κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / CISA Warns of N-able N-Central Deserialization and Injection Vulnerability Exploited in Attacks
άμυνα
.

CISA Warns of N-able N-Central Deserialization and Injection Vulnerability Exploited in Attacks

14/08/2025

CISA has issued urgent warnings regarding two critical security vulnerabilities in N-able N-Central remote monitoring and management (RMM) software that threat actors are actively exploiting. 

The vulnerabilities, identified as CVE-2025-8875 and CVE-2025-8876, pose significant risks to organizations using this widely-deployed IT management platform.

Key Takeaways
1. Two critical N-able N-Central vulnerabilities were actively exploited for remote code execution.
2. CISA deadline: August 20, 2025, for mandatory fixes.
3. Update or discontinue use immediately.

Deserialization Vulnerability

The first vulnerability, CVE-2025-8875, represents an insecure deserialization vulnerability that could lead to arbitrary command execution on affected systems.

Deserialization attacks occur when untrusted data is processed by an application’s deserialization mechanism, potentially allowing attackers to manipulate object states and execute malicious code. 

This particular flaw in N-able N-Central’s architecture creates a pathway for remote attackers to gain unauthorized access and control over managed systems.

The technical nature of this vulnerability lies in the improper handling of serialized objects within the N-Central platform. 

When the application deserializes user-controlled input without proper validation, it creates an attack vector that sophisticated threat actors can exploit to bypass security controls and establish persistent access to target networks. 

The Common Vulnerability Scoring System (CVSS) implications of this flaw make it a high-priority concern for security teams.

Command Injection Vulnerability 

The second vulnerability, CVE-2025-8876, involves a command injection vulnerability stemming from improper sanitization of user input within the N-Central application. 

Command injection attacks allow malicious actors to execute arbitrary system commands by manipulating input fields that are processed by the underlying operating system without adequate filtering or validation.

This vulnerability specifically targets the input validation mechanisms within N-Central’s user interface, where insufficient input sanitization procedures fail to prevent the execution of injected shell commands. 

Attackers can potentially leverage this weakness to execute system-level commands, access sensitive files, modify system configurations, or install malicious software on compromised systems.

Mitigations

CISA has established an aggressive remediation timeline, requiring organizations to implement mitigations by August 20, 2025, just one week after the vulnerabilities were added to the Known Exploited Vulnerabilities (KEV) catalog on August 13. 

The urgency reflects the active exploitation of these vulnerabilities in real-world attack scenarios.

Organizations must immediately apply vendor-provided patches and mitigations, follow applicable Binding Operational Directive (BOD) 22-01 guidance for cloud services, or discontinue use of affected N-Central deployments if adequate mitigations remain unavailable. 

N-able has released version 2025.3.1 of N-Central to address these security issues.

While the connection to ransomware campaigns remains unknown, the combination of deserialization and command injection vulnerabilities creates a potent attack surface that threat actors could exploit for initial access, lateral movement, and payload deployment across enterprise networks.

Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.
Source: cybersecuritynews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-10

Haiku and SerenityOS aren’t daily drivers, but they’re the best weekend projects

Most people stick to Windows, macOS, or Linux because they get the job done with minimal hassle. They support a vast range of hardware, have robust ecosystems, and are built for day-to-day use. That doesn’t mean they’re the only operating systems worth trying. Away from the mainstream, projects like Haiku and SerenityOS demonstrate that there’s still plenty of room for alternative visions of how … [Read More...]

I clustered budget-friendly devices into a Proxmox HA lab, and it's more useful than I thought

Between its support for LXCs, community scripts, and simple management UI, Proxmox has a ton of features to make home labs more accessible to beginners and casual users. Unlike its rivals (especially ESXi), Proxmox requires minimal CPU, memory, and storage provisions. It also works right-out-of-the-box with most hardware, making it a terrific option for budget-friendly setups. However, despite its … [Read More...]

If you just need a laptop for the basics, this one at $349 is an absolute steal

This laptop is perfect for someone that's looking for something new on a budget. The Asus Vivobook 15 packs power with an Intel Core 5 processor, and also comes with a good amount of RAM and storage. But what makes it stand out right now is that steep discount from Walmart. For a limited time, you can score this laptop for $349, which is an absolute steal. Source: xda-developers.com … [Read More...]

The best Prime Day SSD deals: Save on gear from Samsung, Crucial, Seagate and others

If you've never considered adding a solid-state drive (SSD) to your PC or game console, October Prime Day is a great time to start — and if you already know what a difference extra storage can make, October Prime Day is the perfect time to outfit your build. For those who haven't heard of SSDs, they're physical upgrades that stack on top of a device's storage to make more files accessible at once. … [Read More...]

3 mistakes that ruined my first attempt at building a PC

Building your very first PC is never really easy, no matter how many tutorials you've watched on YouTube or parts you've memorized. In fact, it took me a couple of weeks just to properly research and source the parts for my first gaming rig back in 2012. By the time everything arrived, I thought the hard part was behind me. I knew that putting the parts together as a beginner would be … [Read More...]

The Reinforcement Gap — or why some AI skills improve faster than others  

AI coding tools are getting better fast. If you don’t work in code, it can be hard to notice how much things are changing, but GPT-5 and Gemini 2.5 have made a whole new set of developer tricks possible to automate, and last week Sonnet 2.4 did it again.   At the same time, other skills are progressing more slowly. If you are using AI to write emails, you’re probably getting the same … [Read More...]

The best Amazon Prime Day kitchen deals: Get up to 50 percent off our favorite air fryers and more

Whether you call it October Prime Day or use Amazon’s official title, Prime Big Deal days, the sale represents some of the lowest prices of the year in nearly every department — and that includes kitchen gear. We have a slew of food enthusiasts on staff who have tested plenty of excellent kitchen tech, as seen in our reviews and buying guides. We’ve covered everything from air fryers to sous vide … [Read More...]

Astronomers Spot Rapidly Growing Rogue Planet Feeding on Surrounding Gas

Astronomers have identified the fastest-growing planet ever observed, a free-floating world known as Cha 1107-7626. Located about 620 light-years from Earth, it is between five and ten times the mass of Jupiter. The rogue planet has been detected, and it has entered a sudden growth burst in recent months. It is swallowing down six billion tonnes of gas every second, making it the hungriest … [Read More...]

4 reasons why installing HACS was the best decision for my Home Assistant instance

While the Home Assistant Community Store (HACS) is considered by some people to be one of the best tools you can use with Home Assistant, I only stumbled upon it a while after setting up my own server. I'm still very early in my Home Assistant journey, but as I've gotten to know the platform better, I've realized that installing HACS was the best decision for my instance. Source: … [Read More...]

The Young Minds App wants to protect and educate children online and will show its tech at TechCrunch Disrupt 2025

An app called Young Minds wants to give parents control over what their kids do on the internet, while also protecting their children’s privacy and teaching them good online habits.  The startup was founded by Nino Dvalidze (pictured), an entrepreneur and a mother of two from the United Kingdom. Dvalidze told TechCrunch that the idea for Young Minds came from conversations with fellow … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • Haiku and SerenityOS aren’t daily drivers, but they’re the best weekend projects
  • I clustered budget-friendly devices into a Proxmox HA lab, and it's more useful than I thought
  • If you just need a laptop for the basics, this one at $349 is an absolute steal
  • The best Prime Day SSD deals: Save on gear from Samsung, Crucial, Seagate and others
  • 3 mistakes that ruined my first attempt at building a PC

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023