Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Exploit Quest KACE SMA Flaw to Harvest Credentials

Security Researchers have detected active exploitation targeting unpatched Quest KACE Systems Management Appliance (SMA) instances.

Security Researchers have detected active exploitation targeting unpatched Quest KACE Systems Management Appliance (SMA) instances.

Starting the week of Mar 9, 2026, threat actors began leveraging a critical authentication bypass vulnerability , identified as CVE-2025-32975, to infiltrate corporate networks, harvest sensitive credentials, and pivot toward critical infrastructure.

Quest KACE SMA is a popular on-premises solution designed for centralized endpoint management, handling tasks ranging from software deployment to endpoint monitoring.

CVE-2025-32975 represents a severe flaw within the appliance’s Single Sign-On (SSO) authentication handling mechanism.

By exploiting this vulnerability, attackers can successfully bypass authentication protocols and impersonate legitimate users without needing valid credentials.

This effectively grants them complete administrative takeover of the appliance. Although Quest originally released a patch for this flaw in May 2025 alongside several other related vulnerabilities, publicly exposed and outdated systems remain highly vulnerable to compromise nearly a year later.

Security researchers at Arctic Wolf discovered that, upon gaining initial access through the SSO bypass, attackers move rapidly to establish a firm foothold in the victim's environment.

They leverage the native KPluginRunProcess functionality within the KACE software to execute remote commands, heavily relying on Base64-encoded payloads to evade immediate security detection.

Security Researchers have detected active exploitation targeting unpatched Quest KACE Systems Management Appliance (SMA) instances.
John Mason · Thehackingpost

Researchers observed the attackers using simple curl commands to download additional malicious files from an external command-and-control server located at the IP address 216.126.225.156.

To maintain stealthy persistence, the threat actors abuse the legitimate runkbot.exe process to spawn unauthorized administrative accounts .

They actively attempt to add rogue users to both local and domain administrator groups to solidify their network control.

Furthermore, the attackers deploy hidden PowerShell scripts, such as Enable-UpdateServices.ps1 and taskband.ps1, to silently modify registry settings and ensure their backdoor access survives system reboots and routine maintenance.

Once entrenched, the operation shifts entirely to credential access and internal discovery.

The attackers deploy the notorious Mimikatz tool, sometimes cleverly disguised under the arbitrary filename asd.exe, to harvest plaintext credentials directly from memory.

They then aggressively map the local environment and domain administrative structures using native enumeration commands.

Advertisement

Armed with fresh credentials and network maps, the adversaries pivot laterally through the network.

Most alarmingly, researchers noted attackers establishing Remote Desktop Protocol (RDP) sessions to critical infrastructure elements, including domain controllers and enterprise backup servers running Veeam or Veritas software.

To prevent exploitation, administrators must immediately upgrade their KACE SMA environments to the latest patched releases.

Users operating on older 13.0, 13.1, and 13.2 branches must upgrade to versions 13.0.385, 13.1.81, and 13.2.183 or later, respectively.

Similarly, environments running the newer 14.0 and 14.1 branches must apply Patch 5 (version 14.0.341) and Patch 4 (version 14.1.101) to secure their systems.

Additionally, organisations should proactively remove any KACE SMA interfaces from the public internet, restricting remote administrative access strictly to secure VPNs or enterprise firewalls to minimise their external attack surface.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories