ID: 0f0155ee-e498-5555-8169-01c650b59cb0
STIX ID: report--0f0155ee-e498-5555-8169-01c650b59cb0
Feed Name: Huntress Blog
ConnectWise ScreenConnect contained two critical vulnerabilities (CVE-2024-1709 and CVE-2024-1708) that enabled an extremely trivial authentication bypass — dubbed 'SlashAndGrab' — allowing attackers to create accounts via setupwizard.aspx and gain full access; a PoC was developed within hours and exploitation in the wild followed, with adversaries deploying ransomware, coin miners, and persistent remote access. Huntress published technical analysis and detection guidance, contributed Sigma rules, sent incident alerts to partners, and deployed a hotfix/vaccine to mitigate impact while urging immediate patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
