A busier week than most, and the vendor news is the part that will cost you time if you miss it. Broadcom has quietly withdrawn the VDDK downloads, which matters to anyone with a vSphere exit on the books. AWS has added variable retention to S3 Object Lock, which is the first genuinely useful change to that feature in a while.
On the security side, two management platforms were exploited. N-able N-central and Cisco Secure Firewall Management Center, both pre-authentication, both reaching everything underneath them. If you run either, that is your week.
The EU’s Cyber Resilience Act also started its 24 hour reporting clock on Friday. That one is mostly your vendors’ problem rather than yours, which is worth understanding before you start quoting for it.
Vendor and product moves
Broadcom has pulled the VDDK downloads
Public downloads of the Virtual Disk Development Kit went away in late August with no announcement. VDDK is what backup software uses to read virtual disks. It is also what migration tooling uses to move VMs off vSphere onto Nutanix, Red Hat and Apache CloudStack. Broadcom says access is still available “through select TAP for its licensed use case, which has always been backup and recovery”, which is a fairly clear statement that it considers migration to be something else. The large backup vendors have partner relationships and are unaffected. Small migration consultancies, open source projects and customers doing it themselves are not.
The practical bit. If you have quoted a vSphere exit for a client, go and check what your tooling depends on before the cutover date arrives. Workarounds exist. Finding out you need one halfway through a migration is a different situation entirely.
Source: The Register
Veeam adds OpenShift VM protection in v13.1
Veeam Data Platform v13.1 picks up Red Hat OpenShift Virtualization support through the KubeVirt plug-in. OpenShift VMs get discovered automatically and fall under your existing policies, and there is cross hypervisor restore, so a VM can come back onto a different platform than the one it left. Veeam also describes OpenShift as “the leading landing zone” post Broadcom, which is the company’s own view of the market rather than anything independently measured.
The practical bit. The gap between a VM leaving vSphere and being properly covered on whatever it lands on is where people lose data. If you have migrations running, check that the destination actually inherited a policy rather than assuming it did.
Source: Veeam
S3 Object Lock now supports variable retention
AWS has added variable retention to S3 Object Lock. Instead of setting a fixed retain until date when the object is written, you set a retention mode with an event hold and a duration, and the clock only starts when the hold comes off. Before this you either picked a date far enough out to be safe and paid to store everything until then, or you wrote something to keep extending the dates on a schedule.
The practical bit. The worked example in the AWS post is the one to steal. Default new objects to a 30 day variable retention. An attacker then has to release the hold before anything can be deleted, and in compliance mode the wait is enforced regardless of who is asking. If you already sell immutability, this makes the story better without much work.
Source: AWS
Commvault previews a faster Active Directory recovery
Commvault has announced Active Directory Pre Recover. It keeps a clean standby copy of AD in an isolated environment using Cleanroom and Threat Scan, and the company says recovery drops from hours to minutes. Read the availability line carefully though. Early access is promised “in the coming months”, so there is nothing to deploy yet.
The practical bit. AD is usually the dependency that turns a recoverable incident into a long one, so the direction of travel is right. It is a note for later, not something to put in a proposal this quarter.
Source: Blocks and Files
What is being exploited
N-able N-central is being exploited
N-able has patched CVE-2026-86218, a static code injection flaw in N-central. CVSS 10.0, pre-authentication remote code execution. The fix shipped in 2026.3 Hotfix 4 on 5 September. CISA added it to the Known Exploited Vulnerabilities catalog with a federal deadline of 11 September, and N-able says it has “observed a handful of successful exploits against N-central customers”. watchTowr reproduced the attack.
The deployment model decides what you have to do. Hosted instances were patched server side and need nothing from you. On premises instances need HF4 applied by hand. HF3 is not enough. The zero day is unrelated to the two vulnerabilities HF3 fixed, so a box sitting on HF3 is still exposed.
N-central is the thing that reaches every endpoint you manage. A compromise there is not one client having a bad day, it is all of them at once, which is why access to platforms like this gets bought and sold. Patching closes the door. It does not tell you whether anyone came through it first. N-able has published indicators of compromise, and if your instance was reachable and unpatched between 5 and 11 September then you have some looking to do before you call this closed.
The practical bit. Check the version, then check the logs. Those are two separate jobs and only one of them is quick.
Source: The Hacker News · N-able
On premises SharePoint is being hit through a May patch
CVE-2026-45659 is a deserialization flaw in on premises SharePoint Server, rated CVSS 8.8. Microsoft patched it in May 2026. It has been exploited since at least July and was confirmed in ransomware activity by August. CISA has not said who is behind it. The activity looks like the China linked Storm-2603 operation that previously deployed Warlock, but nobody has formally attributed it.
The practical bit. On premises SharePoint is the classic thing that stops getting patched once a client is “mostly” on M365. Four months passed between the fix and ransomware showing up. Worth knowing which of your clients still have one running.
