Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
BeyondTrust

BeyondTrust Vendor Cyber Rating & Cyber Score

beyondtrust.com

BeyondTrust is the global cybersecurity leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders. BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.


BeyondTrust A.I CyberSecurity Scoring

BeyondTrust
Company Information
Website:http://www.beyondtrust.com
Employees number:1,743
Number of followers:102,624
NAICS:5112
Industry Type:Software Development
Homepage:beyondtrust.com
BeyondTrust Risk Score (AI oriented)
Between 650 and 699
logo
BeyondTrustSoftware Development
Updated:
15/07/2026
692/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
BeyondTrust Global Score (TPRM)
xxxx
logo
BeyondTrustSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

BeyondTrust
BeyondTrustWeak
Current Score
692B (WEAK)
01000
5 incidents
-12.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
693Before Incident
AUGUST 2026
694Before Incident
JULY 2026
693Before Incident
JUNE 2026
691Before Incident
MAY 2026
739Before Incident
APRIL 2026
738Before Incident
MARCH 2026
737Before Incident
FEBRUARY 2026
756Before Incident
Cyber Attack
09 Feb 2026BeyondTrust
Apple: Beware of Apple Pay Phishing Attack that Aims to Steal Your Payment Details

Sophisticated Vishing Campaign Targets Apple Pay Users in Phishing Scam

736After Incident
CRITICAL-20
APP1770616335
Sophisticated Vishing Campaign Targets Apple Pay Users in Phishing Scam A highly convincing phishing campaign is actively targeting Apple Pay users, employing deceptive emails and phone-based social engineering to steal financial and login credentials. The attack, analyzed by Malwarebytes, begins with a fraudulent email mimicking an official Apple receipt, complete with the company’s logo, a fabricated case ID, and a timestamp. The message warns of a blocked high-value purchase such as a 2025 MacBook Air and urges the recipient to call a provided support number if the alleged "appointment" to review the fraud is inconvenient. Unlike traditional phishing schemes that rely on malicious links, this campaign uses vishing (voice phishing) to manipulate victims over the phone. When contacted, scammers posing as Apple’s fraud department follow a scripted conversation, initially verifying harmless details like partial phone numbers before escalating to requests for Apple ID two-factor authentication (2FA) codes. In real time, attackers use these codes to hijack accounts, gaining access to stored data, photos, and linked payment methods. The scam’s effectiveness lies in its psychological tactics leveraging urgency, brand trust, and fabricated transaction details to bypass skepticism. Researchers emphasize that Apple never schedules fraud reviews via email or demands callbacks, and official communications always originate from verified Apple domains. Victims who fall for the scheme risk full account compromise, with attackers potentially draining linked credit cards or locking users out of their devices. The campaign underscores the growing sophistication of social engineering attacks, where human manipulation not technical exploits remains the primary vector for financial theft.
INCIDENT DETAILS -
TYPE
Phishing (Vishing)
MOTIVATION
Financial Theft
IMPACT
Financial Loss: Potential draining of linked credit cardsData Compromised: Apple ID credentials, two-factor authentication codes, stored data, photos, linked payment methodsSystems Affected: Apple user accounts, linked devicesOperational Impact: Account lockouts, unauthorized access to devicesBrand Reputation Impact: Erosion of trust in Apple's fraud detection systemsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Login credentials (Apple ID), two-factor authentication codes, payment information, personal data (photos, stored data)Sensitivity Of Data: HighPersonally Identifiable Information: Yes
FEBRUARY 2026
761Before Incident
Vulnerability
02 Feb 2026BeyondTrust
BeyondTrust: BeyondTrust Remote Access Products 0-Day Vulnerability Allows Remote Code Execution

Critical Zero-Day Vulnerability in BeyondTrust Remote Access Platforms Exposes Enterprises to RCE Attacks

