Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
2026-05-05T07:24:09Z•eb6d00cd4738856c590518872e52d475ea799249915afd589294e991816a40d7
ABCDoorAppSheet-phishingCVE-2026-31431DEEP#DOOREtherRATGemini-CLILinux-LPEMOVEitPyTorch-LightningRCERMMSSO-abuseScreenConnectSimpleHelpTrellix-breachVENOMOUS#HELPERauthentication-bypasscPanel-exploitationcrypto-scam-takedowngo-modulesnpm-compromisephishingruby-gemssupply-chain-attackvishing
What happened
Multiple high-impact campaigns and vulnerabilities are reported: an active phishing campaign dubbed VENOMOUS#HELPER is using legitimate RMM tools (SimpleHelp, ScreenConnect) to gain persistent access across 80+ organizations; Progress released patches for MOVEit Automation including a critical authentication-bypass flaw; CISA added the Linux local privilege escalation CVE-2026-31431 (Copy Fail) to its KEV list amid active exploitation. Numerous supply-chain compromises and credential-stealing packages (PyTorch Lightning, SAP-related npm, poisoned Ruby gems/Go modules) and a CVSS 10 RCE fix in@
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- eb6d00cd4738856c590518872e52d475ea799249915afd589294e991816a40d7
- Enrichment time
- 2026-05-05T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.