Hackers Breached the Software Your IT Provider Manages You With: A Perth Guide

In August 2026 attackers actively exploited a widely used remote IT management platform to reach into client networks. Here's what it means for your Perth business. From Computer Mechanics, Perth IT specialists since 1997.

XanderXander · Web Developer & IT Technician
21 August 2026
5 min read
Cybersecurity
Managed IT
RMM
Perth Business
IT technician monitoring business systems remotely

In early August 2026, attackers actively exploited two vulnerabilities in N-able's N-central, a remote monitoring and management (RMM) platform used by managed IT providers worldwide to patch, monitor and remotely access their clients' computers. The flaws let an unauthenticated attacker bypass login entirely and take administrative control of the N-central server itself — then use its built-in remote-access tools to reach into every business network that server managed. If you've never heard of N-central, that's fine; the point isn't the product name, it's what it represents. The software your IT provider uses to look after you is now a genuine attack target in its own right, and it's worth knowing what a well-run provider does differently.

What actually happened

N-able disclosed CVE-2026-18556, an authentication bypass in N-central, and issued a patch. Attackers found the patch was incomplete and kept exploiting the gap as CVE-2026-18577. N-able confirmed exploitation had been happening in the wild since 1 August, rushed out an emergency hotfix on 2 August, and both CVEs were added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalogue within days — with federal agencies given as little as 72 hours to patch.

Once inside an N-central server, attackers used the platform's own legitimate "Take Control" remote-access feature to reach the managed endpoints underneath it, and deployed a tunnelling tool (Cloudflare Tunnel) to keep persistent access even after the initial hole was patched. Researchers estimate a couple of thousand N-central instances were reachable from the internet at the time, with Australia among the more heavily represented countries.

Why this matters even if your provider doesn't use N-central

This is the second time in a few years an RMM platform has been the entry point into hundreds of otherwise unrelated small businesses at once — the 2021 Kaseya incident, which hit roughly 1,500 downstream businesses through their MSPs, is the reason security teams pay close attention whenever one of these tools makes headlines again. RMM software is a deliberate, sanctioned backdoor: it exists so your IT provider can install updates, run security tools and jump on a support call without visiting your office. That's exactly what makes it valuable to attackers too. Compromise the platform, and you inherit legitimate, trusted access to every client network it touches — no phishing email or guessed password required.

None of this means managed IT support is riskier than doing it yourself. An unmanaged small business without patch management, monitoring or a firewall is a far softer target for the much larger volume of everyday attacks — ransomware crews, business email compromise, opportunistic scanning. What it does mean is that not every managed IT provider treats its own tooling with the same care it expects clients to apply to theirs, and that's a reasonable thing to ask about.

Questions worth asking your IT provider

  • How quickly do you patch the software you manage us with, not just our systems? N-able's hotfix landed within two days of active exploitation being confirmed; a provider running months behind on its own platform's updates is leaving the same door open.
  • Is multi-factor authentication enforced on your management console, with no exceptions? An authentication bypass is far less useful to an attacker if a second factor still stands in the way.
  • Do you restrict who and what can reach that console — by IP range, VPN, or another access control — rather than leaving it open to the whole internet?
  • Would you know if someone logged into it who shouldn't have? Anomaly alerting on admin logins is what turns "attacker had access for weeks" into "attacker had access for minutes."
  • What's the plan if the vendor itself is breached? A provider with a real incident response process can answer this without hesitating.

No single tool should be able to sink you

The uncomfortable lesson from incidents like this one isn't "stop using RMM software" — trying to manage a modern business's IT entirely by hand, without centralised patching or monitoring, creates far more exposure than it removes. The lesson is that no single piece of software, however trusted, should be able to take down or expose an entire business on its own if something goes wrong with it.

That's what layered security is actually for. If an RMM platform, an email system, or a firewall is ever compromised, the damage should stop well short of "attacker now has everything." Backups kept separate from the systems they protect mean a breach doesn't also cost you your data. Least-privilege access means a compromised admin account doesn't automatically hand over every system in the business. Network segmentation means a foothold on one machine doesn't become a foothold on all of them. None of this is exotic — it's the same thinking behind the ASD Essential Eight, and it's exactly why relying on any one control, including the management platform your IT provider uses, is the wrong way to think about risk.

What we do

This kind of platform-level risk is exactly why our IT security solutions treat the tools we manage clients with as part of the attack surface, not just the systems we're protecting — patched on disclosure, access-controlled, and monitored for anything unexpected. It's also part of what separates properly managed IT support from a "someone who's good with computers" arrangement.

If you're not sure how your current provider handles patching on their own management tools, that's a fair question to put to them directly — and if you'd rather have someone else look at it, get in touch or call (08) 9325 1196. We've been keeping Perth businesses' systems, and the tools we manage them with, properly looked after since 1997.

Xander
Written by
Xander
Web Developer & IT Technician · 2+ years in IT

Xander builds fast, SEO-friendly websites and handles hands-on IT and computer-repair work — from Next.js builds and local search optimisation through to hardware fixes, OS reinstalls and helpdesk support. He covers the full stack, from the rack to the browser.

Meet the IT Support Perth team →
Xander
21 August 2026
5 min read
Cybersecurity
Managed IT
RMM
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Fake 'Australian Federal Police' Calls: When the 'Proof' Is a Real Government Email

A scam caller posing as the AFP made a genuine, fully-authenticated email from cyber.gov.au land in a Perth inbox as 'proof' he was real. Here's how the trick works and why a verified email never verifies the caller. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Remote Access Scams: How Fraudsters Impersonate 'IT Support' to Rob Perth Businesses

ASIC says remote access scams have cost Australian small businesses $4.9 million, with callers posing as IT support to get onto your PC. Here's how Perth businesses can spot and stop it. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Payment Redirection Scams Are Costing Australian Businesses Millions: A Perth Guide

Payment redirection and invoice scams are the most common fraud reported by Australian small businesses, with losses in the hundreds of millions. Ahead of Scams Awareness Week 2026, here's how Perth businesses can stop them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
Fake 'Australian Federal Police' Calls: When the 'Proof' Is a Real Government Email
Cybersecurity
Scams

Fake 'Australian Federal Police' Calls: When the 'Proof' Is a Real Government Email

A scam caller posing as the AFP made a genuine, fully-authenticated email from cyber.gov.au land in a Perth inbox as 'proof' he was real. Here's how the trick works and why a verified email never verifies the caller. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/20/2026
Call us