Black Basta, Bl00dy ransomware gangs join ScreenConnect attacks
ID: bff5efcc-e35c-57b7-8d5f-6190a5916f8e
STIX ID: report--bff5efcc-e35c-57b7-8d5f-6190a5916f8e
Feed Name: Bleeping Computer
**Executive summary:** The Black Basta and Bl00dy ransomware gangs and other threat actors are actively exploiting a critical ScreenConnect authentication bypass (CVE-2024-1709) to create admin accounts on internet-exposed servers, delete other users, deploy web shells and backdoors, and stage ransomware and malware (Cobalt Strike, XWorm, LockBit-derived payloads); ConnectWise released patches, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, and telemetry (Shadowserver, Shodan) shows large-scale exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
