Skip to content
Threat Feed

Vendor

MeshCentral

8 briefs RSS
low advisory

Detection of RMM Software Deployment via Internet-Originated MSI Files

This detection identifies the download and execution of Windows Installer (MSI) packages from the internet that result in the installation of remote monitoring and management (RMM) software used for persistent system access.

Acronis Cyber Protect Connect +43 defense-evasion command-and-control windows rmm
1t
high advisory

Stored XSS Vulnerabilities in MeshCentral via MeshAgent Data Fields

MeshCentral versions prior to 1.1.60 are vulnerable to stored cross-site scripting (XSS) due to insufficient sanitization of data fields sent from MeshAgents, allowing attackers to execute arbitrary JavaScript in administrative browser sessions.

MeshCentral
1t 1i
high advisory

MeshCentral WebSocket Hijacking Vulnerability

CVE-2026-66420 is a high-severity vulnerability in MeshCentral 1.1.21 allowing unauthenticated attackers to hijack administrator sessions via a cross-site WebSocket hijacking protection bypass.

MeshCentral
1c
medium advisory

Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes

This brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.

01com +151 windows command-and-control endpoint rmm remote-access
1r 193i
medium advisory

Suspicious Activity: Multiple Remote Management Tool Vendors on Same Host

This brief describes a behavioral detection for Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tools from different vendors are observed starting processes within an eight-minute window, indicating potential compromise, shadow IT, or attacker staging of redundant access.

Acronis Cyber Protect Connect +49 command-and-control remote-access-software rmm windows behavioral-detection
1t
medium advisory

Suspicious DNS Queries to RMM Domains from Non-Browser Processes

Detection of DNS queries to remote monitoring and management (RMM) domains from non-browser processes indicating potential misuse of legitimate remote access tools for command and control.

Elastic Endpoint +1 command-and-control remote-access windows
2r
medium advisory

Multiple Remote Management Tool Vendors on Same Host

This rule identifies Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tool vendors are observed starting processes within the same eight-minute window, potentially indicating compromise, shadow IT, or attacker staging of redundant access.

AeroAdmin +60 remote-access-tool command-and-control rmm windows
2r
medium advisory

Multiple Remote Management Tool Vendors on Same Host

This detection identifies a Windows host where two or more distinct remote monitoring and management (RMM) or remote-access tool vendors are observed starting processes within the same eight-minute window, potentially indicating compromise, shadow IT, or attacker staging of redundant access.

AeroAdmin +55 command-and-control rmm windows threat-detection
3r