SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
2026-07-01T19:24:14Z•5c2f0c8590b207e4fea2cb884a6ff63c884d87a9ab7610ee3624c22bbd67ae2b
AI-securityAPI-key-leakAsyncRATClickFixMoneroOusabanPureLogsRustDuckScreenConnectVEIL#DROPactive-exploitationbanking-trojanbotnetbrowser-ransomwarecryptominermalwarepassword-sprayphantom-squattingphishingransomwareremote-accessseo-poisoningstealersupply-chainvulnerability
What happened
The collection highlights a surge of high-severity active threats and disclosures: SEO-poisoned spoofed software sites delivering AsyncRAT via ScreenConnect; multi-stage stealer campaigns (VEIL#DROP delivering PureLogs) and banking trojans (Ousaban) targeting Iberian users; the re-emergence of RustDuck botnet for DDoS; novel browser-based ransomware and a Monero miner delivered via Langflow RCE exploitation. Multiple critical/maximum-severity vulnerabilities are in play and under active exploitation or prompting urgent patching (notably Kemp LoadMaster, SimpleHelp, Langflow, Cursor, and Citrix
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 5c2f0c8590b207e4fea2cb884a6ff63c884d87a9ab7610ee3624c22bbd67ae2b
- Enrichment time
- 2026-07-01T19:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.