Ransomware Gang Exploits SimpleHelp RMM to Compromise Utility Billing Firm
ID: 9ce87f75-d9ff-5512-b80f-222169401a65
STIX ID: report--9ce87f75-d9ff-5512-b80f-222169401a65
Feed Name: Infosecurity Magazine (News)
Ransomware actors have been exploiting multiple SimpleHelp RMM vulnerabilities (including CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726) to access downstream customers and deploy DragonForce ransomware in double-extortion attacks; CISA has added the flaw to its KEV catalog and issued mitigation guidance urging vendors, downstream customers, and end users to identify affected instances, isolate or stop vulnerable servers, patch immediately, and conduct threat hunting for indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
