Hackers breach SmarterTools network using flaw in its own software
ID: d54db2cb-4abc-590b-976b-e209cdabf6ad
STIX ID: report--d54db2cb-4abc-590b-976b-e209cdabf6ad
Feed Name: Bleeping Computer
SmarterTools confirmed a January 29 intrusion after an unpatched SmarterMail VM was exploited via CVE-2026-23760, allowing attackers (attributed to the Warlock ransomware gang and linked to Chinese-affiliated Storm-2603) to reset admin passwords, move laterally across Windows systems using Active Directory, deploy Velociraptor and other tooling, and attempt ransomware encryption; endpoint security and backups prevented widespread data loss. Administrators are advised to upgrade SmarterMail to Build 9511 or later and remediate related flaws (including CVE-2026-24423).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
