Attacker enables RDP, creates admin, erases evidence in ten seconds

At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them.  The intrusion reached 34 endpoints and was over in under ten seconds.  Heimdal Extended Threat Protection (XTP) and Ransomware […]

The post Attacker enables RDP, creates admin, erases evidence in ten seconds appeared first on Heimdal Security Blog.

This article has been indexed from Heimdal Security Blog

Read the original article: