Guide: How to Know if your ScreenConnect Server is Hacked | Huntress
ID: 655588ba-a990-50aa-9fc2-70aa34bd714b
STIX ID: report--655588ba-a990-50aa-9fc2-70aa34bd714b
Feed Name: Huntress Blog
Huntress reports active exploitation of two ConnectWise ScreenConnect vulnerabilities (CVE-2024-1708, CVE-2024-1709), dubbed "SlashAndGrab," used to deliver malware; on-prem ScreenConnect servers and workstation instances are at risk. The advisory urges immediate patching to 23.9.8, describes IOCs (wiped/modified user.xml, zeroed timestamps, malicious .ashx extensions, activity around SetupWizard.aspx with Event ID 4663), and recommends isolating compromised hosts, disabling ScreenConnect services, resetting credentials, and deploying monitoring/mitigation tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
