ConnectWise says nation-state attack targeted multiple ScreenConnect customers
ID: 8a539514-a2a6-5151-8350-ac3a68ebaf59
STIX ID: report--8a539514-a2a6-5151-8350-ac3a68ebaf59
Feed Name: The Record from Recorded Future News
ConnectWise disclosed an investigation into a sophisticated nation-state attack that affected a small number of ScreenConnect customers; the company engaged Mandiant, applied patches and enhanced monitoring, and reported no further suspicious activity. The report links exploitation of CVE-2024-1709 and notes prior use of ScreenConnect vulnerabilities by China-affiliated actors and Russia-linked Sandworm against governments, defense contractors and other organizations, highlighting elevated supply-chain and MSP-related risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
