216.73.216.36

Uptick in Bomgar RMM Exploitation

· Published 17/04/2026 23:18 · Modified 20/04/2026 10:52

Export JSON

Essential information

Published
17/04/2026 23:18
Modified
20/04/2026 10:52
Tags
2026-04-17 CVE-2026-1731 anydesk atera bomgar byovd lockbit msp targeting poisonkiller ransomware remote access tools rmm exploitation screenconnect simplehelp
Related entities
1 vulnerabilities (cve), 5 observables, 18 techniques (mitre), 6 malware, 2 others

Description

Since early April 2026, security researchers have observed a significant increase in attacks targeting remote monitoring and management instances, exploiting , a critical vulnerability disclosed in February. Threat actors have compromised RMM to target downstream customers of MSPs and other service providers, affecting over 78 businesses in one incident alone. Attackers deploy , create privileged administrator accounts for persistence, install additional like and , and conduct domain reconnaissance. Some incidents involved attempts to disable security tools using techniques. The attacks primarily target organizations running outdated versions vulnerable to remote code execution, with compromised instances belonging to dental software companies and MSPs enabling widespread impact across their customer bases.

External references