China-linked hackers are exploiting a critical vulnerability in a popular cybersecurity tool, turning it into a ransomware launchpad, Microsoft warns. This supply-chain attack could have devastating consequences for countless organizations.
The Storm-1175 group, believed to be linked to China, is deploying a new ransomware strain called StormEncryptor. This group has previously used the Medusa ransomware to extort healthcare, professional services, and finance organizations in Australia, Britain, and the United States. Their high-velocity campaigns exploit both disclosed vulnerabilities and zero-day exploits, sometimes a full week before public disclosure.
In this latest campaign, Microsoft suspects the group is exploiting CVE-2026-18577, a vulnerability in N-central, a remote monitoring and management console. This vulnerability gives attackers unauthenticated, 'god-mode' access, allowing them to gain full administrative control of an N-central server with no credentials. Because MSPs use N-central to manage client endpoints, a single compromised server can become a gateway to every endpoint it controls.
This is not the first time such an attack has occurred. In 2021, a supply-chain attack on Kaseya's RMM tool allowed the REvil ransomware gang to compromise 60 of Kaseya's direct customers, leading to numerous downstream ransomware incidents. Similarly, a 2024 attack on ConnectWise's ScreenConnect product impacted numerous downstream entities.
The vulnerability in N-central was first detected in a zero-day attack on July 31, and N-able, the software company behind N-central, issued emergency hotfixes on August 2 and 6. However, Huntress found that over half of reachable N-central cloud servers remained unpatched, leaving them exposed. Turning N-central offline may be necessary for some organizations, but it also means losing central visibility and remote access when they may be needed most.
This incident highlights the ongoing threat of supply-chain attacks and the importance of patching and securing critical software. As threat actors continue to exploit vulnerabilities, organizations must remain vigilant and proactive in their cybersecurity efforts.