Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
2026-05-04T19:24:17Z•b9f6627b23fde1402efd5387df53368a9355dc5608a20105fb5038ff7bc10f86
ABCDoorAccountDumplingCVE-2026-31431DEEP#DOOREtherRATGo modulesKEVLinux LPEMOVEitPyPIRMMRuby gemsSSO-abuseScreenConnectSimpleHelpTrellixVENOMOUS#HELPERauthentication-bypasscPanelcredential-theftnpmphishingsource-code-breachsupply-chainvishing
What happened
A wave of high-impact campaigns and multiple actively exploited vulnerabilities were reported across diverse vectors: phishing using legitimate RMM tools (VENOMOUS#HELPER leveraging SimpleHelp/ScreenConnect) has hit 80+ organizations; Progress released emergency fixes for MOVEit Automation addressing a critical authentication bypass; CISA added the Linux local privilege escalation CVE-2026-31431 (Copy Fail) to its KEV list; and Google fixed a CVSS-10 RCE in the Gemini CLI. Concurrent supply-chain and credential-theft operations are widespread—compromised PyTorch Lightning releases, SAP-related
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b9f6627b23fde1402efd5387df53368a9355dc5608a20105fb5038ff7bc10f86
- Enrichment time
- 2026-05-04T19:24:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.