Cybersecuritynews Phishing Campaign Exploits LogMeIn Resolve and ScreenConnect Tools
Article Content
- •Threat actors are exploiting LogMeIn Resolve and ScreenConnect in phishing campaigns.
- •The campaign blends social engineering with information-stealing malware.
- •Most malicious activity was observed between October and November 2025.
Threat actors are leveraging the legitimate remote monitoring and management tools LogMeIn Resolve and ScreenConnect in a sophisticated phishing campaign. This multi-stage attack combines social engineering tactics with stealthy information-stealing malware. Sophos’ Managed Detection and Response (MDR) teams first detected this activity in April 2025, with a significant increase in malicious activity noted between October and November 2025. The campaign targets organizations primarily in the United States, aiming to bypass security defenses by using trusted software. Specific details regarding the number of affected organizations or systems have not been disclosed. The current status indicates ongoing exploitation of these tools in phishing attempts. Security professionals are advised to remain vigilant against such tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…