet-facing N-central server hits all four, which is how CVE-2026-18577 drew a three-day clock.
What to do this week:
- Get to 2026.3.1.7 now, not on Patch Tuesday. Hosted customers get it automatically; self-hosted must pull it from the support portal. Rapid7 says to prioritize this "on an urgent basis, outside of normal patching schedules."
- Hunt before you declare it clean. On the server, review authentication logs, admin account changes, and Take Control history for the IPs Rapid7 published —
173.249.252[.]200,87.249.138[.]34,37.19.210[.]32,37.153.90[.]88,92.118.112[.]181,68.235.46[.]214. On endpoints, look for a Cloudflared service and "a suspicioussvchost.exelocated within the user's Documents folder." Huntress points at artifacts underC:\ProgramData\GetSupportService_N-Central\Logs\matchingBASupSrvc_*.log.gz. - Treat N-able's checker as a floor, not a verdict. Its detection tool "checks only for the specific indicators currently known to be associated with this attack," and "a clean result should not be interpreted as a guarantee that your environment has not been impacted."
- Audit accounts, especially the default ones. Exploitation rode the built-in MSP Support account. Review N-central users for unauthorized creation or privilege escalation, and follow N-able's advice to "enforce multi-factor authentication, routinely audit user access, and monitor for unusual activity."
Advisories
A CVSS 10.0 command injection in Arista VeloCloud Orchestrator is being exploited
If you run VeloCloud Orchestrator on-prem, patch it this week. CVE-2026-16812 scores 10.0 on both CVSS v3.1 and v4.0 from Arista, and the advisory states it "is known to be actively exploited." It exposes "privileged internal functionality" that "was intended to be for internal use only and is not intended to be remotely accessible." CISA added it July 27, due July 30. Hosted and Dedicated VCO were already patched.
Action: per Security Advisory 0144, upgrade to 5.2.3.14, 6.1.3.4, or 6.4.2.4 and later in their respective trains; 7.0.x needs 7.0.0.1. Then "restrict access to the VCO web interface to trusted administrative networks" and review recent administrator activity for changes you did not make.
Unauthenticated RCE in TeamCity lands on KEV nine days after disclosure
Per NVD, "in JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol." CVE-2026-63077 scores CVSS 9.8, and JetBrains says an unauthenticated attacker with HTTP(S) access could "bypass authentication checks and execute arbitrary operating system commands." CISA added it August 5, due August 8 — while the vendor advisory still reads "we are not aware of any active exploitation."
Action: upgrade TeamCity On-Premises to 2025.11.7 or 2026.1.3. If a change window blocks you, JetBrains published a security patch plugin "for 2017.1+ so that customers who are unable to upgrade can still patch their environments." Cloud customers need do nothing. A build server holds signing keys and deploy credentials — treat a compromise there as a supply-chain incident.
Cisco shipped Secure Firewall Management Center with a hard-coded account
CVE-2026-20316 hit KEV July 29, due August 1. Cisco scores it 5.3 Medium: the flaw "could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data." The cause is "the presence of static user credentials for a low-privileged account" in the Secure Firewall Management Center web interface. A medium score on the box that holds your firewall policy still earns a change window.
Action: check your FMC build against the affected list — 7.0.0–7.0.9, 7.2.0–7.2.11, 7.3.0–7.3.1.2, 7.4.0–7.4.7, 7.6.0–7.6.5, 7.7.0–7.7.12, and 10.0.0–10.0.1 — and apply Cisco's fix per cisco-sa-fmc-static-cred-BET3Cjh. The management interface should not be internet-reachable either way.
A FortiOS patch bypass is on KEV, but Fortinet's page still flags it Known Exploited: No
CISA added CVE-2025-68686 on July 27, due August 10. Per NVD, it lets a remote unauthenticated attacker "bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests" — it restores an attacker's foothold after you thought you had removed it. Exploitation requires the device to have been compromised already at filesystem level, and FG-IR-25-934 still lists Known Exploited: No — as with the FortiSandbox pair in #015, the vendor flag is not the field to triage on.
Action: upgrade FortiOS 7.6.0–7.6.1 to 7.6.2 or above and 7.4.0–7.4.6 to 7.4.7 or above; 7.2, 7.0, and 6.4 need migration to a fixed release at any version. Devices without SSL-VPN enabled are unaffected. Patching does not evict an existing symlink, so if a FortiGate you manage was ever compromised, audit the filesystem.
Chrome shipped 370 security fixes in one stable release
The July 29 Chrome Stable Desktop update moved the channel "to 151.0.7922.71/.72 for Windows and Mac and 151.0.7922.71 for Linux," and states: "This update includes 370 security fixes." The post enumerates all 370 CVEs — 7 Critical, 71 High, 170 Medium, 122 Low. Chrome has since moved again, to 151.0.7922.75/.76 on August 4.
