WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Vulnerability Awareness – Exploitation Broadens in ConnectWise ScreenConnect Flaws
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Vulnerability Awareness – Exploitation Broadens in ConnectWise ScreenConnect Flaws

Author: Chase Snow

Created: Thursday, February 29, 2024 - 17:51

Categories: Cybersecurity, Security Preparedness

Two recently resolved vulnerabilities in ConnectWise ScreenConnect, tracked as CVE-2024-1709 and CVE-2024-1708 (CVSS scores of 10 and 8.4, respectively) are being exploited by more and more threat actors. This greater interest among varied threat actors is broadening the threat and escalating urgency of remediation. Affected versions include ScreenConnect 23.9.7 and earlier versions. Patches were announced by ConnectWise on February 19, yet they have later warned of ongoing exploitation. The issue is further exacerbated by the ease at which threat actors can exploit this vulnerability.

WaterISAC is sharing this information for awareness and urges members to apply the relevant patches if affected versions of ConnectSecure are being used. For more information, access Security Week.

Additional Resources:

  • Think Your ScreenConnect Server Is Hacked? Here’s What To Look For | Huntress
  • SlashAndGrab: ScreenConnect Post-Exploitation in the Wild | Huntress
  • SlashAndGrab: The ConnectWise ScreenConnect Vulnerability Explained | Huntress
  • Threat Actor Groups, Including Black Basta, are Exploiting Recent ScreenConnect Vulnerabilities | Trendmicro
  • Remediation and Hardening Guide for ConnectWise ScreenConnect Vulnerabilities | Mandiant
  • ScreenConnect flaws exploited to deliver all kinds of malware | Help Net Security
  • Exclusive: Cyberattack on Change Healthcare was an exploit of the ConnectWise flaw | SC Media

Related Resources

Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) EPA to Conduct 2026 National Cyber Drill Focused on Operating Without Telecommunications and Internet Connectivity

Jun 4, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar