isc.sans.edu 7 Oct 2026, 02:00 UTC

Fake Invoice PDFs Deliver Legitimate ActionOne Remote Access Tool Attacks

Fake Invoice PDFs Deliver Legitimate ActionOne Remote Access Tool Attacks
CyberSIXT Evidence Panel Source marked as original reporting

A recent SANS ISC Stormcast notes another abuse of a legitimate remote management tool, this time ActionOne’s A1 Agent. The threat arrives via a malicious PDF—an ordinary looking fake invoice or Adobe update—that lures the target into opening a URL as the PDF is opened. The first stage is a Visual Basic script that ultimately pulls in the actual remote management software (the A1 Agent).

The broadcast emphasises the risk of relying on endpoint protection alone since such tools are legitimate software, and suggests monitoring for traffic that originates from unauthorised or unapproved remote-management utilities.

The discussion also touches on broader topical items. Fortinet’s FortiGate advisories around libHEIF vulnerabilities highlight ongoing issues in HEIF parsers that could enable remote code execution; organisations using HEIF libraries should stay current with vendor updates. SonicWall SMA‑1000 is flagged for a high‑severity (CVSS 10) server‑side request forgery, describable as an unauthenticated attacker abusing internal services exposed via a front end.

OpenSSH 10.6 is released with notes about higher‑than‑usual AI‑generated submissions, accelerating patch cadence, and a reminder that duplicate reports do not justify delaying fixes. Finally, the podcast mentions that on 11 October the DNS root zone key signing key will change, with guidance to check resolvers are prepared for the new key, complemented by a Cloudflare blog link.

View full article

Article by CyberSIXT