LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

ZeroDay News ·

Source: Help Net Security

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative activity.

The use of RMM tools by malicious actors has seen a significant surge, increasing by 277% year-over-year in 2025. This approach is favored because it provides a readily available, off-the-shelf solution for maintaining control, bypassing the need for attackers to develop custom tools. Huntress places RMM abuse in the highest-frequency category of attack tactics it tracks, noting its proximity to more severe outcomes like ransomware deployment or data exfiltration.

In one specific instance, a phishing attempt disguised as a fake service agreement led to the installation of Tiflux, an RMM tool. Following this initial compromise, the attacker further deployed UltraVNC, Splashtop, and ScreenConnect on the same device, establishing multiple avenues for re-entry. Attackers are reportedly using artificial intelligence to craft convincing lures, such as fake document-share requests and service agreements, to facilitate these initial intrusions. Organizations are advised to maintain a clear list of approved RMM tools and implement monitoring for the presence of unauthorized RMM software.

Beyond RMM abuse, Huntress also highlighted a rise in identity-based threats. Mailbox manipulation, where attackers create inbox rules to hide vendor replies and then substitute fraudulent invoices to redirect payments, constituted 19% of identity-based threats in 2025 and 24.6% of identity threat signals in 2026.

Another significant identity threat is adversary-in-the-middle (AiTM) attacks, which accounted for 18.9% of identity-based threats in 2025. In AiTM attacks, an attacker intercepts the login process to a service like Microsoft 365, stealing the user's session token. This token allows the attacker to remain logged in without needing a password or triggering multi-factor authentication prompts for the duration of the session. To mitigate this, organizations should review session activity durations and implement policies requiring fresh logins from new devices or locations.

Device code phishing, though less frequent, is categorized as highly damaging. This tactic involves directing victims to a legitimate Microsoft device code login page through a fake workflow prompt. Once the victim enters the code, the attacker obtains an access token that can persist even after a password reset. Huntress reported a 1,380% increase in this tactic between July-December 2025 and January-April 2026, though specific volume figures were not provided. The EvilTokens phishing kit, for example, impacted 344 organizations across five countries in a mere 16 days.

Other notable threats include ClickFix, which was responsible for 53.2% of malware loader activity in 2025. Huntress also identified instances of AI platform abuse, such as FakeAgent, which leveraged a malicious Claude Artifact hosted on the legitimate claude.ai domain. This campaign targeted users seeking a Claude Desktop application, redirecting them to SectopRAT and affecting 29 organizations in two days. Six of the eleven tactics analyzed by Huntress, including AI platform abuse and deepfakes, are marked as being accelerated by AI.

ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.