Researchers warn high-risk ConnectWise flaw under attack is ’embarrassingly easy’ to exploit
ID: eada4e17-d9eb-5bb6-9667-76f15b1358d4
STIX ID: report--eada4e17-d9eb-5bb6-9667-76f15b1358d4
Feed Name: TechCrunch Security News
A high-severity authentication-bypass vulnerability in ConnectWise ScreenConnect is being actively exploited in the wild; ConnectWise released patches and shared three IP addresses tied to suspected threat actors, but telemetry from responders indicates thousands of vulnerable servers remain. Huntress and other analysts report attackers deploying Cobalt Strike and installing ScreenConnect clients on compromised systems, creating elevated risk of widespread ransomware and persistent intrusions—on‑premise users are urged to apply the vendor patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
