Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

All IT Services graphic on dark navy background reading When the Tools Running Your IT Become the Way In, on RMM and EDR software being targeted by attackers

When the Tools Running Your IT Become the Way In

The software meant to protect your business is starting to look like a way into it. Over the past week, N-able rushed out an emergency hotfix for a maximum-severity flaw (CVE-2026-86218) in N-central, the remote monitoring and management platform thousands of IT providers use to run their clients’ networks. An unauthenticated attacker can execute code on an exposed, unpatched server. Security firm Huntress has flagged it as a likely zero-day; N-able says it has no confirmed cases yet but is telling everyone to patch immediately.

Days earlier, a researcher published a working exploit dubbed FalconFlank that turns CrowdStrike’s Falcon sensor — an endpoint protection tool — into a path to full SYSTEM access on a fully patched Windows machine.

Why This Matters

Notice the pattern. These aren’t dusty VPN boxes or forgotten web servers. They’re the tools that sit at the very top of the trust chain — the software with the keys to everything. Compromise the platform that manages a hundred networks and you don’t need to break into a hundred networks. That’s exactly why attackers are drawn to them, and why “we’ve got antivirus and an RMM” is no longer the reassurance it once sounded like.

In the Australian SMB fleets we look after across Sydney’s Northern Beaches and the Central West, the single most common reason a contained incident turns into a full breach isn’t the initial bug at all. It’s standing privilege — admin rights and management consoles left switched on and reachable long after anyone needed them. The patch matters, but the blast radius is decided long before the exploit lands.

The patch matters. But the blast radius is decided long before the exploit lands.

What to Do About It

  • Ask your IT provider what they run. Which RMM and endpoint tools manage your network, and are the latest hotfixes applied? A provider worth keeping will answer the same day.
  • Get admin consoles off the public internet. If N-central, or any management tool, doesn’t need to face the world, it shouldn’t.
  • Cut standing privilege. Fewer permanent local admins and always-on tokens means less for an attacker to inherit if a tool is compromised.
  • Watch the watchers. Turn on alerting for your security and management tools themselves, not just the endpoints they monitor.

This is core managed IT and cyber security work: knowing exactly what has privileged access to your environment, keeping it patched, and shrinking the blast radius before something goes wrong.

Not sure what can reach your management tools?

We’ll review what has privileged access to your network, check it’s patched, and tighten it up.

Talk to All IT Services

Dan BriggsAll IT ServicesDan works with hospitality groups, not-for-profits, financial services firms and SMBs across Sydney, Melbourne, Brisbane and Central West NSW on managed IT, Microsoft 365 and practical cyber security. Get in touch.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →