[ad_1]
“It’s dire—there’s no other way to say it,” remarked the CEO of Huntress

Amidst rising concerns, security professionals are cautioning that an easily exploitable and high-risk vulnerability in a pervasive remote access solution is currently under active cyber attack, as confirmed by the software’s creators.
The critical vulnerability is present in ConnectWise ScreenConnect (previously known as ConnectWise Control), a remote access tool extensively employed by IT service providers and technicians to offer real-time technical support on client computers.
An authentication bypass issue, the vulnerability allows an attacker to gain unauthorized access to systems, potentially leading to information theft or the deployment of harmful software such as viruses. Initially brought to ConnectWise’s attention on February 13, the vulnerability received public acknowledgement in a security advisory posted by the company on February 19.
Initially, ConnectWise did not believe the flaw was being exploited. However, recent updates on Tuesday have shown that there are now “received updates of compromised accounts that our incident response team have been able to investigate and confirm,” according to ConnectWise.
The company even identified three specific IP addresses actively used by cybercriminals in these attacks.
Concerning the scope of the affected customers, a ConnectWise representative, Amanda Lee, opted not to disclose specific numbers but indicated that instances of suspected unauthorized access have been limited in quantity. Lee also mentioned that, thankfully, 80% of the customer foundations using the cloud have had patches applied automatically within two days.
Lee further mentioned that while no reported data exfiltration has occurred, the company cannot confirm whether they have the capability to detect if information was accessed or not.
Based in Florida, ConnectWise serves over a million small to medium businesses with its remote access technology, as quoted on its website.
Huntress, a cybersecurity firm, shared their examination of the vulnerability, which is being exploited. John Hammond from Huntress informed TechCrunch about the ongoing and active exploitation they’ve observed, and the advance of attackers to more sophisticated tactics post-infiltration.
Hammond highlighted that intruders quickly move to plant Cobalt Strike beacons and even set up ScreenConnect clients on compromised servers, indicating that there’s more trouble expected shortly.
Huntress CEO Kyle Hanslovan summed up the severity of the situation, citing telemetry indicating that more than 1,600 servers are exposed.
“The truth is, it’s disastrous. We’re looking at an expanse of ten thousand servers with the potential to affect hundreds of thousands of endpoints,” explained Hanslovan to TechCrunch, with an estimate of over 8,800 ConnectWise servers still susceptible.
Hanslovan also warned of potential widespread ransomware incidents due to the commonly used software and the extent of access the flaw provides.
ConnectWise has dispatched a patch for the vulnerability now being exploited and strongly recommends that customers using on-premises ScreenConnect apply the update without delay. Additionally, the company has fixed another vulnerability concerning their remote desktop software. Lee reassured TechCrunch that there are no indications this particular flaw has been manipulated.
Earlier in the year, the United States agencies CISA and the NSA alerted to a “massive cyber campaign involving malevolent use of rightful Remote Monitoring and Management (RMM) software”— including ConnectWise SecureConnect—targeted at various federal agencies.
The agencies have also noticed cyber assaulters misusing remote access software by AnyDesk, which, earlier this month, was compelled to carry out an emergency reset of passwords and certificate nullification after identifying compromised production systems.
In light of this incident, CISA’s cybersecurity executive assistant director Eric Goldstein acknowledged awareness of the vulnerability and is taking measures to understand the extent of its exploitation to offer necessary advice and aid.
If you are impacted by the ConnectWise vulnerability, please get in touch with Carly Page using Signal at +441536 853968 or via email at carly.page@techcrunch.com. TechCrunch can also be reached through SecureDrop.
[ad_2]
FAQs about the ConnectWise Security Flaw
- How severe is the ConnectWise ScreenConnect vulnerability?
- The flaw is highly severe, as it allows for an authentication bypass that could enable attackers to obtain sensitive data or distribute malware.
- Has ConnectWise issued a patch for the vulnerability?
- Yes, ConnectWise has released a patch for the vulnerability and recommends that all on-premise ScreenConnect users apply it immediately.
- Are cloud-based ConnectWise environments affected?
- About 80% of customer environments that are cloud-based were automatically patched within 48 hours of the vulnerability’s disclosure.
- Has there been any data exfiltration reported?
- As per ConnectWise’s spokesperson Amanda Lee, there has been no data exfiltration reported.
- What should affected users do?
- Affected users should apply the provided patch immediately and monitor their systems for any signs of compromise.
Conclusion
The situation concerning the ConnectWise ScreenConnect vulnerability highlights the urgent and ongoing need for vigilance in cybersecurity. With confirmation of active exploitation and the potential for widespread ransomware attacks looming, the information technology community is on high alert. As Huntress CEO Kyle Hanslovan succinctly puts it, the potential damage is significant. Users of ConnectWise software, particularly those with on-premise deployments, must take immediate action to implement security measures and protect their IT environments against opportunistic cybercriminals. CISA’s involvement signifies the critical nature of the threat and underscores the imperative for prompt and effective response to such vulnerabilities in our increasingly interconnected digital landscape.










































