Follow the latest coverage, related explainers and connected technology stories.
Threat actors have been observed actively exploiting a critical vulnerability in ConnectWise ScreenConnect that enables files to be transferred or executed through remote access sessions without proper authorization. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, while more than 1,000 exposed and unpatched instances remain available online, according to Shadowserver.
ConnectWise warned of a vulnerability affecting file-transfer behavior in ScreenConnect Remote Access, covering both cloud and on-premises versions, while the final patch is not yet available. The company provided a temporary measure to disable file-transfer permissions until the update is released, which is expected later this week.
Phishing actors exploited the legitimate Faronics Deploy platform for remote device management to gain administrative access to more than 457 endpoints, then used PowerShell to install ConnectWise ScreenConnect as an additional access channel. Faronics took action after being notified by Huntress, and indicators of the activity declined as of August 21.