RMM tools currently being distributed through phishing attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able)
In January 2026, the AhnLab SEcurity intelligence Center (ASEC) reported on attack cases that distributed RMM (Remote Monitoring and Management) tools through video files or attachments in phishing emails. [1] [2] In these attack cases, tools such as Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps were exploited. RMM (Remote Monitoring and
Detection of Recent RMM Distribution Cases Using AhnLab EDR
AhnLab SEcurity intelligence Center (ASEC) has recently observed an increase in attack cases exploiting Remote Monitoring and Management (RMM) tools. Whereas attackers previously exploited remote control tools during the process of seizing control after initial penetration, they now increasingly leverage RMM tools even during the initial distribution phase across diverse
ConnectWise ScreenConnect Security Update Advisory (CVE-2025-14265)
Overview We have released a security update to address a vulnerability in ConnectWise ScreenConnect. Users of affected products are advised to update to the latest version. Affected Products CVE-2025-14265 ConnectWise ScreenConnect version: 25.less than 8 Resolved Vulnerabilities Integrity Unvalidated Code Download Vulnerability in

