Arctic Wolf detected active exploitation of CVE-2026-1731 in self-hosted BeyondTrust Remote Support and Privileged Remote Access deployments. Attackers are deploying SimpleHelp RMM for persistence, creating domain admin accounts, performing Active Directory discovery, and using PSexec for lateral movement. Cloud customers were

3m read time From arcticwolf.com
Post cover image
Table of contents
Technical DetailsRecommendation

Sort: