WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
2026-06-23T07:24:11Z•8d930ba7e02527a8da8708c98d8d376e113ad641ea186d2106e88c9545eeda08
ai-securityarystingerautojackbotnetcastlestealerdifytapfortibleedfortigategravity-smtpkluemalwaremanageengine-rmmnginxoauth-token-abuseoxloaderphishingransomwareremote-code-executionsquidbleedsupply-chainusbliter8vbscriptvulnerability-disclosurewhatsappwordpress
What happened
A broad set of active threats and high-impact vulnerabilities reported: a WhatsApp VBScript campaign distributing malicious VBS payloads that install legitimate ManageEngine RMM for remote access; multiple supply-chain and backdoor compromises (ShapedPlugin WordPress Pro plugins, poisoned plugin/update channels); disclosure of multi-tenant data‑exposure flaws in Dify (DifyTap); a long‑standing Squid proxy heap over‑read (Squidbleed) leaking cleartext HTTP; a new OXLOADER loader delivering CastleStealer via malicious Google Ads; widespread FortiGate compromise (FortiBleed) impacting tens of‑thk
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 8d930ba7e02527a8da8708c98d8d376e113ad641ea186d2106e88c9545eeda08
- Enrichment time
- 2026-06-23T07:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.