Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

2026-05-05T01:24:10Za874470cf9ca7550e3b993ad4a812dcc11aac37ae751125263feb960a9222571
ABCDoor malware (phishing)CISA KEVCVE-2026-31431CVSS 10Copy FailGemini CLIGo modulesLinux LPEMOVEit AutomationPyPIRCERMMRuby gemsScreenConnectSilver FoxSimpleHelpTreillix (source code breach)VENOMOUS#HELPERauthentication bypasscredential theftnpmphishingsupply chainsupply-chain compromisevulnerability

What happened

A broad set of active threats and high-impact disclosures: an ongoing phishing campaign (VENOMOUS#HELPER) is using legitimate RMM tools (SimpleHelp, ScreenConnect) to establish persistent access across 80+ organizations; Progress released patches for MOVEit Automation to fix a critical authentication-bypass bug; CISA added an actively exploited Linux local privilege escalation (CVE-2026-31431, aka "Copy Fail") to its KEV list; Google patched a CVSS-10 RCE in the Gemini CLI; multiple supply-chain compromises and malicious package pushes were observed (PyTorch Lightning, SAP-related npm packages

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a874470cf9ca7550e3b993ad4a812dcc11aac37ae751125263feb960a9222571
Enrichment time
2026-05-05T01:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.