756After Incident
CRITICAL-5
BEY1770457908
Critical Zero-Day Vulnerability in BeyondTrust Remote Access Platforms Exposes Enterprises to RCE Attacks BeyondTrust has disclosed a severe pre-authentication remote code execution (RCE) vulnerability, CVE-2026-1731, affecting its Remote Support (RS) and Privileged Remote Access (PRA) platforms. The flaw, classified as an OS command injection (CWE-78), allows unauthenticated attackers to execute arbitrary commands on vulnerable systems without requiring credentials or user interaction. The vulnerability poses a high-risk threat to enterprise environments, as successful exploitation could lead to full system compromise, data exfiltration, service disruption, and lateral movement within networks. Given BeyondTrust’s widespread use in privileged access management, the impact extends across organizational infrastructures. ### Affected Versions & Patch Availability - Remote Support (RS): Versions 25.3.1 and earlier are vulnerable. - Privileged Remote Access (PRA): Versions 24.3.4 and prior are affected. BeyondTrust deployed automatic patches for SaaS customers on February 2, 2026, fully remediating the issue. However, self-hosted customers must manually apply fixes: - Remote Support: Patch BT26-02-RS (or upgrade to 25.3.2+). - Privileged Remote Access: Patch BT26-02-PRA (or upgrade to 25.1.1+). - Legacy systems (RS <21.3 or PRA <22.1) must first upgrade to a supported version before patching. ### Discovery & Disclosure The vulnerability was identified by Harsh Jaiswal and the Hacktron AI team using AI-driven variant analysis. BeyondTrust praised their responsible disclosure, allowing the company to develop and deploy patches before public exploitation occurred. No active attacks have been reported at this time.
INCIDENT DETAILS -
TYPE
Zero-Day Vulnerability
IMPACT
Data Compromised: Potential data exfiltrationSystems Affected: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) platformsDowntime: Potential service disruptionOperational Impact: Full system compromise, lateral movement within networks
DATA BREACH
Data Exfiltration: Potential
JANUARY 2026
761Before Incident
DECEMBER 2025
761Before Incident
NOVEMBER 2025
761Before Incident
OCTOBER 2025
760Before Incident
JUNE 2025
762Before Incident
Vulnerability
16 Jun 2025BeyondTrust
BeyondTrust

Remote Code Execution Vulnerability in BeyondTrust's Remote Support and Privileged Remote Access

760After Incident
CRITICAL-2
BEY602061725
A high-severity remote code execution vulnerability has been identified in BeyondTrust’s Remote Support and Privileged Remote Access platforms. The vulnerability, tracked as CVE-2025-5309, allows attackers to execute arbitrary code on affected systems. The flaw stems from a Server-Side Template Injection (SSTI) issue, which affects the chat feature within both platforms. The CVSSv4 score of 8.6 indicates the vulnerability can be exploited over the network with low complexity and requires no privileges, though user interaction is necessary. The underlying issue occurs because the affected systems fail to properly escape user input intended for the template engine, creating an opportunity for malicious template injection. Organizations running affected versions are at risk of having their systems compromised through the chat functionality.
INCIDENT DETAILS -
TYPE
Remote Code Execution
IMPACT
Remote SupportPrivileged Remote Access
JUNE 2025
762Before Incident
Breach
12 Jun 2025BeyondTrust
LastPass, BeyondTrust, Klue, HackerOne, Jamf, Recorded Future, Snyk, Huntress and Tanium: Klue Data Breach 2026: 200 Firms Hit via Old Credential

Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential

702After Incident
CRITICAL-60
JAMHUNSNYRECHACLASTANKLUBEY1784126732
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential In June 2025, a dormant credential issued by competitive-intelligence platform Klue in 2022 became the entry point for a breach affecting nearly 200 companies, including prominent cybersecurity vendors. The attack, claimed by the extortion group Icarus, exploited an unmonitored OAuth token to access Salesforce environments, underscoring the risks of neglected third-party integrations. ### What Happened? On June 12, 2025, attackers used a compromised legacy credential originally created for a "limited pilot" to infiltrate Klue’s systems. The credential, left active for four years, granted access to OAuth tokens that Klue used to pull data from connected Salesforce instances. Once inside, the threat actors automated data exfiltration from 195–200 companies, including LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, and Huntress. Klue publicly disclosed the breach on June 15, 2025, confirming data theft from an unspecified number of customers. By late June, affected firms began acknowledging the incident, with LastPass and BeyondTrust clarifying that only business contact and CRM data not core product systems were exposed. ### How the Attack Unfolded The breach required no zero-day exploits or sophisticated malware just an overlooked credential. The attackers leveraged Klue’s OAuth tokens to access Salesforce environments en masse, demonstrating the dangers of fourth-party risk: a vendor’s vendor (Klue) becoming the weak link in a supply chain. ### Key Victims & Impact While Klue serves sales and marketing teams, its customer base included security vendors, amplifying the breach’s irony. Confirmed victims span: - Password management (LastPass) - Privileged access (BeyondTrust) - Endpoint security (Tanium, Jamf) - Threat intelligence (Recorded Future) - Bug bounty coordination (HackerOne) - Application security (Snyk) Huntress reported receiving a ransom note from the attackers via a compromised Australian email address, highlighting the group’s reliance on reused infrastructure. ### Broader Context: A Year of Supply Chain Attacks The Klue breach coincided with a separate 2026 supply chain campaign targeting open-source security tools, including Trivy, Bitwarden, and Checkmarx. While unrelated, both incidents reflect a trend: attackers increasingly compromise trusted platforms to bypass direct defenses. ### Regulatory & Industry Reactions - Cyber insurers are tightening scrutiny of third-party integrations, particularly OAuth token hygiene. - Security vendors on the victim list face heightened procurement questions from enterprise buyers. - Regulators are paying closer attention to software supply chain risks, though the Klue breach limited to business data may not trigger major notifications. ### Lessons from the Breach The incident mirrors the 2025 Salesloft Drift breach, where stolen OAuth tokens compromised 700+ Salesforce environments. Both cases reveal a critical gap: point-in-time vendor assessments fail to catch dormant credentials. Mitigation requires: - Automated expiration for pilot credentials. - Minimum-scoped OAuth grants (avoiding broad CRM access). - Recurring token audits to identify stale integrations. As of June 2026, only ~15 of the estimated 200 affected firms have publicly confirmed exposure, with more expected to disclose as investigations continue. The breach serves as a stark reminder that identity and credential management not just perimeter defenses are central to modern cybersecurity.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion
IMPACT
Data Compromised: Business contact and CRM dataSystems Affected: Salesforce environmentsBrand Reputation Impact: Heightened procurement scrutiny for security vendors
DATA BREACH
Type Of Data Compromised: Business contact and CRM dataSensitivity Of Data: Low (non-core product data)
FEBRUARY 2025
762Before Incident
Vulnerability
01 Feb 2025BeyondTrust
Fortinet: CISA Warns of Medusa Ransomware-as-a-Service Attacks Over 300 Organizations

