NYDFS Issues Real-Time Alert on Software Exploitation

On August 11, 2026, the New York Department of Financial Services (NYDFS) issued an Industry Letter notifying its covered entities about an ongoing cybersecurity campaign targeting a known vulnerability in a monitoring and management software for managed service providers (MSPs) and IT departments. The vendor that provides the software published an update on August 10 informing its customers of the incident and providing further information on an associated hotfix to patch the vulnerability.

Issuing a real-time notice tied to a live vulnerability exploit is a notable departure from NYDFS’s usual approach: Rather than waiting to fold this event into a periodic bulletin or post-mortem advisory, NYDFS pushed out guidance in real time, putting covered entities on notice of the issue.

NYDFS has instructed covered entities to immediately identify whether they or any of their MSPs or other third-party service providers use the software, work with those parties to check for signs of unauthorized access or successful exploitation of the vulnerability, confirm that necessary patches are in place, and identify whether any of the covered entity’s systems, credentials or data were impacted.

The NYDFS notice emphasizes that covered entities are expected to stay actively engaged in cybersecurity risk management, including ongoing monitoring and oversight of their third-party service providers. Further, any covered entity potentially impacted by the software vulnerability should assess that exposure through diligence and direct engagement with the service provider and report the incident as required by Part 500. The notice is consistent with NYDFS’ guidance from October 2025, which emphasized that reliance on third-party service providers for access to information systems and nonpublic information carries real cybersecurity risk and requires ongoing governance responsibility owned at the senior level.

Cooley’s financial services and cyber/data/privacy teams are available to assist with covered entities that may be assessing this issue.