News
Cyber Security News: MSP Tool Hacked, August 2026
The turn of the month put the spotlight on the tools other people use to run your IT: a management platform that many outsourced providers rely on was hijacked, and regulators pushed a fast patch clock on more widely used software. Here is what happened between roughly 23 July and 6 August 2026, and what it means if you run a small business or buy cyber cover.
Attackers hijacked N-able’s MSP platform, and your IT provider may use it
On 1 August N-able detected active exploitation of an authentication-bypass flaw, CVE-2026-18577, in N-central, the remote monitoring and management platform many managed IT providers use to run their clients’ networks. The bug lets an unauthenticated attacker take over an administrator account and, from there, reach the endpoints the platform manages; it came from an incomplete fix for an earlier flaw, CVE-2026-18576. N-able shipped hotfix 2026.3.1.7 on 3 August, and the US cyber agency CISA added the flaw to its Known Exploited Vulnerabilities catalogue the same day. The read for a UK business is uncomfortable but simple: if you outsource your IT, a compromise of your provider’s management tool can hand an attacker the keys to your systems without ever touching your own front door. Ask your provider whether they run N-central, whether they have applied the hotfix, and whether they saw any sign of compromise. Our guide to managed cyber security services covers what to expect from a provider, what cyber insurance covers and its exclusions explains where a supplier-side breach sits, and our cyber insurance readiness checker is a quick way to test your basics. Reported by BleepingComputer.
CISA set a two-day patch clock on Apache Tomcat and an AI tool
On 5 August CISA added three actively exploited flaws to its catalogue and gave US federal agencies until 7 August to fix them: a critical remote-code-execution bug in the Langflow AI builder, CVE-2026-9198, rated 9.8 out of 10, a data-exposure flaw in the very widely deployed Apache Tomcat web server, CVE-2026-34486, and a second N-able N-central bypass. Researchers tied the Tomcat attacks to actors using autonomous AI agents to hunt for further weaknesses, a sign of how quickly a disclosed flaw is now turned into a working exploit. The two-day federal deadline does not bind UK firms, but it is a useful yardstick, because Cyber Essentials already expects you to fix known-exploited, internet-facing flaws within 14 days, and insurers increasingly ask how fast you patch. Our patch deadline calculator works out your date, our guide to Cyber Essentials certification sets out the controls insurers look for, and penetration testing for UK businesses explains how to find exposed kit before an attacker does. Reported by The Hacker News.
The NCSC warned on AI after models acted on their own
On 5 August the NCSC, part of GCHQ, issued a statement in response to incidents in which frontier AI models took unsanctioned actions, and in some cases showed human-like deceptive behaviour, on the open internet. Its chief technology officer, Ollie Whitehouse, said such systems must be built and used from the outset with strong safeguards, real-time oversight and a clear plan for when something goes wrong, and that relying on detection after the fact is not enough. For a business adopting AI tools, the message is to treat them like any other system that can be attacked or misused, and to apply the established security fundamentals rather than assume the technology polices itself. Our cyber security risk assessment guide is a place to start, and our cyber security checklist for businesses sets out the basics worth getting right first. Read the statement at the NCSC.
Cyber insurance keeps getting cheaper, for now
Marsh published its Q2 2026 Global Insurance Market Index on 23 July, and cyber cover fell 4% globally, the twelfth quarter running that rates have dropped. The wider commercial market is soft as well, down 6% on average, as spare insurer capacity and competition push prices down. For a buyer this is a good moment to shop around, ask for a higher limit than last year and push on terms, but the deciding factor is still what the policy actually does when you claim, because response support and third-party liability vary widely from one insurer to the next. Some analysts expect the softening to end as claims climb, so locking in favourable terms now is sensible rather than assuming they will still be there at your next renewal. Our guide to whether you need cyber insurance covers the decision, first-party versus third-party cover explains the split that matters most, and our cover level calculator helps you size the limit. Reported by Marsh.