<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #RMM</title><description>Cybersecurity articles tagged #RMM on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Threat Actors Abuse Action1 RMM Tool via Phishing</title><link>https://runtimerebel.com/blog/threat-actors-abuse-action1-rmm-tool-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/threat-actors-abuse-action1-rmm-tool-via-phishing</guid><description>Threat actors are actively exploiting Action1 RMM tools, leveraging phishing emails with fake PDF invoices to deliver malicious VBS and MSI files.</description><pubDate>Tue, 06 Oct 2026 14:41:12 GMT</pubDate><category>Phishing</category><category>Persistence</category><category>Action1</category><category>RMM</category><category>VBS</category></item><item><title>Securing RMM Software: 8 Controls MSPs Must Test</title><link>https://runtimerebel.com/blog/securing-rmm-software-8-controls-msps-must-test</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-rmm-software-8-controls-msps-must-test</guid><description>Learn 8 essential security controls MSPs must test when evaluating remote monitoring and management software to prevent downstream supply chain attacks.</description><pubDate>Tue, 06 Oct 2026 14:37:19 GMT</pubDate><category>Supply Chain Attack</category><category>Vulnerability Management</category><category>RMM</category><category>Managed Service Providers</category><category>CVE-2026-86218</category></item><item><title>ScreenConnect Client Abused in Phishing Campaigns</title><link>https://runtimerebel.com/blog/screenconnect-client-abused-in-phishing-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/screenconnect-client-abused-in-phishing-campaigns</guid><description>Threat actors are leveraging legitimate ConnectWise ScreenConnect clients in phishing campaigns to gain remote access to victim systems.</description><pubDate>Thu, 01 Oct 2026 15:07:34 GMT</pubDate><category>Screenconnect</category><category>Connectwise</category><category>RMM</category><category>Phishing</category><category>Remote Access</category></item><item><title>Microsoft Teams Abuse, The Gentlemen Ransomware, and PhaaS Trends</title><link>https://runtimerebel.com/blog/microsoft-teams-abuse-the-gentlemen-ransomware-and-phaas-trends</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-abuse-the-gentlemen-ransomware-and-phaas-trends</guid><description>Analysis of social engineering campaigns via Microsoft Teams, The Gentlemen ransomware operations, and emerging phishing-as-a-service kits.</description><pubDate>Fri, 04 Sep 2026 02:00:26 GMT</pubDate><category>Microsoft Teams</category><category>Ransomware</category><category>Phishing</category><category>Credential Theft</category><category>RMM</category></item><item><title>CVE-2026-48558: SimpleHelp OIDC Authentication Bypass &amp; Malware</title><link>https://runtimerebel.com/blog/cve-2026-48558-simplehelp-oidc-authentication-bypass-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48558-simplehelp-oidc-authentication-bypass-malware</guid><description>Threat actors are actively exploiting CVE-2026-48558, a critical SimpleHelp OpenID Connect authentication bypass vulnerability, to deploy TaskWeaver and Djinn Stealer…</description><pubDate>Tue, 30 Jun 2026 12:48:54 GMT</pubDate><category>CVE-2026-48558</category><category>SimpleHelp</category><category>TaskWeaver</category><category>Djinn Stealer</category><category>Authentication Bypass</category><category>OIDC</category><category>RMM</category></item><item><title>WhatsApp VBScript Campaign Installs ManageEngine RMM — Technical Guide</title><link>https://runtimerebel.com/blog/whatsapp-vbscript-campaign-installs-manageengine-rmm-technical-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/whatsapp-vbscript-campaign-installs-manageengine-rmm-technical-guide</guid><description>Attackers are targeting WhatsApp Desktop users with malicious VBScripts to install ManageEngine RMM, enabling unauthorized remote access and control.</description><pubDate>Tue, 23 Jun 2026 09:18:25 GMT</pubDate><category>WhatsApp</category><category>VBScript</category><category>ManageEngine</category><category>RMM</category><category>Remote Access</category><category>Social Engineering</category></item><item><title>UNC3753 Targets US Law Firms with Vishing &amp; Physical Intrusions</title><link>https://runtimerebel.com/blog/unc3753-targets-us-law-firms-with-vishing-physical-intrusions</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc3753-targets-us-law-firms-with-vishing-physical-intrusions</guid><description>UNC3753 (Luna Moth) leverages vishing and physical office intrusions to steal sensitive data from US law firms and professional services, leading to swift extortion.</description><pubDate>Fri, 05 Jun 2026 16:59:08 GMT</pubDate><category>UNC3753</category><category>Luna Moth</category><category>Silent Ransom Group</category><category>Vishing</category><category>Social Engineering</category><category>Data Theft</category><category>Extortion</category><category>Law Firms</category><category>Physical Intrusion</category><category>RMM</category><category>WinSCP</category><category>Rclone</category></item><item><title>Stealthy Phishing Abuses ConnectWise ScreenConnect, AnyDesk RMM</title><link>https://runtimerebel.com/blog/stealthy-phishing-abuses-connectwise-screenconnect-anydesk-rmm</link><guid isPermaLink="true">https://runtimerebel.com/blog/stealthy-phishing-abuses-connectwise-screenconnect-anydesk-rmm</guid><description>Attackers leverage legitimate RMM tools like ConnectWise ScreenConnect and AnyDesk in a sophisticated phishing campaign, impacting over 80 organizations and evading…</description><pubDate>Tue, 05 May 2026 00:47:28 GMT</pubDate><category>RMM</category><category>Phishing</category><category>ConnectWise ScreenConnect</category><category>AnyDesk</category><category>Evasion</category><category>Threat Campaign</category></item></channel></rss>