Hackers are exploiting vulnerabilities in SimpleHelp RMM clients to create admin accounts, install backdoors and possibly prepare for ransomware attacks. The cyberattacks, which have been linked to possible Akira ransomware attacks, involved the offenders using the flaws to gain unauthorised access and extract system information. Cybersecurity firms Arctic Wolf and Field Effect have flagged the issue, with the latter confirming exploitation of the flaws in recent attacks.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,