N-able released Hotfix 2 for N-central as attackers actively exploit a known flaw and persist in managed systems. Here's what MSPs need to do right now.
If you're an IT professional running N-able's N-central, you probably felt your stomach drop when you saw the latest security advisory. And honestly, that's the right reaction. The company just released a second hotfix in rapid succession, and the reason isn't pretty: threat actors have already breached managed systems and are actively persisting in environments.
This isn't a drill, and it isn't a routine patch Tuesday. This is a real, ongoing exploitation event that requires your immediate attention.
### The Second Hotfix: What's Actually Happening
N-able has pushed out what they're calling "Hotfix 2" for N-central, following up on an earlier patch. The company is framing this as a proactive expansion of protections in response to how attackers are evolving their techniques in real time. In plain English: the first fix wasn't enough, and the bad guys are adapting.
The official statement from N-able says they are "proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques." They also clarified that this is not a duplicate of the previous hotfix, which suggests the new patch addresses different vectors or closes additional gaps that were discovered during active monitoring.
### Why Attackers Are Going After RMM Tools
Remote Monitoring and Management software is a prime target, and here's the uncomfortable truth: it's not just your systems they want. It's every system you manage. When attackers compromise an RMM platform, they get a master key to every client environment connected to it.
- They can deploy ransomware across multiple organizations at once
- They can harvest credentials silently without triggering endpoint alerts
- They can establish persistence that survives typical cleanup efforts
- They can move laterally through your entire managed ecosystem
The fact that attackers have already "reached managed systems" is significant. That language from N-able suggests this isn't a theoretical vulnerability anymore. It's being exploited in the wild, and some of your peers are already dealing with the fallout.
### The Persistence Problem
Attackers persisting on managed systems is the scariest part of this advisory. When a threat actor establishes persistence, it means they've set up mechanisms to survive reboots, credential resets, and even partial remediation. They plant backdoors, create scheduled tasks, or modify legitimate services to blend in.
The reason persistence is so dangerous is that it turns a quick fix into a full incident response. You can't just patch the vulnerability and call it a day. You have to assume the attacker has been inside your environment, which means you need to hunt for signs of compromise beyond the initial entry point.
### What You Should Do Right Now
If you're running N-central, here's your action plan:
1. Apply Hotfix 2 immediately, but don't stop there
2. Audit your environment for any signs of unauthorized access or unusual behavior
3. Review all accounts that have administrative privileges in N-central
4. Check for any new scheduled tasks or services that you didn't create
5. Rotate credentials for any system that connects to or from N-central
6. Enable detailed logging and monitor for anomalous activity going forward
Don't wait for the weekend. If attackers are already inside managed systems in the wild, the window between patch release and exploitation is shrinking by the hour.
### The Bigger Picture for Managed Service Providers
This incident is a wake-up call for the entire MSP community. RMM tools are foundational to how you operate, but they're also becoming one of the biggest attack surfaces in your stack. The vendors are doing their part by shipping hotfixes, but you need to treat these tools as high-value targets that require constant vigilance.
Consider segmenting your RMM infrastructure from other parts of your network. Limit which systems can talk to the management server. And for heaven's sake, enable multi-factor authentication on every single account that touches N-central, including service accounts.
### Final Thoughts
The reality is that patching is just the beginning. N-able's second hotfix is necessary, but it's not sufficient. You need to treat this as an active threat event and conduct your own investigation into whether your environment has been compromised.
Attackers are already reaching managed systems and persisting. The question isn't whether you should care. It's whether you've already been hit and just haven't noticed yet. Take a deep breath, apply the patch, and start hunting for signs of trouble. Your clients are counting on you to stay ahead of this one.