BeyondTrust A.I CyberSecurity Scoring
BeyondTrust
Company Information
Website:http://www.beyondtrust.com
Employees number:1,743
Number of followers:102,624
NAICS:5112
Industry Type:Software Development
Homepage:beyondtrust.com
BeyondTrust Risk Score (AI oriented)
Between 650 and 699
BeyondTrustSoftware Development
Updated:
15/07/2026
15/07/2026
692/1000
Weak
B
BeyondTrust Global Score (TPRM)
xxxx
BeyondTrustSoftware Development
Score locked

BeyondTrustWeak
Current Score
692B (WEAK)
01000
5 incidents
-12.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
693
AUGUST 2026
694
JULY 2026
693
JUNE 2026
691
MAY 2026
739
APRIL 2026
738
MARCH 2026
737
FEBRUARY 2026
756
Cyber Attack
09 Feb 2026 • BeyondTrust
Apple: Beware of Apple Pay Phishing Attack that Aims to Steal Your Payment Details
Sophisticated Vishing Campaign Targets Apple Pay Users in Phishing Scam
736
CRITICAL-20
APP1770616335
Sophisticated Vishing Campaign Targets Apple Pay Users in Phishing Scam
A highly convincing phishing campaign is actively targeting Apple Pay users, employing deceptive emails and phone-based social engineering to steal financial and login credentials. The attack, analyzed by Malwarebytes, begins with a fraudulent email mimicking an official Apple receipt, complete with the company’s logo, a fabricated case ID, and a timestamp. The message warns of a blocked high-value purchase such as a 2025 MacBook Air and urges the recipient to call a provided support number if the alleged "appointment" to review the fraud is inconvenient.
Unlike traditional phishing schemes that rely on malicious links, this campaign uses vishing (voice phishing) to manipulate victims over the phone. When contacted, scammers posing as Apple’s fraud department follow a scripted conversation, initially verifying harmless details like partial phone numbers before escalating to requests for Apple ID two-factor authentication (2FA) codes. In real time, attackers use these codes to hijack accounts, gaining access to stored data, photos, and linked payment methods.
The scam’s effectiveness lies in its psychological tactics leveraging urgency, brand trust, and fabricated transaction details to bypass skepticism. Researchers emphasize that Apple never schedules fraud reviews via email or demands callbacks, and official communications always originate from verified Apple domains. Victims who fall for the scheme risk full account compromise, with attackers potentially draining linked credit cards or locking users out of their devices.
The campaign underscores the growing sophistication of social engineering attacks, where human manipulation not technical exploits remains the primary vector for financial theft.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
761
Vulnerability
02 Feb 2026 • BeyondTrust
BeyondTrust: BeyondTrust Remote Access Products 0-Day Vulnerability Allows Remote Code Execution
Critical Zero-Day Vulnerability in BeyondTrust Remote Access Platforms Exposes Enterprises to RCE Attacks
756
CRITICAL-5
BEY1770457908
Critical Zero-Day Vulnerability in BeyondTrust Remote Access Platforms Exposes Enterprises to RCE Attacks
BeyondTrust has disclosed a severe pre-authentication remote code execution (RCE) vulnerability, CVE-2026-1731, affecting its Remote Support (RS) and Privileged Remote Access (PRA) platforms. The flaw, classified as an OS command injection (CWE-78), allows unauthenticated attackers to execute arbitrary commands on vulnerable systems without requiring credentials or user interaction.
The vulnerability poses a high-risk threat to enterprise environments, as successful exploitation could lead to full system compromise, data exfiltration, service disruption, and lateral movement within networks. Given BeyondTrust’s widespread use in privileged access management, the impact extends across organizational infrastructures.
### Affected Versions & Patch Availability
- Remote Support (RS): Versions 25.3.1 and earlier are vulnerable.
- Privileged Remote Access (PRA): Versions 24.3.4 and prior are affected.
