CuraSec

tag: Remote-Access · 1 items

2026-09-02 · BleepingComputer · source ↗ #remote-access#phishing#endpoint
  • Engineer — Learn: No CVE or patch involved — attackers are abusing a legitimate admin tool’s functionality. Review whether Faronics Deploy is in your environment and whether its deployment permissions are appropriately scoped.
  • SOC/IR — Act: Hunt for unexpected ScreenConnect installations originating from Faronics Deploy processes; build detections for remote-management tool deployments not initiated by IT change management workflows.
  • Leader — Skip