Ransomware scum disrupted utility services with SimpleHelp attacks
ID: 409d1509-227f-533d-9a0a-56e3fbdd9ff9
STIX ID: report--409d1509-227f-533d-9a0a-56e3fbdd9ff9
Feed Name: The Register (Security)
Threat Score
CISA warns that ransomware groups have been exploiting a path traversal flaw (CVE-2024-57727) in SimpleHelp RMM to compromise downstream customers — including a utility billing software provider — leading to data theft, encryption, and service disruptions; Play and DragonForce are reported as exploiting unpatched SimpleHelp instances since January 2025, and organizations are urged to search for indicators of compromise and apply the vendor patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
