* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Tuesday, June 2, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Celebrate Pride Month 2026 with Seattle Pride in the Park and Exciting Events

    How to find free, low-cost concerts this summer in Louisville: A Q&A – The Courier-Journal

    Morgan Wallen Channels Fiery Billy Joel Vibes with Explosive Piano Flip

    Massive Fire Breaks Out at Boardman Business, Sending Thick Smoke Into the Sky

    This Hidden Entertainment Stock Is Set to Skyrocket to Record Highs

    Caesars Entertainment, Sonoma County casino builder and Las Vegas Strip icon, is selling for nearly $6 billion – The Press Democrat

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Anixa Biosciences Strengthens International Patent Protection for Ovarian Cancer Vaccine Technology with Canadian Notice of Allowance – PR Newswire

    Micron Technology Surges Amid AI Boom and Market Momentum

    I Tried to Sell My House With a Chatbot – The New York Times

    Anthropic’s Partnership with the Pope on AI Harms: Genuine Collaboration or Just ‘Vatican-Washing’?

    Have Your Say: Share Your Thoughts on Technology in North Dakota Schools!

    Cutting-Edge Anti-Jamming Technologies Revolutionizing Modern Drone Operations

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Celebrate Pride Month 2026 with Seattle Pride in the Park and Exciting Events

    How to find free, low-cost concerts this summer in Louisville: A Q&A – The Courier-Journal

    Morgan Wallen Channels Fiery Billy Joel Vibes with Explosive Piano Flip

    Massive Fire Breaks Out at Boardman Business, Sending Thick Smoke Into the Sky

    This Hidden Entertainment Stock Is Set to Skyrocket to Record Highs

    Caesars Entertainment, Sonoma County casino builder and Las Vegas Strip icon, is selling for nearly $6 billion – The Press Democrat

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Anixa Biosciences Strengthens International Patent Protection for Ovarian Cancer Vaccine Technology with Canadian Notice of Allowance – PR Newswire

    Micron Technology Surges Amid AI Boom and Market Momentum

    I Tried to Sell My House With a Chatbot – The New York Times

    Anthropic’s Partnership with the Pope on AI Harms: Genuine Collaboration or Just ‘Vatican-Washing’?

    Have Your Say: Share Your Thoughts on Technology in North Dakota Schools!

    Cutting-Edge Anti-Jamming Technologies Revolutionizing Modern Drone Operations

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

ConnectWise users see cyber attacks surge, including ransomware

February 24, 2024
in Technology
ConnectWise users see cyber attacks surge, including ransomware
Share on FacebookShare on Twitter

Skórzewiak – stock.adobe.com

ConnectWise ScreenConnect users who have yet to patch against a critical vulnerability are now being targeted by a barrage of cyber attacks, including ransomware


Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 23 Feb 2024 15:51

Cyber attacks against vulnerable instances of the ConnectWise ScreenConnect remote management platform are now being observed following the disclosure of a critical vulnerability in the service, including some by an individual using a leaked variant of LockBit ransomware.

CVE-2024-1709 – described as “trivial” to exploit by one researcher who has poked around under the bonnet – is an authentication bypass vulnerability and was disclosed earlier this week. A second, less severe but still dangerous issue, CVE-2024-1708, is also in circulation.

Patches are available and further details of how to apply these, and who needs to do so, are available from ConnectWise.

Given the ease of exploitation, observers had already been predicting that attacks would unfold in short order, and this now appears to be the case, as Sophos X-Ops director Christopher Budd observed.

“We’ve seen multiple attacks involving ScreenConnect in the past 48 hours. The most noteworthy has been a malware that was built using the LockBit 3 ransomware builder tool leaked in 2022: this may not have originated with the actual LockBit developers. But we’re also seeing RATs [remote access Trojans], infostealers, password stealers and other ransomware. All of this shows that many different attackers are targeting ScreenConnect,” said Budd

“Anyone using ScreenConnect should take steps to immediately isolate vulnerable servers and clients, patch them and check for any signs of compromise. Sophos has extensive guidance and threat hunting material from Sophos X-Ops to help. We are continuing our investigations and will make updates as needed,” he told Computer Weekly in emailed comments.

