Itbrief.Au Attackers Exploit Trusted Tools in Cyber Campaigns
Article Content
- •BaoLoader accounted for 40.9% of tracked cyber incidents, primarily through drive-by compromises.
- •ClickFix social engineering technique was involved in over 44% of defense evasion activities.
- •CVE-2026-1731 in BeyondTrust software is actively exploited for initial and ongoing access.
ReliaQuest's analysis reveals a significant rise in cyberattacks utilizing trusted tools and user behavior manipulation from December to February. The report identifies BaoLoader as the leading malware, involved in 40.9% of incidents, primarily through drive-by compromises disguised as legitimate software. ClickFix, a social engineering tactic, was linked to over 44% of defense evasion incidents. The analysis indicates a shift from complex malware to exploiting familiar tools, especially during the US tax season when searches for financial software increased. Shai-Hulud, a new malware variant, ranked second at 27.3%, evolving into a threat targeting cloud credentials. Remote monitoring tools like ConnectWise ScreenConnect and BeyondTrust were also exploited, with BeyondTrust's CVE-2026-1731 being actively exploited shortly after its disclosure. This trend highlights the growing sophistication of cyber threats leveraging legitimate software.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-1731 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI-Discovered Vulnerabilities Surge, Increasing RCE Threats Google's Threat Intelligence Group (GTIG) reports that software vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August 2026, largely influenced by AI-assisted discovery. Notably, 50% of AI-discovered vulnerabilities enable remote code execution (RCE), compared to 26% of non-AI…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…