Advertisement
Threat Actors Abuse Action1 RMM Tool via Phishing
Threat actors are actively exploiting Action1 RMM tools, leveraging phishing emails with fake PDF invoices to deliver malicious VBS and MSI files.
Securing RMM Software: 8 Controls MSPs Must Test
Learn 8 essential security controls MSPs must test when evaluating remote monitoring and management software to prevent downstream supply chain attacks.
ScreenConnect Client Abused in Phishing Campaigns
Threat actors are leveraging legitimate ConnectWise ScreenConnect clients in phishing campaigns to gain remote access to victim systems.
Microsoft Teams Abuse, The Gentlemen Ransomware, and PhaaS Trends
Analysis of social engineering campaigns via Microsoft Teams, The Gentlemen ransomware operations, and emerging phishing-as-a-service kits.
CVE-2026-48558: SimpleHelp OIDC Authentication Bypass & Malware
Threat actors are actively exploiting CVE-2026-48558, a critical SimpleHelp OpenID Connect authentication bypass vulnerability, to deploy TaskWeaver and Djinn Stealer…
WhatsApp VBScript Campaign Installs ManageEngine RMM — Technical Guide
Attackers are targeting WhatsApp Desktop users with malicious VBScripts to install ManageEngine RMM, enabling unauthorized remote access and control.
Advertisement
UNC3753 Targets US Law Firms with Vishing & Physical Intrusions
UNC3753 (Luna Moth) leverages vishing and physical office intrusions to steal sensitive data from US law firms and professional services, leading to swift extortion.
Stealthy Phishing Abuses ConnectWise ScreenConnect, AnyDesk RMM
Attackers leverage legitimate RMM tools like ConnectWise ScreenConnect and AnyDesk in a sophisticated phishing campaign, impacting over 80 organizations and evading…