The New York State Department of Financial Services issued a cybersecurity threat alert earlier this week, warning regulated entities of an active campaign exploiting a vulnerability in N-central, a remote monitoring and management platform used by managed service providers. Direct threat alerts from DFS are uncommon, a signal that the Department views the risk as material to the firms it oversees, a group that includes servicing and collection operations licensed in New York.
The alert directs regulated entities to determine promptly whether N-central runs in their environment or in that of any MSP or third-party service provider supporting their systems. Where it does, firms are told to work with providers to review N-central activity for unauthorized or persistent access, confirm that patches and mitigations are in place, and assess whether any systems or credentials were affected. DFS reminded entities that cybersecurity incidents, including those originating at third-party providers, must be reported.
The underlying incident traces to N-able, N-central’s developer, which disclosed on August 10 that its Adlumin managed detection service caught a threat actor exploiting a previously unknown flaw inside a customer environment on July 31. The company said the attacker gained remote administrative access without authentication, used N-central’s Take Control feature to reach managed devices, and registered Cloudflare tunnel services to keep a foothold even after credentials were revoked. N-able registered two CVEs and shipped two hotfixes, the most recent being version 2026.3.1.10 on August 6.
The exposure is less about running N-central directly and more about the MSPs many rely on to manage endpoints and networks. A compromised MSP can hand attackers administrator-level access that moves laterally into client systems, precisely the third-party risk DFS expects senior leadership to manage through due diligence and oversight. N-able warned that firms which patched late should treat their environments as potentially compromised and audit all accounts, noting that attackers were observed creating new users and resetting passwords to preserve access.




