logo

Hackers are exploiting ConnectWise flaws to deploy LockBit ransomware, security experts warn

ID: 14ac6417-833a-595b-b189-f7963d0f25bc

STIX ID: report--14ac6417-833a-595b-b189-f7963d0f25bc

Feed Name: TechCrunch Security News

Threat Score
80/100

Date Published: 2024-02-23

Date Updated: 2026-04-23

Author: Carly Page

...
...

Security researchers report active exploitation of two high-risk ConnectWise ScreenConnect vulnerabilities (CVE-2024-1709 and CVE-2024-1708) that allow attackers to remotely plant code and deploy LockBit ransomware; Huntress, Sophos, and Shadowserver observed multiple attacks and hundreds of exploit attempts while thousands of servers remain vulnerable, indicating a widespread and ongoing ransomware campaign despite recent law-enforcement disruptions of LockBit infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.