Researchers warn that hackers are exploiting ConnectWise's remote access tool via a flaw “embarrassingly easy” to exploit; ConnectWise has confirmed the attacks
“I can't sugarcoat it — this shit is bad," said Huntress' CEO — Security experts are warning that a high-risk vulnerability …
TechCrunchCarly Page
Context & Ripple Effects
ConnectWise joins a run of exploited flaws in enterprise-facing administration software: Ivanti had already confirmed attacks against its corporate VPN software while patches were delayed, and Microsoft described limited exploitation of a SysAid zero-day to reach corporate servers. Ivanti’s confirmed VPN attacks and the SysAid zero-day campaign make this more than an isolated vendor incident.
Huntress’ role in flagging the issue also fits its focus on incident reporting and security products for smaller organizations, which can face disproportionate exposure when a widely deployed management tool is compromised.
First-order effects
Organizations running the affected ConnectWise remote-access tool face an active-exploitation event rather than a theoretical vulnerability, making exposure assessment and defensive response immediately urgent.
ConnectWise must manage the operational and trust fallout of confirmed attacks, while Huntress gains visibility as the researcher publicly characterizing the risk.
Second-order effects
Other remote-management, VPN, and IT-support vendors will face sharper scrutiny over patch speed, disclosure quality, and safeguards against exploitation, given the similar incidents involving Ivanti’s VPN software and SysAid.
Security teams and managed-service providers may prioritize monitoring for abuse of privileged administration tools, increasing demand for detection and incident-response support from firms such as Huntress.
Third-order effects
If exploitation of remote administration software continues, these tools will increasingly be treated as high-consequence infrastructure: a flaw at one vendor can create correlated risk across many customer environments.
The pattern favors security architectures that reduce standing administrative access and improve visibility into tool behavior, though the corpus does not establish whether vendors will adopt a common standard.
The trend: Exploited vulnerabilities in remote-access and IT administration products are turning trusted operational tooling into a concentrated enterprise attack surface.
New, by @carlypage: Security experts say that actively exploited ConnectWise vulnerability is “trivial and embarrassingly easy” to exploit. — “I can't sugarcoat it — this shit is bad,” Huntress' CEO told TechCrunch. — ConnectWise provides popular remote-access tools used by I…
~3800 vulnerable ConnectWise ScreenConnect instances (authentication bypass using an alternate path or channel (CVSS 10) & path traversal (CVSS 8.4)) https://www.connectwise.com/ ... IP data in: https://www.shadowserver.org/ ... ~93% instances of ScreenConnect seen on 2024-02-20 …
Well, now that other firms have publicly shared the proof-of-concept, and in-the-wild exploitation is already happening... we feel we aren't adding any risk and are comfortable sharing our analysis. @HuntressLabs writeup on #ScreenConnect vulnerabilities: https://www.huntress.com…
🔥 some internal files — mostly employee chat records in 2020-2022 — of 🇨🇳 security solutions company (with cyberespionage capabilities) I-SOON (安洵信息) have been leaked on Github... (quoted thread below) Some notes: * I-SOON has links with APT41 possibly as a contractor *... [image…
ConnectWise has shared publicly that there are users affected by the recent #ScreenConnect vulnerabilities (authentication bypass->remote code execution), confirming in-the-wild exploitation. They share 3 observed IPs exploiting & installing persistence: https://www.connectwise.c…
Big props to the @HuntressLabs crew for disclosing responsibly this vulnerability. Worth pointing out that they also created detections for the community, making it easier for the rest of us to respond, thank you!🙏 https://www.huntress.com/...
Extra amounts of scanning for - CVE-2024-1708 and CVE-2024-1709 kicked off nice and good today looking for #ConnectWise ScreenConnects! - https://github.com/... - https://github.com/... - https://github.com/... Great work by Huntress! https://www.huntress.com/... [image]
Using ScreenConnect? ConnectWise has released a security bulletin regarding critical vulnerabilities (incl. a CVSS 10 RCE): https://www.connectwise.com/ ... You can track accessible instances on our Dashboard: https://dashboard.shadowserver.org/ ... ~4300 accessible daily (no vul…
Epic move by @ConnectWise. The new ScreenConnect patch will now upgrade you to the latest version—even if you're no longer under maintenance. 🎁 History favors the bold and I'm a big fan of this decision. Get the details and the patch here https://www.connectwise.com/ ...
On February 19, 2024, ConnectWise published a security advisory for #ScreenConnect version 23.9.8, referencing two vulnerabilities and software weaknesses.
ConnectWise has suspended non-patched versions of Screen Connect to limit exploitation Todays new patch removes license restrictions so that all can update to the latest version. https://www.connectwise.com/ ... There's also now exploit attempts to deploy xmrig miners via transfe…