Skip to main content

Tag: screenconnect

9 articles

Small business office with computers and networking equipment, one laptop screen blank and out of focus.

CISA Warns of Active ScreenConnect Exploit in Ongoing Attacks

Beware: hackers are actively exploiting a critical flaw in ConnectWise ScreenConnect, allowing them to transfer files and execute code on vulnerable systems without permission. The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning, ordering federal agencies to secure affected systems within three days.

Analyst 207
Network equipment and servers in a data center with a router on a rack.

CISA Flags Actively Exploited Flaws in Artifactory, ScreenConnect, RouterOS

CISA has flagged five severe vulnerabilities in popular software, including JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, that are being actively exploited by attackers to gain unauthorized control. These flaws are now added to CISA's Known Exploited Vulnerabilities catalog, serving as a wake-up call for operators to prioritize patching before they become the next target.

Analyst 207
Technical workspace with computer workstations and network equipment, one laptop showing a remote desktop interface.

Rogue ScreenConnect Clients Propagate VBScript Worm

A sneaky VBScript worm is spreading rapidly through new ScreenConnect connections, launching a four-stage attack chain that wreaks havoc on unsuspecting hosts. This malicious chain was triggered by three distinct initial access routes, including tech-support scams, phishing, and fake refund forms.

Analyst 207
Empty remote access support workstation with laptop and monitor on a clean desk in a typical office setting.

ConnectWise Discloses New ScreenConnect Flaw, Offers Mitigations

ConnectWise has uncovered a new vulnerability in its ScreenConnect platform that affects file transfer behavior in Remote Access Support and Access sessions, and is providing temporary mitigations until a patch is released later this week. To protect your systems, apply these manual workarounds now.

Analyst 207
Cluttered office cubicle with desktop computer and suspicious email nearby.

Hackers Exploit Faronics Tool to Install ScreenConnect on Compromised Endpoints

Hackers are using clever phishing lures disguised as invoices and business files to trick victims into installing malicious software, with over 457 endpoints compromised in just a month. They exploited a legitimate endpoint-management tool to gain remote control and install additional remote-access software.

Analyst 207
Office setting with computers, papers, and a blurred monitor displaying a fake software update prompt.

Malware Campaigns Exploit Software Updates for ScreenConnect Installation

Cyber attackers have launched a sneaky malware campaign, dubbed SMOKE#SCREEN, that uses fake software updates and social-engineering tricks to install ConnectWise ScreenConnect on victims' devices. The campaign relies on clever tactics like phishing emails and fake Adobe and Zoom updates to gain access to systems.

Analyst 207
Cluttered office desk with laptop, papers, and storage devices.

Kaspersky Exposes AsyncRAT Campaign Using ScreenConnect

Malicious actors have launched a massive campaign using fake software downloads to spread the AsyncRAT malware, disguising it as popular utilities like OBS Studio and DNS Jumper. Kaspersky uncovered over 90 spoofed domains in 10 languages, hinting at a sophisticated and widespread threat.

Analyst 207
User downloads software from computer in home office, with fake website and zip file in foreground.

ScreenConnect Exploited in Large-Scale Campaign Disguised as Freeware

Cybercriminals have launched a massive campaign disguising a malicious ScreenConnect installer as freeware, tricking users into downloading it from over 90 fake websites in 10 languages. The scam starts with a bogus OBS Studio download that secretly installs the ScreenConnect utility, ultimately delivering a nasty AsyncRAT payload.

Analyst 207
Modern IT infrastructure room with servers, networking equipment, and exposed cables, with a window showing daylight in the…

CISA Flags Actively Exploited ConnectWise, Windows Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged two major vulnerabilities, including a critical flaw in ConnectWise ScreenConnect and a Microsoft Windows Shell bug, as actively exploited by hackers. These flaws could allow attackers to execute remote code, access confidential data, and compromise critical systems.

Analyst 207