N-able N-central Take Control Session Abuse Consistent with CVE-2026-18577

Detects N-able N-central Take Control remote session start/end events in the Windows Application log where the viewer identity is the default N-central support account 'MSP Support' / mspsupport@n-able.com, or the source/viewer IP matches known attacker infrastructure associated with active exploitation of CVE-2026-18577.