Action: confirm your fleet is on 151.0.7922.75 or later rather than assuming auto-update caught it — asleep machines and pinned enterprise builds drift. Edge inherits the same Chromium CVEs on its own cadence, so check both if you manage a mixed estate.
Product changes
Entra retires the memberOf dynamic group operator on November 3
Microsoft is ending the public preview of the memberOf rule operator. "After November 3, 2026, dynamic membership groups, dynamic administrative units, and entitlement management auto-assignment policies that use the memberOf operator stop updating and remain in their last known state." Microsoft names the consequences: "stale access and enforcement gaps, including outdated Teams and SharePoint access, Conditional Access targeting, group-based licensing, and access package assignments." Nothing breaks loudly.
Action: finding the usages is the slow part. Export dynamic membership groups from the Entra admin center and search the rules for memberOf; use Graph PowerShell for dynamic administrative units and auto-assignment policies. Replace each with supported rule operators or convert the group to assigned membership, then validate membership after the change.
Licensing
The M365 additions you started paying for in July finished rolling out August 1
The pricing side of Microsoft's 2026 packaging and pricing update took effect July 1 — Office 365 E3 rose 13% to $26.00, Microsoft 365 E5 rose 5% to $60.00, Business Basic rose 16% to $7.00. The capability side landed later: "roll out of the following features will be complete by August 1, 2026: Microsoft Defender for Office 365 Plan 1, Intune Remote Help, Intune Advanced Analytics, Intune Plan 2, Intune Privilege Management, Microsoft Cloud PKI, and Intune Application Management."
Action: your clients are already paying for these. Audit each tenant for what is now entitled but not enabled — Defender for Office 365 Plan 1 policies, Remote Help, and Endpoint Privilege Management most often sit dark. If you resell a tool that overlaps with any of them, have that renewal conversation first.
Compliance
DoD suspended CMMC Phase 2, and the comment window closes August 14
If you serve defense contractors, the November certification cliff moved. Per an Arnold & Porter advisory, on July 13, 2026 DoD "temporarily suspended" the CMMC Phase II requirements "originally scheduled to take effect on November 10, 2026." A CMMC Reform Task Force will "conduct a top-to-bottom 60-day review of the certification program," and Request for Information responses are due August 14, 2026. What did not change: DFARS 252.204-7012 and the Phase I self-assessment requirements in DFARS 252.204-7021 "remain in effect," and DoD will keep enforcing "the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments."
Action: tell affected clients the deadline slipped and the obligation did not. Their SPRS score, System Security Plan, and incident reporting duty are still live. If a client paused remediation waiting on C3PAO availability, restart it — the self-assessment they sign is unchanged.
Field notes
A self-propagating npm worm hit more than 400 packages
Microsoft documented ChainDrop, an npm compromise that spread on its own across "more than 400 packages across multiple unrelated publishers," including keyv, flat-cache, and cache-manager. The propagation loop: with stolen publishing credentials, the malware "enumerates packages available to the compromised identity, downloads their latest tarballs, inserts the malware and setup loader, adds a preinstall hook, increments the patch version, and republishes the modified packages." Because "npm runs preinstall scripts before installation completes, the payload could execute on developer workstations and build runners before application tests or conventional security checks began." It hunts npm, GitHub, AWS, Kubernetes, and HashiCorp Vault credentials. It is the second npm compromise in three weeks, after AsyncAPI in #015.
Action: Microsoft's structural fix is to "update npm CLI to npm CLI v 12 and use the npm CLI min-release-age feature," which refuses freshly published packages. Purge npm and Yarn caches on developer endpoints and build hosts, block npm-cache[.]com, pypi-get[.]com, and js-mirror[.]com, and rotate credentials from a clean host if a build agent installed a bad version.
Midnight Blizzard is hijacking hotel Wi-Fi captive portals to steal M365 tokens
Microsoft published CaptiveCrunch, a campaign it attributes to Storm-2945, "a sub-cluster of Midnight Blizzard." The technique is "manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure," and "the goal of this activity is to access the accounts of corporate travelers." Victims get a ClickFix prompt, then CornFlake RAT, "a full-featured Windows RAT written in Go," or ChocoShell, a "Powershell-based infostealer, delivered and executed entirely in-memory," which takes "browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials." It also abuses device code flow, covered in #007.
Action: Microsoft says to "only allow device code flow where necessary" and recommends "blocking device code flow wherever possible" — a Conditional Access authentication flows policy does this. Tell travelling users to prefer a hotspot or eSIM over hotel Wi-Fi, and never to reuse corporate credentials on a guest-network page. The payoff is session tokens, not passwords, so treat a suspected infection as a session-revocation job.
Add a comment: