{"id":626,"date":"2025-06-12T08:27:48","date_gmt":"2025-06-12T06:27:48","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=626"},"modified":"2025-06-13T08:28:15","modified_gmt":"2025-06-13T06:28:15","slug":"ransomware-scum-disrupted-utility-services-with-simplehelp-attacks","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/06\/12\/ransomware-scum-disrupted-utility-services-with-simplehelp-attacks\/","title":{"rendered":"Ransomware scum disrupted utility services with SimpleHelp attacks"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Ransomware criminals infected a utility billing software providers&#8217; customers, and in some cases disrupted services, after exploiting unpatched versions of SimpleHelp\u2019s remote monitoring and management (RMM) tool, according to a Thursday CISA alert.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;This incident is part of a broader trend of ransomware actors exploiting unpatched versions of SimpleHelp RMM since January 2025,&#8221; the security advisory&nbsp;<a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa25-163a\">warned<\/a>. &#8220;Ransomware actors likely exploited CVE-2024-57727 to access downstream customers&#8217; unpatched SimpleHelp RMM, resulting in service disruptions and double extortion incidents.&#8221;<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2025\/06\/12\/ransomware-scum-disrupted-utility-services-with-simplehelp-attacks\/\" target=\"_self\"><a href=\"https:\/\/www.theregister.com\/2025\/06\/12\/cisa_simplehelp_flaw_exploit_warning\/\">Ransomware disrupted utility services in SimpleHelp attacks \u2022 The Register<\/a><span class=\"screen-reader-text\">: Ransomware scum disrupted utility services with SimpleHelp attacks<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Ransomware criminals infected a utility billing software providers&#8217; customers, and in some cases disrupted services, after exploiting unpatched versions of SimpleHelp\u2019s remote monitoring and management (RMM) tool, according to a Thursday CISA alert. &#8220;This incident is part of a broader trend of ransomware actors exploiting unpatched versions of SimpleHelp RMM&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[40],"class_list":["post-626","post","type-post","status-publish","format-standard","hentry","category-ransomware","tag-40"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/626","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=626"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/626\/revisions"}],"predecessor-version":[{"id":627,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/626\/revisions\/627"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}