Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: + –
5 minutes reading time (1040 words)

Remote Access Is This Week's Battleground: Here's What Your Business Needs to Know

Two fresh warnings, a SANS-flagged wave of attacks abusing legitimate remote-support software and a newly exploited Citrix NetScaler zero-day with a federal patch deadline this week, both target the exact remote-access tools SMBs and their IT providers rely on every day.
If you take away one thing from this week's security news, make it this: attackers aren't just breaking down the front door anymore, they're walking in through the same remote-access tools your IT team uses to help you.

Two separate warnings surfaced in the last several days, and together they paint a clear picture of where attackers are focusing right now.


Warning #1: Attackers Are Weaponizing Remote-Support Software

On October 1, 2026, the SANS Internet Storm Center, the threat-intelligence arm of the SANS Institute, one of the most trusted names in cybersecurity, published a diary entry from handler Xavier Mertens titled "ScreenConnect Client (Ab)used by Attackers." It documents attackers distributing legitimate remote-access software through phishing emails to gain hands-on-keyboard access to victim networks.

ScreenConnect (made by ConnectWise) is one of the most widely deployed remote monitoring and management (RMM) tools in the IT services industry, the same category of software many managed service providers (MSPs) use to remotely support client machines, push patches, and troubleshoot issues. That's precisely what makes it attractive to criminals: a tool built to give trusted technicians broad, low-friction access to a network is just as effective in the wrong hands, and because it's "legitimate" software signed by a known vendor, it tends to slip past antivirus tools and raise fewer red flags than custom malware.

The playbook is simple and has been escalating industry-wide over the past year: attackers send a phishing email with a fake invite link or "support session" URL, the victim clicks and installs what looks like a routine remote-access client, and the attacker now has a persistent foothold installed as a Windows service, capable of file transfer, and often indistinguishable from a legitimate help-desk session until it's too late.

Why it matters for your business: If your company works with an MSP (and most SMBs do, whether for help-desk support, patching, or network monitoring), you are trusting that provider's remote-access tooling with the keys to your network. That trust is well placed with a reputable provider that locks down its RMM platform, but it also means your security posture is only as strong as your vendor's. This is exactly the kind of third-party and vendor risk that compliance frameworks like the NIST Cybersecurity Framework (the Identify and Protect functions, specifically around supply-chain and access management) and CIS Controls (Control 6: Access Control Management, and Control 15: Service Provider Management) are designed to address — and it's a question worth asking your provider directly this week: how do you lock down and monitor the remote-access software you run on our network?

Help desk remote support session

Warning #2: A Citrix NetScaler Zero-Day With a Ticking Clock

The second warning is more urgent and has a hard deadline. On October 4, 2026, Citrix disclosed CVE-2026-88779, a memory buffer overflow vulnerability (CVSS 8.7) affecting NetScaler ADC and NetScaler Gateway appliances configured with SAML authentication. NetScaler devices are widely used as the front door for secure remote access and VPN connectivity many SMBs and the MSPs who manage their infrastructure rely on them for exactly that purpose.

What makes this urgent: researchers have confirmed active exploitation. Attackers are crafting malicious SAML authentication requests containing shell commands designed to download and run malware on unpatched appliances. The flaw was initially described as a denial-of-service issue, but evidence now suggests it may also enable remote code execution meaning a successful attack could hand an outsider control of the very appliance meant to secure remote access.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to mitigate it by October 7, 2026. While that mandate technically applies to federal systems, CISA's KEV deadlines are widely treated across the industry and by cyber insurers and auditors — as the baseline for "known, exploited, and you should have already patched this." Organizations running affected NetScaler versions should upgrade immediately to patched builds (14.1-73.41 or 13.1-64.28), review SAML authentication configurations, and apply Citrix's Global Deny Lists to block known malicious IP addresses.

Why it matters for your business: This is the latest in a string of NetScaler vulnerabilities disclosed throughout 2026, and the pattern is consistent — public disclosure is quickly followed by active, opportunistic exploitation of anyone slow to patch. For regulated organizations, timely patching of internet-facing remote-access infrastructure isn't optional. It's a direct requirement under the HIPAA Security Rule's risk management provisions, CMMC's Access Control and System and Information Integrity domains, and NIST CSF's Protect function and it's increasingly a question cyber insurers ask before renewing a policy.

Secure Cloud Gateway

The Common Thread 

Taken together, these two stories point to the same underlying lesson: the infrastructure built to make remote work and remote support convenient is now squarely in attackers' crosshairs. That includes the VPN gateways and SSO systems that let your team log in from home, and the RMM platforms your IT provider uses to keep your systems running. Both are "trusted by default" in most environments, which is exactly why they're valuable targets.

For an SMB without a dedicated security team, the practical response isn't complicated, but it does require follow-through:

  • Confirm patch status on any internet-facing remote-access appliances, VPN gateways, SSO portals, and remote-access concentrators, and treat CISA KEV deadlines as your patching SLA even if you're not a federal contractor.
  • Ask your MSP or IT provider directly what controls, monitoring, and multi-factor authentication protect the remote-access tools they use to manage your network, and whether that configuration is documented as part of your vendor risk assessment.
  • If you operate under a compliance framework, HIPAA, FERPA, CMMC, or a NIST CSF or CIS Controls-based program, treat remote-access tooling (both yours and your vendors') as in-scope for your next risk assessment, not an afterthought.

None of this requires a massive budget. It requires asking the right questions this week, while these two warnings are fresh, rather than after an incident forces the conversation.

Your Team's "Vibe Coded" App Might Already Be Leak...
Cybersecurity Threat Advisory: TrustSink Turns Mic...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024