SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

2026-07-01T19:24:14Z5c2f0c8590b207e4fea2cb884a6ff63c884d87a9ab7610ee3624c22bbd67ae2b
AI-securityAPI-key-leakAsyncRATClickFixMoneroOusabanPureLogsRustDuckScreenConnectVEIL#DROPactive-exploitationbanking-trojanbotnetbrowser-ransomwarecryptominermalwarepassword-sprayphantom-squattingphishingransomwareremote-accessseo-poisoningstealersupply-chainvulnerability

What happened

The collection highlights a surge of high-severity active threats and disclosures: SEO-poisoned spoofed software sites delivering AsyncRAT via ScreenConnect; multi-stage stealer campaigns (VEIL#DROP delivering PureLogs) and banking trojans (Ousaban) targeting Iberian users; the re-emergence of RustDuck botnet for DDoS; novel browser-based ransomware and a Monero miner delivered via Langflow RCE exploitation. Multiple critical/maximum-severity vulnerabilities are in play and under active exploitation or prompting urgent patching (notably Kemp LoadMaster, SimpleHelp, Langflow, Cursor, and Citrix

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5c2f0c8590b207e4fea2cb884a6ff63c884d87a9ab7610ee3624c22bbd67ae2b
Enrichment time
2026-07-01T19:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.