logo

ConnectWise Breached, ScreenConnect Customers Targeted

ID: 9057b5fd-0afa-5258-970e-f51cdce17566

STIX ID: report--9057b5fd-0afa-5258-970e-f51cdce17566

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-05-30

Date Updated: 2026-04-21

Author: Rob Wright

...
...

ConnectWise disclosed a breach of its ScreenConnect environment tied to a suspected nation-state actor; the company engaged Mandiant, notified affected customers, and implemented a patch and hardening measures. The intrusion is associated with CVE-2025-3935, a high-severity ViewState code-injection flaw that can enable remote code execution if ASP.NET machine keys are exposed, and the report warns of broader risks from exposed keys and historic abuse of RMM tools for ransomware and espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.