# When the Tool That Protects Everyone Gets Compromised
Remote monitoring and management software is the closest thing MSPs have to a master key. One login, one agent, thousands of endpoints across dozens of client networks. That's precisely why threat actors keep targeting it — and why N-able's announcement of a second hotfix for N-central, issued while attackers are actively reaching managed systems and establishing persistence, deserves more attention than it's getting.
## The Second Hotfix Is the Tell
N-able framed its latest release carefully: "This is not a duplicate of our [previous fix]." That parenthetical matters. It's the company acknowledging, in the polished language of incident communications, that the first round of protections wasn't enough — that attackers observed the initial patch, adapted their techniques, and kept moving.
That's a different kind of problem than a static CVE waiting to be closed. It's an active adversarial exchange, the kind where defenders patch and attackers probe until they find the gap that wasn't closed. The company's language confirms it: "proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques." Read that again slowly. They are watching attackers evolve in real time. And attackers are still getting through to managed systems.
The detail about persistence is the one burying the lede in most coverage. Reaching a managed endpoint is bad. Staying on it is catastrophically worse. Persistence mechanisms survive reboots, agent reinstalls, and sometimes even re-imaging if the attacker has established a foothold at a deep enough layer. The fact that N-able specifically called out persistence as part of the threat actor behavior suggests victims who haven't moved quickly enough may already be dealing with dwell time measured in days, not hours.
## Why RMM Attacks Follow This Pattern
The Kaseya VSA attack in July 2021 was the case study that made enterprise boards care about RMM security. REvil exploited an authentication bypass in the VSA on-premises product, pushed a malicious update to roughly 1,500 downstream MSP clients, and encrypted an estimated 60 managed service providers and up to 1,500 of their customers in a single weekend. The ransom demand hit $70 million.
N-central is a different product and a different attacker, but the structural vulnerability is identical: a platform with legitimate, trusted, deeply privileged access to client infrastructure is exactly what sophisticated threat actors want to compromise. The economics are ruthless. One successful exploitation of an MSP tool can unlock access to hospitals, law firms, manufacturers, and municipal governments simultaneously — targets that would each require significant independent effort to breach directly.
ConnectWise had its own RMM reckoning in early 2024, when two critical vulnerabilities in ScreenConnect were disclosed and immediately weaponized, with ransomware operators in the field within days of public disclosure. The pattern is consistent: RMM platforms get hit, attackers move fast to downstream clients, and organizations that assumed their MSP relationship meant someone else was watching the perimeter find out otherwise.
## What "Managed Systems" Actually Means Here
The language in N-able's disclosure — "attackers reach managed systems" — is worth unpacking for anyone outside the MSP world. N-central agents sit on client endpoints and servers and provide centralized management, patching, scripting, and remote access. When an attacker compromises the N-central server or abuses a session tied to it, they're not just in one box. They potentially have the same access the MSP technician has: the ability to push scripts, execute commands, access file systems, and move laterally across every endpoint enrolled in that N-central instance.
For an MSP managing 50 clients with 20 endpoints each, that's 1,000 targets accessible through a single point of failure. Most of those clients are small and mid-size businesses that hired the MSP specifically because they lack in-house security expertise. They have no visibility into what's happening at the RMM layer. They won't know they're compromised until ransomware fires or data appears on a leak site.
## The Hotfix Timeline Defenders Need to Watch
The fact that N-able is on hotfix 2 suggests an incident response process still in motion. The relevant operational questions for MSPs using N-central right now:
If your MSP hasn't sent you a communication about this incident in the past 48 hours, that's worth a phone call.
## HackWire Analysis
The N-central hotfix 2 story fits a pattern that's accelerated sharply since 2023: threat actors treating RMM and PSA platforms not as targets of opportunity but as primary objectives in their supply chain strategy. The calculus is simple and documented — compromising one well-deployed RMM platform yields more access than directly attacking dozens of individual organizations.
What's being undercovered here is the persistence dimension. Most incident response frameworks are built around the assumption that patching the initial vulnerability ends the threat window. That assumption breaks when attackers have already established footholds before the patch lands. N-able's disclosure explicitly acknowledges that attackers are persisting on managed systems — which means the incident timeline for some MSPs may have already crossed into full-blown compromise, with the RMM server itself being only the entry point.
The MSP security community has had three years since Kaseya to implement the structural changes that would make these attacks harder: zero-trust architecture at the RMM layer, mandatory MFA on management consoles, client-side alerting for RMM-initiated changes, and offline backups not reachable by the management plane. The fact that we're watching this same category of attack succeed again in 2026 suggests those changes haven't become standard practice at enough providers.
The advisory for defenders in the N-central ecosystem isn't just "patch fast." It's: assume the window of exposure may have already produced dwell time, hunt for persistence artifacts actively, and treat this as a potential breach until hunting proves otherwise. The second hotfix is not a signal that N-able has gotten ahead of this. It's a signal that attackers adapted to the first one.
— HackWire Editorial
---
## Related Coverage