Researchers warn that hackers are exploiting ConnectWise's remote access tool via a flaw “embarrassingly easy” to exploit; ConnectWise has confirmed the attacks
TechCrunchCarly Page
Context & Ripple Effects
ConnectWise joins a recurring set of security incidents involving tools that sit close to enterprise administration. Related coverage documented attackers using a zero-day in the SysAid IT support product to reach corporate servers and deploy ransomware, underscoring why compromise of these platforms carries outsized operational risk.
The immediate significance is not simply another software flaw: ConnectWise has acknowledged active abuse. That confirmation turns a researcher warning into an exposure-management issue for organizations that rely on the vendor's remote-access capability.
First-order effects
ConnectWise customers using the affected remote-access tool must treat the confirmed exploitation as a live security incident, reviewing potentially affected systems and vendor guidance.
ConnectWise faces an immediate response burden: contain abuse, communicate clearly with customers, and demonstrate that its remote-administration environment can be trusted.
Second-order effects
Managed service providers and enterprise IT teams are likely to scrutinize remote-support access paths and monitoring more closely, because these tools can concentrate privileged access across customer environments.
Other IT-management vendors face heightened pressure to identify and remediate exploitable weaknesses quickly; the earlier exploitation of SysAid's support-tool zero-day shows attackers' continued interest in this software category.
Third-order effects
If active exploitation of remote-administration products persists, buyers may place more weight on security controls, incident transparency, and limits on privileged remote access when selecting IT-management platforms.
The pattern points toward remote support and VPN tools being treated as high-value defensive boundaries rather than routine operational software, as reflected by the later exploitation warning involving Ivanti Connect Secure.
The trend: Attackers are increasingly targeting enterprise tools that administer systems remotely, forcing vendors and customers to treat management software as critical security infrastructure.
~3800 vulnerable ConnectWise ScreenConnect instances (authentication bypass using an alternate path or channel (CVSS 10) & path traversal (CVSS 8.4)) https://www.connectwise.com/ ... IP data in: https://www.shadowserver.org/ ... ~93% instances of ScreenConnect seen on 2024-02-20 …
Well, now that other firms have publicly shared the proof-of-concept, and in-the-wild exploitation is already happening... we feel we aren't adding any risk and are comfortable sharing our analysis. @HuntressLabs writeup on #ScreenConnect vulnerabilities: https://www.huntress.com…
🔥 some internal files — mostly employee chat records in 2020-2022 — of 🇨🇳 security solutions company (with cyberespionage capabilities) I-SOON (安洵信息) have been leaked on Github... (quoted thread below) Some notes: * I-SOON has links with APT41 possibly as a contractor *... [image…
ConnectWise has shared publicly that there are users affected by the recent #ScreenConnect vulnerabilities (authentication bypass->remote code execution), confirming in-the-wild exploitation. They share 3 observed IPs exploiting & installing persistence: https://www.connectwise.c…
ConnectWise has suspended non-patched versions of Screen Connect to limit exploitation Todays new patch removes license restrictions so that all can update to the latest version. https://www.connectwise.com/ ... There's also now exploit attempts to deploy xmrig miners via transfe…
On February 19, 2024, ConnectWise published a security advisory for #ScreenConnect version 23.9.8, referencing two vulnerabilities and software weaknesses.
Extra amounts of scanning for - CVE-2024-1708 and CVE-2024-1709 kicked off nice and good today looking for #ConnectWise ScreenConnects! - https://github.com/... - https://github.com/... - https://github.com/... Great work by Huntress! https://www.huntress.com/... [image]
Epic move by @ConnectWise. The new ScreenConnect patch will now upgrade you to the latest version—even if you're no longer under maintenance. 🎁 History favors the bold and I'm a big fan of this decision. Get the details and the patch here https://www.connectwise.com/ ...
Big props to the @HuntressLabs crew for disclosing responsibly this vulnerability. Worth pointing out that they also created detections for the community, making it easier for the rest of us to respond, thank you!🙏 https://www.huntress.com/...
Using ScreenConnect? ConnectWise has released a security bulletin regarding critical vulnerabilities (incl. a CVSS 10 RCE): https://www.connectwise.com/ ... You can track accessible instances on our Dashboard: https://dashboard.shadowserver.org/ ... ~4300 accessible daily (no vul…