ioc.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
INDICATORS OF COMPROMISE (IOC) InfoSec Community within the Fediverse. Newbies, experts, gurus - Everyone is Welcome! Instance is supposed to be fast and secure.

Administered by:

Server stats:

1.3K
active users

#SimpleHelp

2 posts1 participant0 posts today

Targeted attacks against MSP:s, NATO and Ukraine. Two stories from Sophos and Microsoft published today.

The MSP-attack involved abusing vulnerabilities in SimpleHelp chaining a number of vulnerabilities. A little bit of a more advanced attack IMHO.

Then you have the NATO and Ukraine attacks as detailed by Microsoft, involving password spraying and likely bought credentials from criminal ecosystems.

Funny. Ransomware attackers are more advanced than APTs 🙂

References:
news.sophos.com/en-us/2025/05/

microsoft.com/en-us/security/b

Sophos News · DragonForce actors target SimpleHelp vulnerabilities to attack MSP, customersRansomware actor exploited RMM to access multiple organizations; Sophos EDR blocked encryption on customer’s network

Security researchers reveal #activeexploitation against #SimpleHelp RMM vulnerabilities

The vulnerabilities are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, and when exploited, allows an attacker to gain admin privileges

Administrators are advised to patch ASAP

#cybersecurity #vulnerabilitymanagement

bleepingcomputer.com/news/secu

BleepingComputer · Hackers exploiting flaws in SimpleHelp RMM to breach networksBy Bill Toulas