remote access

Attackers spread malware through ScreenConnect file transfers

Attackers spread malware through ScreenConnect file transfers 2026-09-07 at 12:13 By Sinisa Markovic A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A CVE identifier and an official fix will be issued within the week,” the company wrote in its September 3 advisory. ScreenConnect […]

Attackers spread malware through ScreenConnect file transfers Read More »

SonicWall SMA 1000 appliances under attack via zero-day flaws

SonicWall SMA 1000 appliances under attack via zero-day flaws 2026-09-02 at 13:13 By Zeljka Zorz Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built […]

SonicWall SMA 1000 appliances under attack via zero-day flaws Read More »

Attackers plant remote access tools on compromised PaperCut servers

Attackers plant remote access tools on compromised PaperCut servers 2026-08-31 at 17:54 By Zeljka Zorz The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools The vendor […]

Attackers plant remote access tools on compromised PaperCut servers Read More »

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove 2026-08-05 at 11:43 By Zeljka Zorz A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it. Different traps for Mac and Windows users By […]

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Read More »

FreeRDP 3.29.0 security update resolves 22 advisories

FreeRDP 3.29.0 security update resolves 22 advisories 2026-07-15 at 11:42 By Anamarija Pogorelec FreeRDP is a free implementation of the Remote Desktop Protocol, released under the Apache license, and it runs on a large share of workstations and servers through the many tools built on it. The 3.29.0 version is a security, bugfix, and maintenance […]

FreeRDP 3.29.0 security update resolves 22 advisories Read More »

Hundreds of Internet-Facing VNC Servers Expose ICS/OT

Hundreds of Internet-Facing VNC Servers Expose ICS/OT 2026-04-29 at 15:03 By Eduard Kovacs Forescout has identified tens of thousands of exposed RDP and VNC servers that can be mapped to specific industries. The post Hundreds of Internet-Facing VNC Servers Expose ICS/OT appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hundreds of Internet-Facing VNC Servers Expose ICS/OT Read More »

Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks

Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks 2026-04-23 at 07:13 By Mirko Zorz The 2026 InsurSec Report from At-Bay, covering more than 100,000 policy years of claims data, documents a 7% year-over-year rise in overall claim frequency and an all-time high average severity of $221,000. Ransomware severity reached $508,000, up 16% […]

Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks Read More »

Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks

Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks 2026-03-26 at 15:52 By Zeljka Zorz Telecommunications providers around the world have been dealing with the burrowing efforts of the China-linked APTs for many years now. To help them identify hard-to-detect implants used by the China-based group dubbed Red Menshen, Rapid7 researchers have […]

Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks Read More »

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731)

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) 2026-02-09 at 13:36 By Zeljka Zorz BeyondTrust fixed a critical remote code execution vulnerability (CVE-2026-1731) in its Remote Support (RS) and Privileged Remote Access (PRA) solutions and is urging self-hosted customers to apply the patch as soon a possible. Unlike the Remote Support zero-day […]

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) Read More »

Attackers exploited another Gladinet Triofox zero-day (CVE-2025-12480)

Attackers exploited another Gladinet Triofox zero-day (CVE-2025-12480) 2025-11-11 at 14:47 By Zeljka Zorz Attackers have exploited a now-fixed vulnerability (CVE-2025-12480) in the Gladinet Triofox secure file sharing and remote access platform while it was still a zero-day, Mandiant revealed on Monday. CVE-2025-12480 exploitation and attack details Gladinet’s Triofox solution is used by medium and large […]

Attackers exploited another Gladinet Triofox zero-day (CVE-2025-12480) Read More »

Ransomware, extortion groups adapt as payment rates reach historic lows

Ransomware, extortion groups adapt as payment rates reach historic lows 2025-10-27 at 15:12 By Zeljka Zorz Ransomware groups are facing an economic downturn of their own: In Q3 2025, only 23 percent of victims paid a ransom, and for data theft incidents that involved no encryption, the payment rate dropped to just 19 percent, according […]

Ransomware, extortion groups adapt as payment rates reach historic lows Read More »

