N-able says attackers bypassed N-central authentication, reached managed client devices and installed Cloudflare tunnels that survived server access revocation.