All issues
Tech & Security Intelligence Issue 012 · 10 Aug 2026

The Weekly
Brief

The software that manages your PCs is now the way in — and the first patch didn't hold. Microsoft lets other companies recall emails from your inbox, the biometrics deadline quietly passed, and the scammers are now phoning as the NCSC.

Paul, Director of Node-Red
Curated by Paul
Editor · Node-Red

4 stories · 6 min read

In this issue

01 Threat Alert

Attackers are taking over the software that manages business PCs — and the first patch didn't hold

Almost every managed business runs some form of remote monitoring and management software — the agent that lets an IT provider patch, monitor and remotely control staff machines. One of the biggest, N-able's N-central, has spent the past fortnight being taken apart. In late July N-able disclosed CVE-2026-18556, an authentication bypass that hands an attacker an administrator account on the N-central server without any credentials at all, and shipped a fix.

The fix didn't hold. Attackers found a second route to the same outcome, forcing a fresh advisory, a second identifier — CVE-2026-18577, also rated 8.2 — and an emergency hotfix in build 2026.3.1.7 on 2 August. In the intrusions N-able investigated, attackers used their new admin access to drive N-central's own Take Control remote-access feature onto managed endpoints, then registered Cloudflare tunnels as services on those machines. Because a tunnel dials out, it needs no inbound firewall rule, and it kept working after the N-central server access was cut off. CISA added the original flaw to its Known Exploited Vulnerabilities catalogue on 5 August. N-able says it has contacted "a limited number of affected customers", and warns that patching the server does not remove tunnels already planted on endpoints.

02 Microsoft 365

From mid-August, another company can un-send an email from your inbox — if you let them

Message recall in Outlook has always stopped at the edge of your own organisation: you could claw back an email sent to a colleague, never one sent to a customer. That changes from mid-August, as Microsoft begins rolling out cross-tenant message recall in Exchange Online (message centre post MC1423106), with the rollout running through to early September 2026.

The important detail is that it is off by default, and the control sits with the receiving organisation, not the sender. Nobody can pull a message out of your staff's mailboxes unless your administrator first turns the feature on in Exchange Online PowerShell and then explicitly allow-lists the sending organisation's tenant ID. Do nothing and nothing changes. Where it is enabled, a recall from a trusted partner behaves exactly like an internal one.

03 New Zealand

The biometrics deadline passed on 3 August — and most businesses don't know it applies to them

New Zealand's Biometric Processing Privacy Code 2025 has been law since 3 November 2025 for anything newly switched on, but organisations already running biometric systems were given a nine-month grace period to get in line. That period ended on 3 August 2026. From that date every existing system has to meet the Code in full.

The catch is how ordinary the affected technology is. The Code covers biometric verification (one-to-one matching), identification (one-to-many) and categorisation — which in practice means fingerprint time clocks, voice authentication on a phone line, facial recognition used to open an account or watch a shop floor, and even behavioural typing analysis. Before running any of it you must complete a proportionality assessment — is this genuinely necessary, and would something less intrusive do the same job — and tell people clearly, before you collect, what is being taken, why, how long you'll keep it and what the alternative is. The Code also flatly prohibits using biometrics to infer someone's emotional state, attention, health or ethnicity.

04 Scams

The scammers are now phoning as the NCSC — the agency you'd report a scam to

New Zealand's National Cyber Security Centre has warned that fraudsters are making unsolicited phone calls while claiming to be from the NCSC itself. It is a neat piece of social engineering: the agency you'd ring to check whether something is a scam is now the cover story for the scam. The NCSC's guidance is blunt — it does not generally initiate unsolicited contact by phone, so an unexpected call claiming otherwise should not be followed, and can be reported through the agency's own portal.

It lands against a quarter of unusually bad numbers. The NCSC handled 1,164 incident reports in the first quarter of 2026, of which 437 were phishing and credential harvesting and 340 were scams and fraud accounting for around NZ$3.8 million of direct loss. Total reported losses reached NZ$5.6 million, up from NZ$3.2 million the previous quarter — and the quarter included three incidents serious enough to be classified "highly significant", the first of that grade since 2021/22.

Tip of the week

Write down every tool that can take over your screen

Stories 01 and 04 are the same problem from opposite ends: an attacker taking remote control of a machine through a management console, and an attacker talking a person into handing it over on the phone. Both are far easier to spot if you know what normal looks like — so spend twenty minutes making a list of every product in your business that can view or control a screen remotely. Your IT provider’s management agent, the remote-support tool, anything a software vendor installed to help with their own system, and anything a staff member downloaded once to help a relative. For each one, answer three questions: who can use it, does it require MFA, and would you notice if it ran at 2am. The list is almost always longer than people expect, and it is the forgotten entries that get used against you. Then agree the human half of the rule with your team: nobody outside that list ever gets control of a screen, no matter who the caller says they are, and hanging up to ring back on a number you looked up yourself is always the right move rather than a rude one. If you’d like ours, ask — we’ll send you the list of exactly what can reach your machines and who holds the keys.

Node-Red

Want all of this handled for you?

We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.

Book your free IT checkup