SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access

2026-08-05T08:51:35Z63823234851e48fa3d3003f43e54adef148bb5c62d1449c7faf05371ebf039a1
CVE-2026-18577CVE-2026-58048AI-assisted-attacksConnectWiseDeepSeekINC ransomwareN-able N-centralSMOKE#SCREENScreenConnectSharePointSonicWall SMA 1000authentication-bypasscPanelcredential-exposuredata-breachfake-software-updatesknown-exploited-vulnerabilityphishingransomwareremote-access-trojansocial-engineeringsource-code-leak

What happened

SecurityAffairs reports multiple incidents and vulnerabilities, including an active SMOKE#SCREEN campaign delivering ScreenConnect through fake software updates, SharePoint exploitation affecting approximately 200 Swiss federal IT agency accounts, INC ransomware exploitation of SonicWall SMA 1000 flaws, critical cPanel vulnerability CVE-2026-58048 enabling authenticated SQL execution as root, and actively exploited N-able N-central authentication bypass CVE-2026-18577. Additional reports cover data breaches, AI-assisted attacks, ransomware extortion, and alleged source-code and secrets leakage

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
63823234851e48fa3d3003f43e54adef148bb5c62d1449c7faf05371ebf039a1
Enrichment time
2026-08-05T08:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.