Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
2026-05-05T01:24:10Z•a874470cf9ca7550e3b993ad4a812dcc11aac37ae751125263feb960a9222571
ABCDoor malware (phishing)CISA KEVCVE-2026-31431CVSS 10Copy FailGemini CLIGo modulesLinux LPEMOVEit AutomationPyPIRCERMMRuby gemsScreenConnectSilver FoxSimpleHelpTreillix (source code breach)VENOMOUS#HELPERauthentication bypasscredential theftnpmphishingsupply chainsupply-chain compromisevulnerability
What happened
A broad set of active threats and high-impact disclosures: an ongoing phishing campaign (VENOMOUS#HELPER) is using legitimate RMM tools (SimpleHelp, ScreenConnect) to establish persistent access across 80+ organizations; Progress released patches for MOVEit Automation to fix a critical authentication-bypass bug; CISA added an actively exploited Linux local privilege escalation (CVE-2026-31431, aka "Copy Fail") to its KEV list; Google patched a CVSS-10 RCE in the Gemini CLI; multiple supply-chain compromises and malicious package pushes were observed (PyTorch Lightning, SAP-related npm packages
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- a874470cf9ca7550e3b993ad4a812dcc11aac37ae751125263feb960a9222571
- Enrichment time
- 2026-05-05T01:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.