Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

2026-05-05T07:24:09Zeb6d00cd4738856c590518872e52d475ea799249915afd589294e991816a40d7
ABCDoorAppSheet-phishingCVE-2026-31431DEEP#DOOREtherRATGemini-CLILinux-LPEMOVEitPyTorch-LightningRCERMMSSO-abuseScreenConnectSimpleHelpTrellix-breachVENOMOUS#HELPERauthentication-bypasscPanel-exploitationcrypto-scam-takedowngo-modulesnpm-compromisephishingruby-gemssupply-chain-attackvishing

What happened

Multiple high-impact campaigns and vulnerabilities are reported: an active phishing campaign dubbed VENOMOUS#HELPER is using legitimate RMM tools (SimpleHelp, ScreenConnect) to gain persistent access across 80+ organizations; Progress released patches for MOVEit Automation including a critical authentication-bypass flaw; CISA added the Linux local privilege escalation CVE-2026-31431 (Copy Fail) to its KEV list amid active exploitation. Numerous supply-chain compromises and credential-stealing packages (PyTorch Lightning, SAP-related npm, poisoned Ruby gems/Go modules) and a CVSS 10 RCE fix in@

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
eb6d00cd4738856c590518872e52d475ea799249915afd589294e991816a40d7
Enrichment time
2026-05-05T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools · Baitaphish