Critical

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

The Hacker News
Actively Exploited

Overview

Cybersecurity researchers have identified a worm-like attack that uses ConnectWise ScreenConnect to spread a malicious Visual Basic Script (VBScript) payload. This attack targets newly connected systems and has been linked to three different initial access methods: a tech-support scam using Quick Assist, a phishing campaign distributing an MSI installer, and a fake software update. The worm's ability to propagate itself makes it particularly concerning, as it can infect multiple systems once it gains access. This incident underscores the need for vigilance among users and organizations to protect against such multi-staged attacks, which can lead to further exploitation and data breaches.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: ConnectWise ScreenConnect, Windows systems
  • Action Required: Ensure that ConnectWise ScreenConnect is updated to the latest version and educate users on recognizing phishing attempts and tech-support scams.
  • Timeline: Newly disclosed

Original Article Summary

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake

Impact

ConnectWise ScreenConnect, Windows systems

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Ensure that ConnectWise ScreenConnect is updated to the latest version and educate users on recognizing phishing attempts and tech-support scams.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Phishing, Update, Malware.

Related Coverage

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

The Hacker News

This week, a new cybersecurity issue emerged where attackers circumvented email image blocking by using scannable QR codes made from text. This means that even if users have images turned off in their email settings, they can still be targeted by these codes, which can be a nuisance for those relying on this precaution. In a separate incident, a trusted software source was compromised, resulting in the distribution of malicious code that steals user credentials. Additionally, a security protocol meant for managing networks securely was exploited, leading to further vulnerabilities. These incidents highlight ongoing challenges in maintaining online security and the need for vigilance among users and organizations alike.

Sep 7, 2026

NCSC Warns Shadow AI Creates New Security Risks

Infosecurity Magazine

The UK's National Cyber Security Centre (NCSC) has issued a warning about the risks associated with unapproved artificial intelligence tools, often referred to as 'shadow AI.' These tools can potentially expose sensitive corporate data and introduce new security vulnerabilities. The NCSC emphasizes that employees using unauthorized AI applications may inadvertently compromise their organization's security, as these tools might not comply with established security protocols. Companies are urged to enforce strict policies regarding AI usage and to educate their employees about the potential dangers. With the rapid rise of AI technologies, ensuring that only approved tools are utilized is crucial for maintaining data security and protecting against data breaches.

Sep 7, 2026

Mathspace discloses data breach affecting over 1 million people

BleepingComputer

Mathspace, an online math learning platform, has reported a data breach that has compromised the information of over 1 million individuals, including students, staff, and parents. The breach occurred due to attackers accessing Mathspace's Metabase internal reporting system. The stolen data potentially includes sensitive personal information, which raises concerns about privacy and the security of educational platforms. This incident highlights the risks associated with online learning environments, especially as they store large amounts of personal data. Users and educational institutions need to be vigilant and consider enhancing their security measures to protect against similar attacks in the future.

Sep 7, 2026

N-able Releases Hotfix for Critical Remote Code Execution Vulnerability

Infosecurity Magazine

N-able has released a hotfix for a serious vulnerability identified as CVE-2026-86218, which has been rated as maximum severity by the company. This vulnerability allows remote code execution, meaning that attackers could potentially gain control of affected systems without physical access. Users of N-able's software are urged to apply the hotfix immediately to protect their systems from exploitation. The urgency of this update stems from the risk of attackers leveraging this vulnerability to compromise sensitive data and disrupt operations. Timely patching is crucial for organizations relying on N-able's products to maintain their cybersecurity posture.

Sep 7, 2026

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

SecurityWeek

A new set of proof-of-concept exploits has been revealed, targeting vulnerabilities in CrowdStrike, Nvidia, and Avast products. These zero-day exploits allow attackers to escalate privileges, potentially granting them system-level access on affected machines. This poses a significant risk as it could enable malicious actors to execute unauthorized commands and take control of systems. Organizations using these products need to be vigilant, as the ease of exploitation could lead to widespread attacks. It's crucial for users to remain informed about these vulnerabilities and take necessary precautions to secure their systems.

Sep 7, 2026

North Korean Hackers Deploy New Linux Espionage Toolkit

SecurityWeek

North Korean hackers have deployed a new espionage toolkit that embeds a backdoor in HAProxy, a widely used software for managing web traffic. This toolkit is specifically targeting automotive and media companies in South Korea, allowing the attackers to conduct long-term surveillance on these organizations. The use of HAProxy as a vector for infiltration raises concerns about the security of systems that rely on this software. As these sectors are critical to South Korea's economy, the implications of such attacks could be significant, potentially leading to data breaches and compromised operations. Organizations in these industries should be vigilant and assess their defenses against this emerging threat.

Sep 7, 2026