logo

Researchers warn high-risk ConnectWise flaw under attack is ’embarrassingly easy’ to exploit

ID: eada4e17-d9eb-5bb6-9667-76f15b1358d4

STIX ID: report--eada4e17-d9eb-5bb6-9667-76f15b1358d4

Feed Name: TechCrunch Security News

Threat Score
90/100

Date Published: 2024-02-21

Date Updated: 2026-04-23

Author: Carly Page

...
...

A high-severity authentication-bypass vulnerability in ConnectWise ScreenConnect is being actively exploited in the wild; ConnectWise released patches and shared three IP addresses tied to suspected threat actors, but telemetry from responders indicates thousands of vulnerable servers remain. Huntress and other analysts report attackers deploying Cobalt Strike and installing ScreenConnect clients on compromised systems, creating elevated risk of widespread ransomware and persistent intrusions—on‑premise users are urged to apply the vendor patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.