Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Superhuman bets on redesigned smart ring to win back US market after Oura controversy

Dive into Boston’s startup ecosystem at Founder Summit 2026 | TechCrunch

Anthropic CEO stands firm as Pentagon deadline looms

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Anthropic CEO stands firm as Pentagon deadline looms

    27 February 2026

    Jack Dorsey just halved the size of Block’s employee base — and he says your company is next

    27 February 2026

    Salesforce CEO Marc Benioff: This isn’t our first SaaSpocalypse

    26 February 2026

    Gushwork is betting on AI prospecting for leads — and the first results are showing

    26 February 2026

    India’s AI boom prompts companies to trade short-term revenue for users

    25 February 2026
  • Apps

    Bumble adds AI photo feedback and profile guidance tools

    27 February 2026

    Threads is testing a shortcut to quickly start DM conversations

    27 February 2026

    Instagram now alerts parents if their teen is looking for suicide or self-harm content

    26 February 2026

    Snapchat announces ‘The Snappys’, its first creator awards show

    26 February 2026

    Discord delays global rollout of age verification after backlash

    25 February 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    3 days left: Save up to $680 on your ticket to Disrupt 2026

    25 February 2026

    More startups surpass $10M ARR in 3 months than ever before

    24 February 2026

    Stripe, PayPal Ventures Bet on India’s Xflow to Fix Cross-Border B2B Payments

    24 February 2026

    InScope raises $14.5M to solve financial reporting pain

    20 February 2026

    OpenAI deepens India push with Pine Labs fintech partnership

    19 February 2026
  • Hardware

    Everything announced at Samsung’s Galaxy Unpacked event, including S26 smartphones, privacy screen and more

    26 February 2026

    Samsung introduces new display technology that adds a privacy screen to apps and notifications

    25 February 2026

    Oura launches a proprietary AI model focused on women’s health

    25 February 2026

    Spotify and Liquid Death are releasing a limited-edition speaker shaped like a … container?

    24 February 2026

    5 days left to lock in the lowest Disrupt 2026 rates

    23 February 2026
  • Media & Entertainment

    Netflix pulls out of bid for Warner Bros. Discovery, giving studios, HBO and CNN to Ellison-owned Paramount

    27 February 2026

    Book the best deals for Disrupt 2026 | TechCrunch

    26 February 2026

    Americans now listen to podcasts more often than talk radio, study shows

    25 February 2026

    Music producer ProducerAI joins Google Labs

    25 February 2026

    YouTube boosts its $7.99/month Lite subscription with offline downloads and background playback

    24 February 2026
  • Security

    Cisco Says Hackers Are Exploiting Critical Flaw To Break Into Large Customer Networks By 2023

    26 February 2026

    US cybersecurity agency CISA reportedly in dire straits amid Trump cuts and layoffs

    26 February 2026

    Treasury sanctions Russian zero-day broker accused of buying holdings stolen from US defense contractor

    25 February 2026

    Former L3Harris Trenchant boss jailed for selling hacking tools to Russian broker

    25 February 2026

    Marquis Sues Firewall Provider SonicWall, Claims Security Flaws With Firewall Backup Led To Ransomware Attack

    24 February 2026
  • Startups

    Superhuman bets on redesigned smart ring to win back US market after Oura controversy

    27 February 2026

    Trace raises $3 million to solve AI agent adoption in the enterprise

    27 February 2026

    How to avoid bad hires in early stage startups

    26 February 2026

    Apply to take the stage at Founder Summit 2026

    26 February 2026

    Ukrainian startups continue to build | TechCrunch

    25 February 2026
  • Transportation

    Self-driving truck startup Einride raises $113M PIPE ahead of public debut

    27 February 2026

    It’s time to pull the plug on plug-in hybrids

    26 February 2026

    Harbinger acquires self-driving company Phantom AI

    26 February 2026

    Waymo robotaxis are now operating in 10 US cities

    25 February 2026

    Self-driving tech startup Wayve raises $1.2 billion from Nvidia, Uber and three automakers

    25 February 2026
  • Venture

    Dive into Boston’s startup ecosystem at Founder Summit 2026 | TechCrunch

    27 February 2026

    A VC and some big-name developers are trying to solve the open source funding problem, permanently

    27 February 2026

    Y Combinator grad and AI insurance brokerage Harper raises $47 million

    26 February 2026

    Anthropic acquires AI startup Vercept after Meta indicts one of its founders

    26 February 2026

    Last 4 days to save up to $680 on your Disrupt 2026 Pass

    25 February 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Hackers Exploit ConnectWise Flaws to Deploy LockBit Ransomware, Security Experts Warn
Security

Hackers Exploit ConnectWise Flaws to Deploy LockBit Ransomware, Security Experts Warn

techtost.comBy techtost.com24 February 202403 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Hackers Exploit Connectwise Flaws To Deploy Lockbit Ransomware, Security Experts
Share
Facebook Twitter LinkedIn Pinterest Email

Security experts are warning that a pair of high-risk flaws in a popular remote access tool are being exploited by hackers to develop LockBit ransomware – days after authorities announced they had busted a notorious Russian-linked cybercrime gang.

