The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 07:52 am AEST · 11 August 2026

41 DAYS AGO Key event Share

China-linked hackers exploit software flaw in ransomware supply-chain attack

China-linked hackers exploit software flaw in ransomware supply-chain attack
Photograph: The Record

Microsoft Threat Intelligence warned that Storm-1175, a financially motivated group linked to China, is exploiting a critical vulnerability in N-central, a remote monitoring tool used by managed service providers, to deploy custom ransomware called StormEncryptor across victim networks. The group began attacks on August 2, the same day the flaw in N-central was disclosed, gaining what Huntress described as "unauthenticated, 'god-mode' access" to servers that control thousands of downstream business endpoints.

A single compromised N-central server can cascade into dozens of ransomware incidents across an MSP's entire client base. Storm-1175 previously used Medusa ransomware to target healthcare, professional services and finance organisations in Australia, Britain and the United States, and has moved from initial access to full encryption in under 24 hours. N-able, which makes N-central, said it contacted a "limited number" of affected customers. Huntress found more than half of reachable N-central cloud servers across its partner base remained unpatched even after emergency fixes were issued on August 2 and August 6, The Record reports.

China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns A China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able. therecord.media
cybersecurityransomwaremicrosoftsupply-chain-attackvulnerability

Follow the live coverage →

China-linked hackers exploit software flaw in ransomware supply-chain attack | The Financial Register Inward Money