logo

New ScreenConnect RCE flaw exploited in ransomware attacks

ID: fab48291-65b5-51ad-874d-5fb37aa0f498

STIX ID: report--fab48291-65b5-51ad-874d-5fb37aa0f498

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-02-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Attackers are actively exploiting a critical ScreenConnect authentication-bypass (CVE-2024-1709) — and a related path traversal bug (CVE-2024-1708) — to breach unpatched servers and deploy LockBit ransomware and variants (including payloads produced with a leaked LockBit builder). Security firms (Sophos, Huntress) observed recent attacks impacting government and healthcare targets; CISA added CVE-2024-1709 to its Known Exploited Vulnerabilities Catalog and ConnectWise urged immediate patching while removing license restrictions to help customers update. Although a global law-enforcement operation (Operation Cronos) seized LockBit infrastructure and released a decryptor, affiliates and offshoots continue to operate and exploit exposed ScreenConnect instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.