WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

2026-06-23T07:24:11Z8d930ba7e02527a8da8708c98d8d376e113ad641ea186d2106e88c9545eeda08
ai-securityarystingerautojackbotnetcastlestealerdifytapfortibleedfortigategravity-smtpkluemalwaremanageengine-rmmnginxoauth-token-abuseoxloaderphishingransomwareremote-code-executionsquidbleedsupply-chainusbliter8vbscriptvulnerability-disclosurewhatsappwordpress

What happened

A broad set of active threats and high-impact vulnerabilities reported: a WhatsApp VBScript campaign distributing malicious VBS payloads that install legitimate ManageEngine RMM for remote access; multiple supply-chain and backdoor compromises (ShapedPlugin WordPress Pro plugins, poisoned plugin/update channels); disclosure of multi-tenant data‑exposure flaws in Dify (DifyTap); a long‑standing Squid proxy heap over‑read (Squidbleed) leaking cleartext HTTP; a new OXLOADER loader delivering CastleStealer via malicious Google Ads; widespread FortiGate compromise (FortiBleed) impacting tens of‑thk

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
8d930ba7e02527a8da8708c98d8d376e113ad641ea186d2106e88c9545eeda08
Enrichment time
2026-06-23T07:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.