China Attacks Vulnerabilities In Microsoft Software

China-linked hackers exploiting a critical vulnerability in Microsoft’s software and turning that access toward ransomware. While you can find out about the issue here, this is the TL:DR. Please read the entire chain:

Phillip Wylie, Chief Security Evangelist & Sr. Consultant, Suzu Labs (https://www.linkedin.com/in/phillipwylie)

“The biggest takeaway isn’t just another critical vulnerability – it’s that attackers are increasingly targeting the tools organizations trust most. RMM platforms, identity systems, and security products provide privileged access by design, making them ideal force multipliers for threat actors. Organizations should treat these platforms as crown-jewel assets, prioritize rapid patching, closely monitor privileged activity, and assume that even trusted management infrastructure can become an attack vector.”

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“This particular attack fits into China’s broader cyber great power initiative that they’ve been working on for well over a decade, building the capability to exploit and gain access to as many systems as possible. I tend to think this particular attack was triggered by the vulnerability being discovered. China may have already been exploiting it for some period of time before the vendor publicly disclosed it on July 31.

“And this gets into a larger question that I think we need to ask whenever we see nation-state attacks suddenly transition into ransomware campaigns. What were they doing before?

“Remember, with a nation state like China, Russia, or even the United States, the primary goal generally isn’t ransomware. The goal is access. They want to dwell inside environments and maintain that access for as long as they possibly can. The way this particular attack has been linked to China leads me to believe the vulnerability may have been used for that type of access and persistence for some period of time. But once the vulnerability became public and a patch was available, its usefulness for longer-term nation-state operations dropped significantly. At that point, you might as well transfer the capability over to ransomware operations and extract whatever remaining value you can from the vulnerable systems that are still out there.

“There’s another issue here involving the vendors we choose for core security technologies, especially RMM tools. We really need to question whether we should be self-hosting these systems at all. If it’s a cloud service, the provider can potentially patch and update that service very quickly across its entire customer base. If you’re self-hosting it, you’re now dependent on your own organization getting that patch deployed as quickly as possible. And that matters here. Some of the research we’ve been seeing indicates that more than 25% of these servers may still be unpatched and vulnerable to this attack.

“Once again, this highlights one of the major problems with on-premises technology when a serious vulnerability drops. Getting a patch is one thing. Getting that patch deployed everywhere fast enough to matter is something completely different.”

The threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the CISA KEV catalog on August 3, 2026. You should apply all updates to your Windows systems and Microsoft Defender for Endpoint detects this activity. So update that too.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading