Dive Brief:
- N-able raced to deploy a security fix for critical vulnerabilities in its N-central remote monitoring and management platform after detecting exploitations over the weekend, the company said in a Monday security update. Only a limited number of customers suffered breaches as of Monday, according to N-able.
- The vendor, which supplies managed service providers with unified IT and security automation and management tooling, released the latest version of its flagship platform on July 30. A subsequent spike in licensing issues among on-premises N-central users led engineers to a previously unidentified vulnerability that extended to cloud-based deployments.
- The vulnerability gave attackers remote access to the N-central managed endpoints through the platform’s Take Control feature, exposing MSP client environments to potential exploitation. N-able identified six IP addresses linked to the attacks as of Monday morning.
Dive Insight:
MSPs have turned to unified RMM and professional services automation platforms to scale their management capacity, fueling double-digit growth in a $20 billion industry. The N-able hacks underscore the inherent risks in remote management consoles.
“These tools are designed to give MSPs privileged access across many customer environments,” Jessica Davis, a principal analyst at Channel Dive sister company Omdia, said. “If attackers gain control of that access, they can use the same legitimate capabilities MSPs rely on every day to move into customer systems. This is not a new concern. Attackers have previously targeted or abused RMM tools from vendors including Kaseya and ConnectWise.”
N-able was the fourth largest RMM vendor last year, capturing 8.4% of the market, according to an Omdia analysis. Despite trailing Kaseya, ConnectWise and NinjaOne, which together command roughly 60% of the market, N-able has a sizable footprint among MSPs.
“N-central is very popular, so this has the potential to be huge,” John Hammond, senior principal security researcher at cybersecurity vendor Huntress, told Channel Dive. “These things start as embers, but they can turn into a wildfire if we don’t get out in front of them.”
Huntress had only confirmed one N-able platform breach among its customer base, according to a Monday-morning blog post. The managed security services provider protects more than 270,000 businesses and surpassed $250 million in annual recurring revenue last month. More than half of Huntress’ clients had yet to patch vulnerable cloud servers as of Monday, Hammond confirmed.
Installing the latest patch and waiting for additional intel are the immediate priority for N-able customers. The company said it has reached out to a “limited number of customers” impacted by the breach.
MSPs that use N-central should also take the initiative in contacting customers.
“An incident like this is not just a security risk for an MSP — it can quickly become a customer relationship and customer retention risk,” Davis said. “Impacted MSPs need to be proactive and tell customers what they know, what they are still investigating, what they have done so far and when they will provide another update. When customers don't hear anything, they tend to fill in the gaps themselves.”
Correction: This story has been updated to indidate that Huntress protects more than 270,000 businesses.