Medusa Ransomware Targets Critical Infrastructure in Escalating RaaS Campaign

760After Incident
CRITICAL-2
FOR1787120638
Medusa Ransomware Targets Critical Infrastructure in Escalating RaaS Campaign The Cybersecurity and Infrastructure Security Agency (CISA), FBI, and Multi-State Information Sharing and Analysis Center (MS-ISAC) have issued a joint advisory (AA25-071A) warning of ongoing Medusa ransomware attacks against critical infrastructure sectors. As of February 2025, the group has compromised over 300 organizations, with confirmed victims spanning healthcare, education, legal services, insurance, technology, and manufacturing. First detected in June 2021, Medusa initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) model. Core developers now recruit affiliates while retaining control over ransom negotiations. The group employs a double-extortion tactic, stealing data before encrypting systems and threatening to leak or sell it via a Tor-based site if demands aren’t met. Victims are given 48 hours to respond via Tor chat or the Tox messaging platform, with an option to pay $10,000 in cryptocurrency to delay data leaks by one day. Medusa’s operations rely heavily on initial access brokers, who are recruited through criminal forums and paid between $100 and $1 million for network access. Phishing and exploitation of known vulnerabilities such as ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788) are primary entry points. Once inside, attackers use living-off-the-land techniques, leveraging PowerShell, cmd.exe, Windows Management Instrumentation, and legitimate tools like AnyDesk, Atera, and ConnectWise for lateral movement. Mimikatz is used to extract credentials, while Rclone facilitates data exfiltration. The ransomware encryptor, typically named gaze.exe, is deployed via PsExec, PDQ Deploy, or BigFix. Before encryption, it disables security tools, terminates critical services, and deletes volume shadow copies. Files are encrypted with AES-256 and appended with the .medusa extension. In some cases, attackers also target virtual machines to maximize disruption. Federal agencies recommend immediate patching of internet-facing systems, network segmentation, and monitoring for suspicious activity, including unauthorized use of remote management tools, abnormal PowerShell commands, and attempts to disable endpoint protection. Indicators of compromise (IOCs) include multiple IP addresses and domains linked to command-and-control infrastructure, exfiltration, and backdoor access.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData extortion
IMPACT
Data Compromised: YesSystems Affected: Over 300 organizationsOperational Impact: Disruption of critical servicesBrand Reputation Impact: YesIdentity Theft Risk: YesPayment Information Risk: Yes
DATA BREACH
Personally identifiable informationPayment informationSensitive corporate dataSensitivity Of Data: HighData Exfiltration: YesData Encryption: Yes (AES-256)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for BeyondTrust ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in August 2026 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in July 2026 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in June 2026 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in May 2026 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in April 2026 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in March 2026 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in February 2026 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in January 2026 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in December 2025 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in November 2025 ?
?
What was BeyondTrust's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on BeyondTrust's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with BeyondTrust ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view BeyondTrust's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?