Mike Walters, president and co-founder of Action1, a patch management specialist, was among those urging ConnectWise customers to sit up and take notice. “Potentially there could be thousands of compromised instances. The massive attack exploiting these vulnerabilities may be similar to the Kaseya vulnerability exploitation in 2021, as ScreenConnect is a very popular RMM among MSPs and MSSPs, and could result in comparable damage,” he said.

“The security advisory states that updated ScreenConnect versions 22.4 through 23.9.7 are planned for release and emphasises the recommendation to upgrade to ScreenConnect version 23.9.8 as a priority.

“Cloud customers hosting ScreenConnect servers on the ‘screenconnect.com’ or ‘hostedrmm.com’ domains are not affected, as updates have been implemented to address these vulnerabilities in the cloud service,” added Walters.

At the time of writing, Shodan data shows that there are around 9,000 vulnerable instances of ScreenConnect exposed to the internet, with just under 500 of those located in the UK.  

Sophos said the simplicity of exploitation made it imperative for users to assess their exposure and take steps beyond simply patching.

For maximum protection, security teams should be sure they have identified all ScreenConnect installations – including those run by external managed service providers (MSPs), isolate or uninstall the client software from identified devices until they can confirm they have patched, and then check those devices for potential malicious activity. This can include the creation of new local users, suspicious client software activity, system and domain recon, and any actions that may indicate someone has attempted to disable security controls.

A spokesperson for ConnectWise told Computer Weekly: “We have swiftly addressed the two vulnerabilities in our ScreenConnect software. Our cloud partners were automatically protected within 48 hours, while on-premise customers were urged to apply the provided patch immediately through the upgrade path we provided. We remain committed to prioritising the security of our partners’ systems and will continue to take proactive measures to address vulnerabilities promptly and effectively.

They added: “At this time, we cannot definitively establish a direct link between the vulnerability and any security incidents.”

This article was edited at 17:30 GMT on 23 February 2024 to incorporate a statement from ConnectWise.

Read more on Data breach incident management and recovery


ConnectWise ScreenConnect flaws under attack, patch now

AlexanderCulafi

By: Alexander Culafi


Cyber experts alarmed by ‘trivial’ ConnectWise vulns

AlexScroxton

By: Alex Scroxton


LockBit locked out: Cyber community reacts

AlexScroxton

By: Alex Scroxton


CISA reveals how LockBit hacked Boeing via Citrix Bleed

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366571022/ConnectWise-users-see-cyber-attacks-surge-including-ransomware

Tags: ConnectWisetechnologyusers
Previous Post

NCA trolls under fire LockBit gang leaders

Next Post

King Charles strips disgraced Post Office CEO of her CBE

Celebrate Pride Month 2026 with Seattle Pride in the Park and Exciting Events

June 2, 2026

Judge Rules: Demonstrators Have the Right to Keep ’86-47′ Flag Flying

June 2, 2026

Anixa Biosciences Strengthens International Patent Protection for Ovarian Cancer Vaccine Technology with Canadian Notice of Allowance – PR Newswire

June 2, 2026

Drake Maye gets new WR1 with Monday NFL trade – Yahoo Sports

June 2, 2026

Congo Basin, the World’s Largest Ecological Lung, Attracts Over $3 Billion in Project Funding

June 2, 2026

Revitalizing US Science and Technology Policy in the Wake of Trump 2.0 Challenges

June 2, 2026

Waunakee Student Honored with Prestigious Animal Science Scholarship

June 2, 2026

Integrating Exercise and Lifestyle Intervention Into Oncologic Therapy – CancerNetwork

June 2, 2026

Heading to Atlanta for the World Cup? Don’t Miss These Essential Tips!

June 2, 2026

We asked, you answered: Has the current economy changed your summer vacation plans? – The Keystone Newsroom

June 2, 2026

Categories

Archives

June 2026
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
2930  
« May    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,244)
  • Economy (1,267)
  • Entertainment (22,144)
  • General (21,855)
  • Health (10,300)
  • Lifestyle (1,277)
  • News (22,149)
  • People (1,268)
  • Politics (1,287)
  • Science (16,480)
  • Sports (21,764)
  • Technology (16,251)
  • World (1,257)

Recent News

Celebrate Pride Month 2026 with Seattle Pride in the Park and Exciting Events

June 2, 2026

Judge Rules: Demonstrators Have the Right to Keep ’86-47′ Flag Flying

June 2, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version