The news
Three security reports published at the end of September point at the same weak spot: remote-access software. TeamViewer told customers to patch five vulnerabilities, while Microsoft and the sandbox firm ANY.RUN separately described phishing campaigns that install legitimate remote monitoring and management (RMM) tools, the software IT teams use to control computers from afar, to keep a foothold on victims' machines.
According to BleepingComputer, TeamViewer's advisory covers its Full Client and Host software for Windows, Linux and macOS before version 15.82. The most serious flaw, CVE-2026-92370, is a bypass of remote session access controls that the advisory says could lead to remote code execution. The other four, including a path traversal and a heap buffer overflow, could let a local attacker run code or gain the highest system privileges. TeamViewer said it was not aware of public disclosure or active exploitation and "strongly recommends" updating as soon as possible.
Microsoft's security researchers, as reported by The Hacker News, described phishing emails carrying a digitally signed MSP360 RMM installer, version 2.5.0.67, disguised under names such as ZoomSetup_Installation, VIP_ECARD_INVITATION and a fake Adobe PDF reader. The files were hosted on attacker servers and on legitimate services including Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase. Once run, the installer asked for administrator rights, set up MSP360 for persistent access, then used PowerShell to quietly install ConnectWise ScreenConnect as a backup channel. Microsoft said it spotted the activity in July 2026 and did not attribute it to a known group.
ANY.RUN, also reported by The Hacker News, described a campaign it calls CSuite that follows two paths after a victim clicks a lure. One steals Microsoft 365 access through credential harvesting or device-code phishing, a trick that gets users to approve a sign-in code on a real Microsoft page. The other drops installers for ScreenConnect or Action1. In one case, ANY.RUN said, an Adobe-themed lure delivered a script that raised privileges and installed ScreenConnect.
ANY.RUN said 51% of 351 sandbox submissions tied to CSuite came from the United States and 18% from India, with technology, manufacturing, government and consulting among the most exposed sectors.
The numbers
- TeamViewer fixed version
- 15.82
- TeamViewer flaws patched
- 5
- CSuite sandbox submissions analyzed
- 351
- Share of CSuite submissions from the US
- 51%
Why CEOs should care
For CISOs, these reports describe attackers who no longer need custom malware to stay inside. A signed MSP360 or ScreenConnect agent looks like routine IT work to many security tools. The most direct defense is an allowlist: name the one or two remote-access tools your company approves, block installation of the rest, and alert on any new RMM agent, firewall rule or service that appears outside your change process.
For IT leaders, TeamViewer is often installed by individual staff or vendors rather than centrally. Find every copy, update to 15.82, and remove the ones nobody can justify. Ask your managed service providers which remote tools they use on your network and how their accounts are protected.
For executives and boards, the CSuite findings matter because a stolen Microsoft 365 session can lead to mailbox takeover and payment fraud, according to ANY.RUN. Ask whether staff are trained to treat unexpected meeting invites, software updates and PDF readers as possible lures, and whether finance teams verify payment changes by phone.
The bigger picture
Microsoft's researchers summed up the trend: attackers keep abusing legitimate remote administration software to blend into normal IT operations. Because the tools are real products with valid signatures, the distinction between help desk and intruder comes down to policy and inventory, not file reputation.
What’s next
TeamViewer users should confirm they are on 15.82. Security teams should search endpoints for unexpected MSP360, ScreenConnect and Action1 installations and for the RMM.Agent.exe services and UDP port 48678 firewall rule Microsoft described.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








