N-able N-central fixes authentication bypass issues
N-able has resolved two newly identified vulnerabilities in its N-central remote monitoring platform, which allowed an unauthenticated attacker to bypass login restrictions and create an administrator account. The flaws, discovered by Rapid7 Labs, could be exploited by sending crafted network requests. The company has issued a fix in N-central 2026.3 Hotfix 3 to address these security issues affecting enterprise users.
- Two new N-central vulnerabilities identified
- Allowed admin account creation without authentication
- Vulnerabilities reported by Rapid7 Labs
- Vendor released N-central 2026.3 Hotfix 3
- Affected enterprise-grade remote management software
Sources covering this
More in Cybersecurity
Google warns of rising attacks on enterprise AI assets
Google Cloud's security team reports that attackers are increasingly targeting enterprise AI systems, including proprietary models, source code, and cloud resources. Threat actors have shifted from using basic AI prompts to deploying automated, multi-agent AI workflows that can execute breaches rapidly, sometimes in under six hours. The report highlights incidents of mass credential theft and the compromise of cloud infrastructure to run unauthorized AI workloads.
OpenAI pledges $1 billion for AI cyber defense program
OpenAI has pledged $1 billion in credits to help organizations defending critical U.S. infrastructure—including water utilities, electric grids, local governments, banks, and nonprofits—access its AI-powered cybersecurity tools, training, and support. The "Daybreak for Frontline Defenders" initiative aims to help these sectors strengthen their defenses as AI-driven cyberattacks become more advanced. OpenAI says it will expand the program to partner countries in the coming weeks.
WeChat patched zero-click worm flaw after researcher demo
Researchers at Calif found and privately reported a flaw in WeChat that let attackers take over accounts on iOS and Android through an incoming call from a contact. The attack did not require the victim to answer. Calif demonstrated the exploit among test phones and said Tencent has blocked the issue as of late August. There are no reports the flaw was used in real attacks.
Cloudflare automates post-quantum secure web connections
Cloudflare says it's rolling out Automatic Key Exchange, a system that learns which encryption method each website prefers and uses that from the start. This cuts handshake time for web connections, lowering retries from 52% to 3.7% and shaving over 150 milliseconds off for most people. Hundreds of thousands of sites now have upgraded post-quantum security by default, with no manual setup needed.