logo

Ransomware scum disrupted utility services with SimpleHelp attacks

ID: 409d1509-227f-533d-9a0a-56e3fbdd9ff9

STIX ID: report--409d1509-227f-533d-9a0a-56e3fbdd9ff9

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2025-06-12

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

CISA warns that ransomware groups have been exploiting a path traversal flaw (CVE-2024-57727) in SimpleHelp RMM to compromise downstream customers — including a utility billing software provider — leading to data theft, encryption, and service disruptions; Play and DragonForce are reported as exploiting unpatched SimpleHelp instances since January 2025, and organizations are urged to search for indicators of compromise and apply the vendor patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.