Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

2026-05-04T19:24:17Zb9f6627b23fde1402efd5387df53368a9355dc5608a20105fb5038ff7bc10f86
ABCDoorAccountDumplingCVE-2026-31431DEEP#DOOREtherRATGo modulesKEVLinux LPEMOVEitPyPIRMMRuby gemsSSO-abuseScreenConnectSimpleHelpTrellixVENOMOUS#HELPERauthentication-bypasscPanelcredential-theftnpmphishingsource-code-breachsupply-chainvishing

What happened

A wave of high-impact campaigns and multiple actively exploited vulnerabilities were reported across diverse vectors: phishing using legitimate RMM tools (VENOMOUS#HELPER leveraging SimpleHelp/ScreenConnect) has hit 80+ organizations; Progress released emergency fixes for MOVEit Automation addressing a critical authentication bypass; CISA added the Linux local privilege escalation CVE-2026-31431 (Copy Fail) to its KEV list; and Google fixed a CVSS-10 RCE in the Gemini CLI. Concurrent supply-chain and credential-theft operations are widespread—compromised PyTorch Lightning releases, SAP-related

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b9f6627b23fde1402efd5387df53368a9355dc5608a20105fb5038ff7bc10f86
Enrichment time
2026-05-04T19:24:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.