Microsoft Alerts on Malware Abuse of HPE Operations Agent
Article Content
- •Attackers used the HPE Operations Agent to infiltrate networks without traditional malware.
- •Access was gained through a compromised third-party IT services provider.
- •No vulnerabilities in HPE OA were exploited, complicating detection efforts.
Microsoft has reported a stealthy intrusion campaign where attackers exploited the HPE Operations Agent, a trusted enterprise tool, to infiltrate networks without using traditional malware. The attackers gained access through a compromised third-party IT services provider and moved laterally within the victim's environment using legitimate software already in place. No vulnerabilities in the HPE Operations Agent were exploited, making detection difficult. The scope of the impact remains unclear, but the use of trusted tools indicates a significant shift in attack methodologies. Organizations are advised to review their security postures and monitor for unusual activity involving trusted applications. This incident highlights the evolving tactics of cyber adversaries who leverage existing trust relationships to evade detection.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track HPE in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…