logo

Hackers breach SmarterTools network using flaw in its own software

ID: d54db2cb-4abc-590b-976b-e209cdabf6ad

STIX ID: report--d54db2cb-4abc-590b-976b-e209cdabf6ad

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-02-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SmarterTools confirmed a January 29 intrusion after an unpatched SmarterMail VM was exploited via CVE-2026-23760, allowing attackers (attributed to the Warlock ransomware gang and linked to Chinese-affiliated Storm-2603) to reset admin passwords, move laterally across Windows systems using Active Directory, deploy Velociraptor and other tooling, and attempt ransomware encryption; endpoint security and backups prevented widespread data loss. Administrators are advised to upgrade SmarterMail to Build 9511 or later and remediate related flaws (including CVE-2026-24423).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.