September 15, 2026
- ScreenConnect exploitation is now documented as worm-like. Huntress first saw attacks on August 20 in which social-engineered, modified clients automatically pushed scripts into newly connected sessions, SecurityWeek reports. CVE-2026-84869 affects clients before 26.6.5, not servers; ConnectWise says operators must reinstall host clients and update access agents after upgrading. (earlier coverage) · Exploitation & Vulnerability Research
in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents