Unpatched SimpleHelp Vulnerabilities Continue to be Exploited by DragonForce
ID: 0f3d409c-6c1d-5cca-9ba1-72279f8c98cf
STIX ID: report--0f3d409c-6c1d-5cca-9ba1-72279f8c98cf
Feed Name: Halcyon Blog
Threat Score
CISA warns that ransomware actors have been exploiting unpatched SimpleHelp RMM (version 5.5.7 and earlier) via known vulnerabilities (including CVE-2024-57727) since January 2025, enabling downstream intrusions and double-extortion attacks; organizations are urged to identify affected instances, apply updates or mitigations, and hunt for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
