ConnectWise ScreenConnect is a tool tracked across 8 threat clusters and 19 intelligence report mentions on ThreatCluster. First observed January 13, 2026; most recent activity July 16, 2026.
ConnectWise ScreenConnect has been compromised by two critical vulnerabilities, CVE-2024-1708 and CVE-2024-1709, which allow attackers to bypass authentication and execute remote code. The vulnerabilities were disclosed…
The SeasonalInvite phishing campaign has been active since January 2026, targeting Windows and macOS users by tricking them into installing legitimate remote monitoring and management (RMM) software via fake eCards. The…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a…
Cybercriminals have launched three phishing campaigns utilizing Vercel's free hosting service to distribute malicious content. The attacks leverage familiar platforms like Zoom and ConnectWise ScreenConnect to send…
CERT-UA has reported a new wave of cyberattacks targeting Ukrainian government agencies and EU organizations, exploiting the Microsoft Office vulnerability CVE-2026-21509. Attackers are using malicious emails disguised…
Cybercriminals are exploiting remote monitoring and management (RMM) tools through weaponized PDF files to gain unauthorized access to victim machines. These attacks leverage the trusted nature of RMM software, such as…