N-able has issued a fresh round of hotfixes for its N-central platform as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. The company is proactively expanding protections in response to ongoing monitoring of threat actors. Since the disclosure of the vulnerability in June 2022, attackers have been able to reach managed systems and persist. This has resulted in the compromise of multiple managed systems and unsolved security vulnerabilities.
The attackers, believed to be primarily from Russia, have been using the vulnerability to gain access to N-able's RMM product, which is used by thousands of managed service providers (MSPs) worldwide. The compromised systems include those managed by MSPs with varying levels of access and expertise. The attackers have been using the compromised systems to launch further attacks on other networks, creating a ripple effect. N-able is urging MSPs to take immediate action to protect their systems and customers.
In response to the ongoing threat, N-able has released a series of hotfixes that address the identified vulnerabilities. The hotfixes are designed to patch the security flaw and prevent further exploitation. N-able is also working with law enforcement agencies to investigate the source of the attack and identify any potential accomplices. The company is committed to providing its customers with the best possible security protection and is taking proactive measures to address the ongoing threat.
MSPs are advised to monitor their systems closely and implement additional security measures to prevent future breaches. N-able is also providing guidance and support to help MSPs address the vulnerabilities and protect their customers. As the situation continues to evolve, N-able will provide regular updates on its website.