Source: ChannelPro Network
Qilin is using a Cisco FMC bypass
CVE-2026-20079 is a critical authentication bypass in Cisco Secure Firewall Management Center. It lets an unauthenticated attacker run scripts and potentially get root. The Qilin affiliate tracked as UAT-11988 goes in with static credentials, sets up Python SOCKS5 proxies and reverse SSH tunnels forwarding LDAP, Kerberos, SMB and WinRM, runs a custom antivirus killer, then deploys ransomware. CISA set a federal patching deadline of 12 September.
The practical bit. Same shape as N-central. The management interface gets compromised and everything it manages comes with it. These boxes deserve the patching discipline you already apply to domain controllers, and most of the time they do not get it.
Source: Security Affairs
September’s Windows Server updates break Remote Desktop
KB5122876 on Server 2019, KB5122882 on Server 2022 and KB5122871 on Server 2025 leave Remote Desktop Services working for a few hours, after which new connections start failing and existing sessions hang when they try to disconnect. One investigation points at a deadlock between RDP and the Local Session Manager service. Microsoft is looking at it and has not confirmed a cause or shipped a fix. Rolling back restores RDS and removes the month’s security updates with it.
The practical bit. That is an unpleasant choice in a month whose patch set includes two Windows privilege escalation flaws already being exploited. Make the call per client, write down which way you went and why, and do it now rather than at 2am when someone else is holding the ticket.
Source: BleepingComputer
A Conti developer got four years
Oleksii Lytvynenko, a 44 year old Ukrainian national extradited from Ireland, has been sentenced to four years in US federal prison after pleading guilty to conspiracy to commit wire fraud. He worked as an intruder and a developer for Conti, personally harmed at least 12 companies and wrote a loader used in attacks. Conti hit victims across 47 US states and 31 countries between 2020 and 2022, with payouts past $150m by January 2022 and more than 1,000 victims in total.
The practical bit. Four years against $150m in payments. Whatever is keeping ransomware numbers where they are, it is not the sentencing. Your ability to recover is still the only part of this you control.
Source: BleepingComputer
Regulation and compliance
CRA Article 14 reporting is now live
Article 14 of the Cyber Resilience Act became applicable on 11 September 2026. Manufacturers selling products with digital elements into the EU, wherever they are based, now have to file an early warning within 24 hours of finding an actively exploited vulnerability or a severe incident, a detailed notification within 72 hours, and a final report within 14 days of a fix being available. For serious incidents the final report is due a month after the first one. It all goes through ENISA’s Single Reporting Platform. Maximum fine is €15m or 2.5% of annual turnover, whichever is larger. The rest of the CRA, meaning security by design, mandatory updates and no default passwords, lands on 11 December 2027.
The practical bit. Check the scope before you either panic or start quoting for it. Most MSPs are not manufacturers, so this is a filing obligation that sits with your vendors. Two things follow from that. If you ship anything with digital elements into the EU, whether that is an appliance, a white labelled tool or your own software, find out now whether you are in scope. And expect vendor disclosure to get faster and noisier from here, which mostly shows up as more “our supplier has disclosed something” conversations with clients.
Source: The Register
NCSC has written about shadow AI
The NCSC warned on 7 September that staff using unapproved AI tools put corporate data somewhere the organisation cannot see, citing Microsoft research that 71% of UK employees had used unauthorised AI tools. Its advice leans towards governance rather than blocking, on the basis that you cannot realistically block every AI endpoint, so you are better off with a culture where people say what they are using and clear guardrails around it.
The practical bit. This is a piece of sellable work rather than a threat bulletin. An acceptable use policy, a DLP review and a short awareness session is a defined engagement with a regulator’s name attached to the reasoning, which makes it an easier conversation than most.
Source: Infosecurity Magazine
Also worth knowing
- CISA added four flaws to the KEV catalog. N-central’s CVE-2026-86218 and Adobe Commerce CVE-2026-75650, both CVSS 10.0, plus Windows privilege escalation flaws CVE-2026-81963 and CVE-2026-85880. Federal deadlines were 11 and 22 September. (Security Affairs)
- N-able’s HF3 fixed CVE-2026-86206 and CVE-2026-86207. It does not cover the zero day. HF4 is the one that matters. (N-able)
- WEKA is partnering with Backblaze to use B2 as a cloud tier, validated as a two tier pipeline for AI workloads. (Blocks and Files)
What to do this week
- Get N-central onto 2026.3 HF4. On premises only, hosted is already done. If the box was reachable from the internet and unpatched between 5 and 11 September, pull N-able’s indicators of compromise and go looking for unfamiliar accounts and scanning before you close the ticket.
- Find out which clients still run on premises SharePoint. The patch is from May and there is ransomware behind it now. “We are mostly on M365” is not an answer to this question.
- Decide the Remote Desktop question per client. Patched and broken, or rolled back and exposed. Either is defensible. Deciding it in advance and writing it down is the part that matters.
- Check VDDK exposure on any vSphere exit you have quoted. Do it now rather than at cutover.
Backuptron’s weekly briefing on backup, disaster recovery and business continuity for managed service providers.










