TechSkimm

Attackers use ScreenConnect for four-stage VBScript malware

Researchers have found that attackers are leveraging ConnectWise ScreenConnect to install and execute a sequence of malicious VBScript files on new hosts. The incidents, observed in August 2026, began through social engineering or phishing, resulting in rogue ScreenConnect clients repeatedly running a four-stage VBScript chain. These scripts profile the system, check for security tools, and attempt to download additional payloads. Multiple unrelated attacks have used this method.

Why it mattersScreenConnect is a widely used remote access tool. Its compromise for malware delivery could threaten organizations using it for legitimate remote support, increasing risk of unauthorized access and system infection.

Sources covering this

The Hacker NewsRogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts11:36 AMSecurityWeekHeadline onlyModified ScreenConnect Clients Used in Worm-Like Campaign11:45 AM

More in Cybersecurity

7 sources · 9h ago

OpenAI pledges $1 billion for AI cyber defense program

OpenAI has pledged $1 billion in credits to help organizations defending critical U.S. infrastructure—including water utilities, electric grids, local governments, banks, and nonprofits—access its AI-powered cybersecurity tools, training, and support. The "Daybreak for Frontline Defenders" initiative aims to help these sectors strengthen their defenses as AI-driven cyberattacks become more advanced. OpenAI says it will expand the program to partner countries in the coming weeks.

3 sources · 9h ago

Breeze Comet targets Brazilian financial firms with fraud

A group known as Breeze Comet has targeted Brazilian banks, retailers, and e-commerce companies through sophisticated attacks since early 2024, according to Google Cloud and Mandiant. The organization uses malware and voice phishing to access internal payment systems and carry out fraudulent transfers. Google states that Breeze Comet is also using generative AI to develop new malware and may expand operations to parts of Latin America and Africa.

3 sources · 10h ago

Microsoft detects mass phishing using hidden Unicode tags

Microsoft identified a large phishing campaign that uses hidden Unicode tag characters to disguise key words in emails, enabling attackers to evade spam filters and machine learning-based detection. Microsoft tracked this method, known as ASCII smuggling, in more than 2.3 million messages over two days. While invisible to recipients, these tags break up high-risk words like “credit” or “loan,” allowing them to slip past automated screening systems.

3 sources · 2h ago

N-able issues urgent patch for critical N-central flaw

N-able has released a fourth emergency hotfix for its N-central remote monitoring software, addressing a critical vulnerability that could allow remote code execution without authentication. The patch, released hours after the previous fix, affects all on-premises N-central builds before version 2026.3.1.14. N-able's notices are inconsistent on whether the flaw has been exploited: some communications say there are confirmed attacks, others say exploitation is unconfirmed.