logo

Researchers say easy-to-exploit security bugs in ConnectWise remote-access software now under mass attack

ID: 84519f2d-2452-591b-b1ca-8db0bf882a59

STIX ID: report--84519f2d-2452-591b-b1ca-8db0bf882a59

Feed Name: TechCrunch Security News

Threat Score
85/100

Date Published: 2024-02-26

Date Updated: 2026-04-23

Author: Carly Page

...
...

Security researchers report mass exploitation of two critical ConnectWise ScreenConnect vulnerabilities (CVE-2024-1709 and CVE-2024-1708) that allow authentication bypass and remote code placement; multiple threat actors have used these flaws to deploy ransomware (including LockBit), backdoors like KrustyLoader, password stealers, crypto miners, and persistent remote access, while many on-premise servers remain unpatched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.