<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Remote-Access on CuraSec</title><link>https://curasec.metacog.co.kr/tags/remote-access/</link><description>Recent content in Remote-Access on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/remote-access/index.xml" rel="self" type="application/rss+xml"/><item><title>Hackers abuse Faronics Deploy to silently install ScreenConnect RAT</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-hackers-abuse-faronics-deploy-admin-tool-to-install-screenco/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-hackers-abuse-faronics-deploy-admin-tool-to-install-screenco/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No CVE or patch involved — attackers are abusing a legitimate admin tool&amp;rsquo;s functionality. Review whether Faronics Deploy is in your environment and whether its deployment permissions are appropriately scoped.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Hunt for unexpected ScreenConnect installations originating from Faronics Deploy processes; build detections for remote-management tool deployments not initiated by IT change management workflows.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>