NEWS

  • HOME PAGE
  • Bitcoin News
  • FOOT news
  • Kpop News
  • SPORTS
  • Bitcoin News
  • Tech News
  • Forum

Hackers are exploiting ConnectWise flaws to deploy LockBit ransomware, security experts warn

23rd February 2024 by admin

  • Texas pushes three-loss playoff debate to next level with third top-10 victory against Texas A&M
  • “Squid Game” Actor Admits Co-star Burst Into Tears After Filming Explicit Scene With Him
  • The Progression of Cam Ward

  • Security experts are warning that a pair of high-risk flaws in a popular remote access tool are being exploited by hackers to deploy LockBit ransomware — days after authorities announced that they had disrupted the notorious Russia-linked cybercrime gang.

    Researchers at cybersecurity companies Huntress and Sophos told TechCrunch on Thursday that both had observed LockBit attacks following the exploitation of a set of vulnerabilities impacting ConnectWise ScreenConnect, a widely used remote access tool used by IT technicians to provide remote technical support on customer systems.

    The flaws consist of two bugs. CVE-2024-1709 is an authentication bypass vulnerability deemed “embarrassingly easy” to exploit, which has been under active exploitation since Tuesday, soon after ConnectWise released security updates and urged organizations to patch. The other bug, CVE-2024-1708, is a path traversal vulnerability that can be used in conjunction with the other bug to remotely plant malicious code on an affected system.

    In a post on Mastodon on Thursday, Sophos said that it had observed “several LockBit attacks” following exploitation of the ConnectWise vulnerabilities.

    “Two things of interest here: first, as noted by others, the ScreenConnect vulnerabilities are being actively exploited in the wild. Second, despite the law enforcement operation against LockBit, it seems as though some affiliates are still up and running,” Sophos said, referring to the law enforcement operation earlier this week that claimed to take down LockBit’s infrastructure.

    Christopher Budd, director of threat research at Sophos X-Ops, told TechCrunch by email that the company’s observations show that, “ScreenConnect was the start of the observed execution chain, and the version of ScreenConnect in use was vulnerable.”

    Max Rogers, senior director of threat operations at Huntress, told TechCrunch that the cybersecurity company has also observed LockBit ransomware being deployed in attacks exploiting the ScreenConnect vulnerability.

    Rogers said that Huntress has seen LockBit ransomware deployed on customer systems spanning a range of industries, but declined to name the customers affected.

    LockBit ransomware’s infrastructure was seized earlier this week as part of a sweeping international law enforcement operation led by the U.K.’s National Crime Agency. The operation downed LockBit’s public-facing websites, including its dark web leak site, which the gang used to publish stolen data from victims. The leak site now hosts information uncovered by the U.K.-led operation exposing LockBit’s capabilities and operations.

    The action, known as “Operation Cronos,” also saw the takedown of 34 servers across Europe, the U.K., and the United States, the seizure of more than 200 cryptocurrency wallets, and the arrests of two alleged LockBit members in Poland and Ukraine.

    “We can’t attribute [the ransomware attacks abusing the ConnectWise flaws] directly to the larger LockBit group, but it is clear that LockBit has a large reach that spans tooling, various affiliate groups, and offshoots that have not been completely erased even with the major takedown by law enforcement,” Rogers told TechCrunch via email.

    When asked whether the deployment of ransomware was something that ConnectWise was also observing internally, ConnectWise chief information security officer Patrick Beggs told TechCrunch that “this is not something we are seeing as of today.”

    It remains unknown how many ConnectWise ScreenConnect users have been impacted by this vulnerability, and ConnectWise declined to provide numbers. The company’s website claims that the organization provides its remote access technology to more than a million small to medium-sized businesses.

    According to the Shadowserver Foundation, a nonprofit that gathers and analyzes data on malicious internet activity, the ScreenConnect flaws are being “widely exploited.” The non-profit said Thursday in a post on X, formerly Twitter, that it had so far observed 643 IP addresses exploiting the vulnerabilities — adding that more than 8,200 servers remain vulnerable.