The five-minute guide to OT cyber resilience

The five-minute guide to OT cyber resilience 2025-10-13 at 08:19 By Help Net Security In this Help Net Security video, Rob Demain, CEO of e2e-assure, explains the essentials of OT cybersecurity resilience. He discusses the importance of understanding remote access points, supply chain connections, and the need for specialized sensors to monitor OT networks that […]

The five-minute guide to OT cyber resilience Read More »

Attackers are exploiting Gladinet CentreStack, Triofox vulnerability with no patch (CVE-2025-11371)

Attackers are exploiting Gladinet CentreStack, Triofox vulnerability with no patch (CVE-2025-11371) 2025-10-10 at 13:40 By Zeljka Zorz CVE-2025-11371, a unauthenticated Local File Inclusion vulnerability in Gladinet CentreStack and Triofox file-sharing and remote access platforms, is being exploited by attackers in the wild. While Gladinet is aware of the vulnerability and of its active exploitation, a […]

Attackers are exploiting Gladinet CentreStack, Triofox vulnerability with no patch (CVE-2025-11371) Read More »

Firezone: Open-source platform to securely manage remote access

Firezone: Open-source platform to securely manage remote access 2025-09-29 at 08:36 By Sinisa Markovic Firezone is an open-source platform that helps organizations of any size manage secure remote access. Unlike most VPNs, it uses a least-privileged model, giving users only the access they need. Firezone was built to scale from the start, so you can […]

Firezone: Open-source platform to securely manage remote access Read More »

Attackers breached ConnectWise, compromised customer ScreenConnect instances

Attackers breached ConnectWise, compromised customer ScreenConnect instances 2025-06-02 at 20:19 By Zeljka Zorz A suspected “sophisticated nation state actor” has compromised ScreenConnect cloud instances of a “very small number” of ConnectWise customers, the company has revealed on Wednesday. “We have not observed any additional suspicious activity in ScreenConnect cloud instances since the patch was released […]

Attackers breached ConnectWise, compromised customer ScreenConnect instances Read More »

SimpleHelp Remote Access Software Exploited in Attacks

SimpleHelp Remote Access Software Exploited in Attacks 2025-01-29 at 12:48 By Ionut Arghire Threat actors have been exploiting SimpleHelp remote access software shortly after the disclosure of three vulnerabilities. The post SimpleHelp Remote Access Software Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SimpleHelp Remote Access Software Exploited in Attacks Read More »

Ransomware attackers are “vishing” organizations via Microsoft Teams

Ransomware attackers are “vishing” organizations via Microsoft Teams 2025-01-21 at 14:10 By Zeljka Zorz The “email bombing + posing as tech support via Microsoft Teams” combination is proving fruitful for two threat actors looking to deliver ransomware to organizations, and they seem to be ramping up their efforts. “Sophos MDR has observed more than 15 […]

Ransomware attackers are “vishing” organizations via Microsoft Teams Read More »

CERT-UA warns against “security audit” requests via AnyDesk

CERT-UA warns against “security audit” requests via AnyDesk 2025-01-20 at 11:34 By Zeljka Zorz Attackers are impersonating the Computer Emergency Response Team of Ukraine (CERT-UA) via AnyDesk to gain access to target computers. The request (Source: CERT-UA) “Unidentified individuals are sending connection requests via AnyDesk under the pretext of conducting a ‘security audit to verify […]

CERT-UA warns against “security audit” requests via AnyDesk Read More »

Critical SimpleHelp vulnerabilities fixed, update your server instances!

Critical SimpleHelp vulnerabilities fixed, update your server instances! 2025-01-16 at 17:04 By Zeljka Zorz If you’re an organization using SimpleHelp for your remote IT support/access needs, you should update or patch your server installation without delay, to fix security vulnerabilities that may be exploited by remote attackers to execute code on the underlying host. About […]

Critical SimpleHelp vulnerabilities fixed, update your server instances! Read More »

BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356)

BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356) 2024-12-18 at 11:48 By Zeljka Zorz BeyondTrust has fixed an unauthenticated command injection vulnerability (CVE-2024-12356) in its Privileged Remote Access (PRA) and Remote Support (RS) products that may allow remote code execution, and is urging organizations with on-premise installations to test the patch and implement […]

BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356) Read More »

Scroll to Top