BeyondTrust deployed automatic patches for SaaS customers on February 2, 2026, fully remediating the issue. However, self-hosted customers must manually apply fixes:
- Remote Support: Patch BT26-02-RS (or upgrade to 25.3.2+).
- Privileged Remote Access: Patch BT26-02-PRA (or upgrade to 25.1.1+).
- Legacy systems (RS <21.3 or PRA <22.1) must first upgrade to a supported version before patching.
### Discovery & Disclosure
The vulnerability was identified by Harsh Jaiswal and the Hacktron AI team using AI-driven variant analysis. BeyondTrust praised their responsible disclosure, allowing the company to develop and deploy patches before public exploitation occurred. No active attacks have been reported at this time.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
761
DECEMBER 2025
761
NOVEMBER 2025
761
OCTOBER 2025
760
JUNE 2025
762
Vulnerability
16 Jun 2025 • BeyondTrust
BeyondTrust
Remote Code Execution Vulnerability in BeyondTrust's Remote Support and Privileged Remote Access
760
CRITICAL-2
BEY602061725
A high-severity remote code execution vulnerability has been identified in BeyondTrust’s Remote Support and Privileged Remote Access platforms. The vulnerability, tracked as CVE-2025-5309, allows attackers to execute arbitrary code on affected systems. The flaw stems from a Server-Side Template Injection (SSTI) issue, which affects the chat feature within both platforms. The CVSSv4 score of 8.6 indicates the vulnerability can be exploited over the network with low complexity and requires no privileges, though user interaction is necessary. The underlying issue occurs because the affected systems fail to properly escape user input intended for the template engine, creating an opportunity for malicious template injection. Organizations running affected versions are at risk of having their systems compromised through the chat functionality.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2025
762
Breach
12 Jun 2025 • BeyondTrust
LastPass, BeyondTrust, Klue, HackerOne, Jamf, Recorded Future, Snyk, Huntress and Tanium: Klue Data Breach 2026: 200 Firms Hit via Old Credential
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
702
CRITICAL-60
JAMHUNSNYRECHACLASTANKLUBEY1784126732
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
In June 2025, a dormant credential issued by competitive-intelligence platform Klue in 2022 became the entry point for a breach affecting nearly 200 companies, including prominent cybersecurity vendors. The attack, claimed by the extortion group Icarus, exploited an unmonitored OAuth token to access Salesforce environments, underscoring the risks of neglected third-party integrations.
### What Happened?
On June 12, 2025, attackers used a compromised legacy credential originally created for a "limited pilot" to infiltrate Klue’s systems. The credential, left active for four years, granted access to OAuth tokens that Klue used to pull data from connected Salesforce instances. Once inside, the threat actors automated data exfiltration from 195–200 companies, including LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, and Huntress.
Klue publicly disclosed the breach on June 15, 2025, confirming data theft from an unspecified number of customers. By late June, affected firms began acknowledging the incident, with LastPass and BeyondTrust clarifying that only business contact and CRM data not core product systems were exposed.
### How the Attack Unfolded
The breach required no zero-day exploits or sophisticated malware just an overlooked credential. The attackers leveraged Klue’s OAuth tokens to access Salesforce environments en masse, demonstrating the dangers of fourth-party risk: a vendor’s vendor (Klue) becoming the weak link in a supply chain.
### Key Victims & Impact
While Klue serves sales and marketing teams, its customer base included security vendors, amplifying the breach’s irony. Confirmed victims span:
- Password management (LastPass)
- Privileged access (BeyondTrust)
- Endpoint security (Tanium, Jamf)
- Threat intelligence (Recorded Future)
- Bug bounty coordination (HackerOne)
- Application security (Snyk)
Huntress reported receiving a ransom note from the attackers via a compromised Australian email address, highlighting the group’s reliance on reused infrastructure.
