Get the latest tech news

Researchers warn high-risk ConnectWise flaw under attack is ’embarrassingly easy’ to exploit


“I can’t sugarcoat it — this shit is bad," warned one cybersecurity firm, as thousands of servers remain vulnerable to remote hacks

Hanslovan added that due to the “sheer prevalence of this software and the access afforded by this vulnerability signals we are on the cusp of a ransomware free-for-all.” ConnectWise has released a patch for the actively exploited vulnerability and is urging on-premise ScreenConnect users to apply the fix immediately. The U.S. agencies also observed hackers abusing remote access software from AnyDesk, which was earlier this month forced to reset passwords and revoke certificates after finding evidence of compromised production systems.

Get the Android app

Or read this on TechCrunch

Read more on:

Photo of attack

attack

Photo of researchers

researchers

Photo of ConnectWise

ConnectWise

Related news:

News photo

ScreenConnect critical bug now under attack as exploit code emerges

News photo

Spam attack on Twitter/X rival Mastodon highlights ‘fediverse’ vulnerabilities

News photo

ConnectWise urges ScreenConnect admins to patch critical RCE flaw