    Related

    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Microsoft buys another 100 MW of solar, this time in Japan Microsoft buys another 100 MW of solar, this time in Japan
    Microsoft buys another 100 MW of solar, this time in Japan Microsoft buys another 100 MW of solar, this time in Japan
    OpenAI ramps up developer push with more powerful models in its API  OpenAI ramps up developer push with more powerful models in its API 
    OpenAI launches AgentKit to help developers build and ship AI agents  OpenAI launches AgentKit to help developers build and ship AI agents 
    Okosix will show its biodegradable plastic at TechCrunch Disrupt 2025 Okosix will show its biodegradable plastic at TechCrunch Disrupt 2025

    Filed Under: Tech News Tagged With: “Plastic, 2025, biodegradable, Disrupt, Okosix, Show, TechCrunch

    eNews Extended

    Enter your Email to receive the latest promotional information from the Website

    Featured Post

    Texas pushes three-loss playoff debate to next level with third top-10 victory against Texas A&M Texas pushes three-loss playoff debate to next level with third top-10 victory against Texas A&M
    The Progression of Cam Ward The Progression of Cam Ward
    The Progression of Cam Ward The Progression of Cam Ward
    The Progression of Cam Ward The Progression of Cam Ward
    Glenville vs. Indian Valley live score, updates, highlights from OHSAA D-IV state semifinal game Glenville vs. Indian Valley live score, updates, highlights from OHSAA D-IV state semifinal game
    Avon vs. Walsh Jesuit live score, updates, highlights from OHSAA D-II state semifinal game Avon vs. Walsh Jesuit live score, updates, highlights from OHSAA D-II state semifinal game

    Laptop

    44.990.000đ
    Laptop LG Gram 2022 17Z90Q-G.AH76A5 (Core-i7 1260P/16GB/512GB/17″ WQXGA/Win 11/Xám)
    24.790.000đ
    Laptop LG Gram 2021 16ZD90P-G.AX54A5 (i5-1135G7/8GB RAM/512GB SSD/16″WQXGA/Dos/Trắng)
    14.590.000đ
    Laptop Acer Gaming Aspire 7 A715-42G-R4ST NH.QAYSV.004 (R5 5500U/8GB RAM/256GB SSD/15.6″FHD IPS/GTX1650 4GB/Win10) – Hàng chính hãng
    15.190.000đ
    Laptop Acer Aspire 3 A315-58G-50S4 (Core i5 1135G7/8GB RAM/512GB/15.6″FHD/MX350 2GB/Win 10/Bạc)
    21.990.000đ
    Laptop Acer Swift 5 SF514-55TA-59N4 NX.A6SSV.001 (i5-1135G7/16GB RAM/1TB SSD/14″FHD_Touch/Win10/Xanh) – Hàng chính hãng
    14.890.000đ
    Laptop Acer Aspire 5 A514-54-59QK (Core i5 1135G7/8GB RAM/512GB/14″FHD/Win 11/Vàng)

    Tech news

    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Microsoft buys another 100 MW of solar, this time in Japan Microsoft buys another 100 MW of solar, this time in Japan
    Microsoft buys another 100 MW of solar, this time in Japan Microsoft buys another 100 MW of solar, this time in Japan
    OpenAI ramps up developer push with more powerful models in its API  OpenAI ramps up developer push with more powerful models in its API 

    Fashion

    299.000đ
    QUẦN JEAN ỐNG RỘNG CẠP CAO, DÀI XẺ GẤU PHONG CÁCH J6
    99.000đ
    ÁO KHOÁC CARDIGAN MẶT CƯỜI NỮ CHẤT NỈ COTTON
    150.000đ
    ÁO KHOÁC HOODIE NAM NỮ PHỐI THEO PHONG CÁCH HÀN QUỐC FORM RỘNG HÌNH THÊU SIÊU ĐẸP CỰC CHẤT LƯỢNG HÀNG HOT TREND
    148.000đ
    QUẦN DÀI NỮ SUÔNG KẺ CARO
    148.000đ
    SET ĐẦM MẶC HAI KIỂU KÈM BÔNG CỔ MOCKING THÂN SAU(CÓ MÚT) MD126
    49.000đ
    ÁO THUN NỮ, ÁO PHÔNG UNISEX COTTON SU MÁT MẺ EDIE BAUER

    Recent post

    • Texas pushes three-loss playoff debate to next level with third top-10 victory against Texas A&M
    • “Squid Game” Actor Admits Co-star Burst Into Tears After Filming Explicit Scene With Him
    • The Progression of Cam Ward
    • The Progression of Cam Ward
    • The Progression of Cam Ward

    Tags

    2024 2025 About After Best BTS’s Channel College Fans First football Former From Game Goes Group highlights Idol Idols injury Korean KPop Latest League Live match More Netizens Over Popular Reactions Results Schedule score Sparks Star Stream Their Time Today” Trade Updates Viral Watch Week

    Calendar

    February 2024
    M T W T F S S
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
    « Jan   Mar »

    © Copyright 2026 · All Rights Reserved · Website Design By: www.tctshop.com