A critical vulnerability was discovered by N-Able in it's product N-Central, a remote management appliance used for IT administration.
Following exploitation, attackers abused built-in functionality to take full control of highly sensitive machines in the environment, including domain controllers, which manage the security and identities for the entire network.
Several factors greatly increase the risk of exploitation and malicious activity:
If an un-patched appliance has been exposed to the internet, customers should perform manual checks for non-standard authentications and behaviour within associated networks.
N-Able released a set of IP addresses used in previously observed attacks. These should be blocked and attempted connections monitored:
173[.]249[.]252[.]200
87[.]249[.]138[.]34
37[.]19[.]210[.]32
37[.]153[.]90[.]88
92[.]118[.]112[.]181
68[.]235[.]46[.]214
If you believe your network may have been affected by this vulnerability, or are not sure, contact the Integrity360 Incident Response team for assistance.