Researchers at cybersecurity firms Huntress and Sophos told TechCrunch on Thursday that both had observed LockBit attacks after exploiting a set of vulnerabilities affecting ConnectWise ScreenConnect, a widely used remote access tool used by IT technicians to provide remote technical support on client systems.

Defects consist of two errors. CVE-2024-1709 is an authentication bypass vulnerability considered “annoyingly easy” to exploit that has been in active exploitation since Tuesday, shortly after ConnectWise released security updates and urged organizations to patch. The other bug, CVE-2024-1708, is a path traversal vulnerability that can be used in conjunction with the other bug to remotely install malicious code on an affected system.

In a post on Mastodon On Thursday, Sophos said it had observed “several LockBit attacks” exploiting ConnectWise vulnerabilities.

“Two things of interest here: first, as noted by others, ScreenConnect vulnerabilities are actively exploited in the wild. Second, despite the enforcement operation against LockBit, it appears that some affiliates are still operating,” Sophos said, referring to the enforcement operation earlier this week that claimed to have taken down LockBit’s infrastructure.

Christopher Budd, director of threat research at Sophos X-Ops, told TechCrunch via email that the company’s observations show that, “ScreenConnect was the start of the observed execution chain, and the version of ScreenConnect used was vulnerable.”

Max Rogers, senior director of threat operations at Huntress, told TechCrunch that the cybersecurity firm has also seen the development of LockBit ransomware in attacks that exploit the ScreenConnect vulnerability.

Rogers said Huntress has seen LockBit ransomware deployed on customer systems spanning a range of industries, but declined to name the customers affected.

The LockBit ransomware infrastructure was seized earlier this week as part of a sweeping international law enforcement operation led by the UK’s National Crime Agency. The operation took down LockBit’s public websites, including the dark leak site, which the gang used to post data stolen from victims. The leak site now hosts information leaked by the UK-led firm that reveals LockBit’s features and functionality.

The operation, known as “Operation Cronos,” also saw the takedown of 34 servers across Europe, the United Kingdom, and the United States, the seizure of more than 200 cryptocurrency wallets, and the arrest of two alleged LockBit members in Poland and Ukraine.

“We can’t perform [the ransomware attacks abusing the ConnectWise flaws] directly to the larger LockBit group, but it’s clear that LockBit has a large reach that spans tools, various affiliate groups, and offshoots that haven’t been completely wiped out even with the big takedown by law enforcement,” Rogers told TechCrunch via e-mail.

When asked if the growth of ransomware was something ConnectWise was also noticing internally, ConnectWise’s chief information security officer Patrick Beggs told TechCrunch that “that’s not something we’re seeing today.”

It remains unknown how many ConnectWise ScreenConnect users have been affected by this vulnerability, and ConnectWise declined to provide numbers. The company’s website claims that the organization provides remote access technology to more than one million small and medium-sized businesses.

According to the Shadowserver Foundation, a nonprofit organization that collects and analyzes data on malicious Internet activity, the ScreenConnect flaws are “widely exploited.” The nonprofit organization said Thursday in a post on Xformerly of Twitter, that so far it had observed 643 IP addresses exploiting the vulnerabilities — adding that more than 8,200 servers remain vulnerable.

binders ConnectWise Deploy experts exploit flaws hackers lockbit ransomware security vulnerability Warn
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTechstars CEO defends changes, says physical presence in a city not necessary for investment
Next Article Humane pushes Ai Pin ship date to mid-April
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Cisco Says Hackers Are Exploiting Critical Flaw To Break Into Large Customer Networks By 2023

26 February 2026

US cybersecurity agency CISA reportedly in dire straits amid Trump cuts and layoffs

26 February 2026

Treasury sanctions Russian zero-day broker accused of buying holdings stolen from US defense contractor

25 February 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Superhuman bets on redesigned smart ring to win back US market after Oura controversy

27 February 2026

Dive into Boston’s startup ecosystem at Founder Summit 2026 | TechCrunch

27 February 2026

Anthropic CEO stands firm as Pentagon deadline looms

27 February 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

3 days left: Save up to $680 on your ticket to Disrupt 2026

25 February 2026

More startups surpass $10M ARR in 3 months than ever before

24 February 2026

Stripe, PayPal Ventures Bet on India’s Xflow to Fix Cross-Border B2B Payments

24 February 2026
Startups

Superhuman bets on redesigned smart ring to win back US market after Oura controversy

Trace raises $3 million to solve AI agent adoption in the enterprise

How to avoid bad hires in early stage startups

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.