
ConnectWise's ScreenConnect software has been found to have critical vulnerabilities, including an authentication bypass leading to remote code execution. Security experts warn that the exploitation of these flaws is trivial and actively happening in the wild. Researchers have recreated the exploit and shared details, with CVEs assigned for the vulnerabilities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings and deadlines related to the vulnerabilities, with reports of ransomware attacks exploiting the flaws.





















SlashAndGrab: ScreenConnect Post-Exploitation in the Wild (CVE-2024-1709 & CVE-2024-1708) https://t.co/l8VEDxKzCF
CISA: Update ConnectWise ScreenConnect Servers Or Take Offline As Ransomware Is Deployed: https://t.co/EPJW5usUBE @HuntressLabs is tracking multiple ransomware exploits amid the ConnectWise ScreenConnect vulnerabilities. Here’s what @_JohnHammond told @cj_fairfield.
EXCLUSIVE: Critical #ConnectWise ScreenConnect bug exploited in Change Healthcare #ransomware attack https://t.co/6fC8RB2woL