- Engineer — Act: Three confirmed incidents show worm-like spread via ScreenConnect to newly connected hosts — if you run ScreenConnect, audit your relay configuration for unauthorized clients and review logs for unexpected new-host onboarding activity since the worm spreads automatically on connection.
- SOC/IR — Act: Hunt for VBScript execution chains spawned from ScreenConnect parent processes across your estate, and sweep RMM logs for abnormal new-client connection events; initial access spans tech-support scam lures, phishing MSIs, and at least one other vector, so assume diverse entry points.
- Leader — Plan: RMM tool abuse as a worm vector is a growing pattern — use this quarter to review governance of ScreenConnect and similar remote-access tools (access restrictions, audit logging, approved-relay allowlists) before an incident forces the conversation.