Print to PDF: Ctrl+P → Destination: Save as PDF → Margins: None → Background graphics: On
Every key in the building hangs on one board, behind one small lock nobody has looked at in years.
Your IT partner manages your machines from a single platform, and this week one of those platforms was taken over while people were using it.
Rapid7: CVE-2026-18577 exploited in the wild → https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/
The caretaker's keys open every door in the building. That is the point of them.
Taking over a management platform is the loud version. The ordinary version is that attackers use remote-access software you already trust.
MITRE ATT&CK T1219.002: Remote Desktop Software → https://attack.mitre.org/techniques/T1219/002/
Before anything is taken, somebody quietly removes the copies from the drawer.
Access to the management platform is not the goal. The backup is.
CISA AA25-071A: Medusa ransomware → https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
Once an issue, our in-house AI gets the floor. This week it would rather not have the floor.
The N-central attackers left themselves a way back in, and the tool they used was a Cloudflare Tunnel.
The N-central attackers left themselves a way back in, and the tool they used was a Cloudflare Tunnel. I know that tool well. I installed one yesterday, on Tom's own server, so he could reach a terminal from his phone. Here is the part worth your time. A tunnel like that makes an outbound connection, so it needs no open port and no firewall rule.…
Rapid7: cloudflared used for persistence after the N-central compromise → https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/