Glossary
Remote Monitoring and Management (RMM)
Software that IT providers and internal teams use to remotely administer fleets of machines — deploying patches, running scripts, and accessing desktops. Because RMM tools are powerful and trusted, attackers increasingly abuse legitimate RMM software for persistence and remote control, and compromising an MSP's RMM platform yields access to every downstream customer.
Recent coverage mentioning Remote Monitoring and Management (RMM)
Microsoft Teams Abuse, The Gentlemen Ransomware, and PhaaS Trends
Analysis of social engineering campaigns via Microsoft Teams, The Gentlemen ransomware operations, and emerging phishing-as-a-service kits.
BREEZE COMET Exploits Brazilian Financial Systems
BREEZE COMET, a financially motivated threat actor, targets Brazilian financial services for fraudulent transfers, leveraging custom malware and AI for development.
Spring Ring Voice Phishing Targets Microsoft Teams Users
Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.
msaRAT: Chaos Ransomware's Covert Browser-Based C2
Cisco Talos uncovers msaRAT, a new Rust-based RAT used by Chaos ransomware for covert C2 via Chrome DevTools Protocol, evading detection.
Q2 2026 IR Trends: Phishing, MFA Bypass, RMM Tool Abuse
Talos Q2 2026 incident response data shows rising phishing and MFA bypass, with new actors like UAT-11764 and Sinobi ransomware leveraging RMM tools.
CISA Warns: Actively Exploited Langflow, N-central, and Tomcat Vulnerabilities
CISA warns federal agencies and organizations about active exploitation of critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat.
Advertisement