INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Critical Remote Support Vulnerability Exploit Flaw Found

| 2026-02-09 13:07 CRITICAL HIGH
Executive Summary AI-generated
The Chinese cyberspies have also targeted the Committee on Foreign Investment in the United States, which reviews foreign investments for national security risks, and the Office of Foreign Assets Control, which administers U.S. sanctions programs. This is not an isolated incident as CISA added CVE-2024-12356 to its Known Exploited Vulnerabilities catalog on December 19 and ordered US government agencies to secure their networks within a week. BeyondTrust has secured all RS/PRA cloud systems by February 2, 2026, advising customers to patch their systems manually due to the vulnerability. This highlights the ongoing threat of state-sponsored hacking groups like Silk Typhoon, which have been linked to previous attacks on US companies and government agencies.
Technical Mitigations AI-generated
* Patch RS/PSA software to the latest version: Customers should upgrade their Remote Support (RS) and Privileged Remote Access (PRA) products to the latest versions, specifically Remote Support 25.3.2 or later and Privileged Remote Access 25.1.1 or later. * Implement secure authentication mechanisms: Organizations should ensure that all users have strong authentication credentials before allowing access to remote support tools, and consider implementing multi-factor authentication (MFA) for added security. * Monitor network traffic for suspicious activity: IT teams should regularly monitor network traffic for signs of unauthorized access attempts, and implement measures such as intrusion detection systems (IDS), firewalls, and antivirus software to detect and respond to potential threats. * Regularly update and patch operating systems and applications: Ensure that all operating systems, applications, and services are up-to-date with the latest security patches, including those related to remote code execution vulnerabilities like CVE-2026-1731. * Implement a secure incident response plan: Organizations should have a well-defined incident response plan in place to quickly respond to potential attacks, minimize damage, and contain the threat.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-12686CVE-2024-12686 CVE-2026-1731CVE-2026-1731 CVE-2024-12356CVE-2024-12356
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
June 2025
Attackers used a stolen API key to compromise 17 Remote Support SaaS instances after breaching BeyondTrust's systems.
tactic Remote Code Execution
tactic T1584.004 - Server
tactic T1221 - Template Injection
organisation CVE-2026
organisation Previous BeyondTrust
organisation BeyondTrust RS
organisation the Committee on Foreign Investment
organisation the Office of Foreign Assets Control (OFAC
organisation The U.S. Treasury Department
organisation API
organisation Treasury
organisation Remote Access
organisation Modern
organisation Tines
victims 20,000 customers
January 31, 2026
Threat actors exploited a critical Remote Access Security System (RASS) vulnerability in BeyondTrust's remote support software.
general_metric 11,000 instances
February 2, 2026
Threat actors exploited a remote support software vulnerability to gain unauthorized access and compromise systems.
tactic Exfiltration
infrastructure 25.3.2
infrastructure 25.1.1
February 6, 2026
Threat actors exploited a critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA).
tactic Remote Code Execution
organisation Privileged Remote Access
Feb 09, 2026
Threat actors exploited a previously unknown remote access vulnerability in BeyondTrust's remote support software to gain unauthorized access.
2026-02-09
BeyondTrust warned of a critical pre-authentication remote code execution vulnerability in its Remote Support and Privileged Remote Access products that could be exploited by unauthenticated attackers to execute arbitrary operating system commands.
organisation BeyondTrust
organisation Hacktron
organisation CVE
organisation CVE-2026
infrastructure 25.3.1
infrastructure 24.3.4
infrastructure 25.3.2
infrastructure 21.3
infrastructure 22.1
infrastructure 25.1.1
organisation PRA
organisation CVSS
organisation RCE
December 19
Threat actors exploited a remote support software vulnerability to gain unauthorized access.
industry Government
vulnerability CVE-2024-12356
attribution CISA
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
Tactical Metrics
Metrics
infrastructure
​25.3.1
Software Version
Metrics
infrastructure
​24.3.4
Software Version
Metrics
infrastructure
​25.3.2
Software Version
Metrics
infrastructure
​21.3
Software Version
Metrics
infrastructure
​22.1
Software Version
Metrics
infrastructure
​25.1.1
Software Version
Metrics
victims
20,000
Customers
Intelligence Sources