Misconfigured Server Exposes Three Evilginx Phishing Operations Targeting Microsoft 365
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing…
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing…
An unknown threat actor is exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp (CVSS 10.0), to deliver two new malware families:…
SimpleHelp Authentication Bypass Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on…
SimpleHelp is an RMM software affected by CVE-2026-48558, a critical authentication bypass vulnerability exploited to deploy malware.
Cybersecurity researchers have charted the evolution of INC from a nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups…
A vulnerability in SimpleHelp used by INC ransomware for initial access.
SimpleHelp is a remote support tool that was found running on the same server as the Evilginx proxy, used by the operator…
SimpleHelp Path Traversal Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the…
SimpleHelp Missing Authorization Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the…