### Broader Context: A Year of Supply Chain Attacks
The Klue breach coincided with a separate 2026 supply chain campaign targeting open-source security tools, including Trivy, Bitwarden, and Checkmarx. While unrelated, both incidents reflect a trend: attackers increasingly compromise trusted platforms to bypass direct defenses.
### Regulatory & Industry Reactions
- Cyber insurers are tightening scrutiny of third-party integrations, particularly OAuth token hygiene.
- Security vendors on the victim list face heightened procurement questions from enterprise buyers.
- Regulators are paying closer attention to software supply chain risks, though the Klue breach limited to business data may not trigger major notifications.
### Lessons from the Breach
The incident mirrors the 2025 Salesloft Drift breach, where stolen OAuth tokens compromised 700+ Salesforce environments. Both cases reveal a critical gap: point-in-time vendor assessments fail to catch dormant credentials. Mitigation requires:
- Automated expiration for pilot credentials.
- Minimum-scoped OAuth grants (avoiding broad CRM access).
- Recurring token audits to identify stale integrations.
As of June 2026, only ~15 of the estimated 200 affected firms have publicly confirmed exposure, with more expected to disclose as investigations continue. The breach serves as a stark reminder that identity and credential management not just perimeter defenses are central to modern cybersecurity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2025
762
Vulnerability
01 Feb 2025 • BeyondTrust
Fortinet: CISA Warns of Medusa Ransomware-as-a-Service Attacks Over 300 Organizations
Medusa Ransomware Targets Critical Infrastructure in Escalating RaaS Campaign
760
CRITICAL-2
FOR1787120638
Medusa Ransomware Targets Critical Infrastructure in Escalating RaaS Campaign
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, and Multi-State Information Sharing and Analysis Center (MS-ISAC) have issued a joint advisory (AA25-071A) warning of ongoing Medusa ransomware attacks against critical infrastructure sectors. As of February 2025, the group has compromised over 300 organizations, with confirmed victims spanning healthcare, education, legal services, insurance, technology, and manufacturing.
First detected in June 2021, Medusa initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) model. Core developers now recruit affiliates while retaining control over ransom negotiations. The group employs a double-extortion tactic, stealing data before encrypting systems and threatening to leak or sell it via a Tor-based site if demands aren’t met. Victims are given 48 hours to respond via Tor chat or the Tox messaging platform, with an option to pay $10,000 in cryptocurrency to delay data leaks by one day.
Medusa’s operations rely heavily on initial access brokers, who are recruited through criminal forums and paid between $100 and $1 million for network access. Phishing and exploitation of known vulnerabilities such as ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788) are primary entry points. Once inside, attackers use living-off-the-land techniques, leveraging PowerShell, cmd.exe, Windows Management Instrumentation, and legitimate tools like AnyDesk, Atera, and ConnectWise for lateral movement. Mimikatz is used to extract credentials, while Rclone facilitates data exfiltration.
The ransomware encryptor, typically named gaze.exe, is deployed via PsExec, PDQ Deploy, or BigFix. Before encryption, it disables security tools, terminates critical services, and deletes volume shadow copies. Files are encrypted with AES-256 and appended with the .medusa extension. In some cases, attackers also target virtual machines to maximize disruption.
Federal agencies recommend immediate patching of internet-facing systems, network segmentation, and monitoring for suspicious activity, including unauthorized use of remote management tools, abnormal PowerShell commands, and attempts to disable endpoint protection. Indicators of compromise (IOCs) include multiple IP addresses and domains linked to command-and-control infrastructure, exfiltration, and backdoor access.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for BeyondTrust ??
What was BeyondTrust's A.I Rankiteo Cyber Score in August 2026 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in July 2026 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in June 2026 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in May 2026 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in April 2026 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in March 2026 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in February 2026 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in January 2026 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in December 2025 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in November 2025 ??
What was BeyondTrust's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on BeyondTrust's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with BeyondTrust ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view BeyondTrust's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?