Hackers abuse Faronics Deploy admin tool to install ScreenConnect

2026-09-02T01:23:22Z574d9188001459e74160e0b4e492c4b4169102dda950cd411d919b4b590fe6fa
CVE-2026-0768ATM jackpottingBGP hijackingCisco IOS XRClickFixFaronics DeployGRE tunnelLangflowMicrosoft ExchangePaperCutPowerShellScreenConnectVirtualizoractive exploitationauthentication bypasscredential theftcritical vulnerabilitycryptocurrencydata breachhealthcareremote access softwareremote code executionreverse tunnelssupply-chain compromisethreat intelligence

What happened

A BleepingComputer security-news feed reports multiple active and emerging cyber threats, including exploitation of a critical unauthenticated Langflow remote-code-execution flaw (CVE-2026-0768) to steal OpenAI and AWS credentials, abuse of Faronics Deploy to install ScreenConnect, malicious Virtualizor updates delivered through BGP hijacking, exploitation of PaperCut zero-days, Microsoft Exchange authentication-bypass exposure, ClickFix/TerminalFix PowerShell attacks, and Cisco router compromise. The feed also covers major healthcare data breaches, ATM jackpotting, and a cryptocurrency-lendig

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
574d9188001459e74160e0b4e492c4b4169102dda950cd411d919b4b590fe6fa
Enrichment time
2026-09-02T01:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.