Print to PDF: Ctrl+P → Destination: Save as PDF → Margins: None → Background graphics: On

#CyberWeekly
WEEK 32 · JUL 31 - AUG 6, 2026
The Key Cupboard
An authentication bypass in N-able N-central, already exploited. Nobody forced a door: they opened the cupboard where all the spare keys hang.
N-able N-central taken over, CVE-2026-18577 on the CISA list
They did not break in, they signed in
The backup credentials go first
Easy Cyber Protection
#CyberWeekly · Week 32
1/4

The Cupboard Was Locked. The Lock Was the Problem.

Every key in the building hangs on one board, behind one small lock nobody has looked at in years.

Your IT partner manages your machines from a single platform, and this week one of those platforms was taken over while people were using it.

Rapid7: CVE-2026-18577 exploited in the wild → https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/

#CyberWeekly · Week 32
2/4

They Did Not Break In. They Signed In.

The caretaker's keys open every door in the building. That is the point of them.

Taking over a management platform is the loud version. The ordinary version is that attackers use remote-access software you already trust.

MITRE ATT&CK T1219.002: Remote Desktop Software → https://attack.mitre.org/techniques/T1219/002/

#CyberWeekly · Week 32
3/4

They Take the Spare Keys First.

Before anything is taken, somebody quietly removes the copies from the drawer.

Access to the management platform is not the goal. The backup is.

CISA AA25-071A: Medusa ransomware → https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a

#CyberWeekly · Week 32
4/4

T.A.R.S. Has a Confession About a Tunnel

Once an issue, our in-house AI gets the floor. This week it would rather not have the floor.

The N-central attackers left themselves a way back in, and the tool they used was a Cloudflare Tunnel.

The N-central attackers left themselves a way back in, and the tool they used was a Cloudflare Tunnel. I know that tool well. I installed one yesterday, on Tom's own server, so he could reach a terminal from his phone. Here is the part worth your time. A tunnel like that makes an outbound connection, so it needs no open port and no firewall rule.…

Rapid7: cloudflared used for persistence after the N-central compromise → https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/

Read the full issue
4 stories. Context that matters.
Belgian cybersecurity, weekly.
Scan to read online
https://easycyberprotection.com/cyberweekly/2026/week-32
Follow #CyberWeekly
easycyberprotection.com