SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
2026-08-05T08:51:35Z•63823234851e48fa3d3003f43e54adef148bb5c62d1449c7faf05371ebf039a1
CVE-2026-18577CVE-2026-58048AI-assisted-attacksConnectWiseDeepSeekINC ransomwareN-able N-centralSMOKE#SCREENScreenConnectSharePointSonicWall SMA 1000authentication-bypasscPanelcredential-exposuredata-breachfake-software-updatesknown-exploited-vulnerabilityphishingransomwareremote-access-trojansocial-engineeringsource-code-leak
What happened
SecurityAffairs reports multiple incidents and vulnerabilities, including an active SMOKE#SCREEN campaign delivering ScreenConnect through fake software updates, SharePoint exploitation affecting approximately 200 Swiss federal IT agency accounts, INC ransomware exploitation of SonicWall SMA 1000 flaws, critical cPanel vulnerability CVE-2026-58048 enabling authenticated SQL execution as root, and actively exploited N-able N-central authentication bypass CVE-2026-18577. Additional reports cover data breaches, AI-assisted attacks, ransomware extortion, and alleged source-code and secrets leakage
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 63823234851e48fa3d3003f43e54adef148bb5c62d1449c7faf05371ebf039a1
- Enrichment time
- 2026-08-05T08:51:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.