OPERATION SILENTCANVAS: JPEG BASED MULTISTAGE POWERSHELL INTRUSION
Reported 10 May 2026 by otx · Severity: medium
A sophisticated multi-stage intrusion campaign was identified leveraging a weaponized PowerShell payload disguised as a JPEG image file (sysupdate.jpeg) to deploy a trojanized ConnectWise ScreenConnect instance for covert remote access. The attack likely originates through social