logo

ScreenConnect servers hacked in LockBit ransomware attacks

ID: 476e1803-a7ad-5a60-b422-3e60ee7c48a4

STIX ID: report--476e1803-a7ad-5a60-b422-3e60ee7c48a4

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-02-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Attackers are exploiting a critical authentication bypass (CVE-2024-1709) and related ScreenConnect vulnerabilities to breach unpatched servers and deploy LockBit ransomware; Sophos, Huntress and others have observed active intrusions, CISA added CVE-2024-1709 to its Known Exploited Vulnerabilities catalog, and ConnectWise released patches and removed license restrictions so customers can upgrade. Despite a coordinated law-enforcement takedown of LockBit infrastructure (Operation Cronos) and release of decryptors, affiliates and offshoots — including payloads created with a leaked LockBit builder — continue to operate, placing thousands of internet-exposed ScreenConnect instances at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.