Hackers abuse Faronics Deploy admin tool to install ScreenConnect
2026-09-02T01:23:22Z•574d9188001459e74160e0b4e492c4b4169102dda950cd411d919b4b590fe6fa
CVE-2026-0768ATM jackpottingBGP hijackingCisco IOS XRClickFixFaronics DeployGRE tunnelLangflowMicrosoft ExchangePaperCutPowerShellScreenConnectVirtualizoractive exploitationauthentication bypasscredential theftcritical vulnerabilitycryptocurrencydata breachhealthcareremote access softwareremote code executionreverse tunnelssupply-chain compromisethreat intelligence
What happened
A BleepingComputer security-news feed reports multiple active and emerging cyber threats, including exploitation of a critical unauthenticated Langflow remote-code-execution flaw (CVE-2026-0768) to steal OpenAI and AWS credentials, abuse of Faronics Deploy to install ScreenConnect, malicious Virtualizor updates delivered through BGP hijacking, exploitation of PaperCut zero-days, Microsoft Exchange authentication-bypass exposure, ClickFix/TerminalFix PowerShell attacks, and Cisco router compromise. The feed also covers major healthcare data breaches, ATM jackpotting, and a cryptocurrency-lendig
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 574d9188001459e74160e0b4e492c4b4169102dda950cd411d919b4b590fe6fa
- Enrichment time
- 2026-09-02T01:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.