Follow the latest coverage, related explainers and connected technology stories.
Threat actors have been observed actively exploiting a critical vulnerability in ConnectWise ScreenConnect that enables files to be transferred or executed through remote access sessions without proper authorization. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, while more than 1,000 exposed and unpatched instances remain available online, according to Shadowserver.
Attackers are attempting to exploit a chain of two critical vulnerabilities in MikroTik RouterOS to bypass SSH authentication and then obtain full administrative privileges, amid warnings of active attacks against devices exposed to the internet. MikroTik has released security updates, while Poland’s CERT recommended isolating devices suspected of compromise and rebuilding them from trusted configurations.