Skip to content
tag — rmm

grep -rl "rmm" ./articles

#rmm

3 articles

The rogue ScreenConnect clients infect the hosts that connect to them

2026-09-08Security

Huntress found ScreenConnect clients that write a four-stage VBScript chain onto machines as they connect, profile each host, and then request a different payload depending on how much RAM it has and which EDR is installed. There is no code execution vulnerability to patch — it abuses file transfer, and ConnectWise says the fix is to turn the permission off.

N-able's two documents disagreed about exploitation. CISA has settled it

2026-09-07Security

CVE-2026-86218 is a CVSS 10.0 pre-authentication RCE in N-central, patched in the fourth hotfix in five weeks. For two days the vendor's release notes and its incident notice said opposite things about whether it was being exploited. CISA added it to the KEV catalogue on 8 September with a three-day federal deadline.