Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

The features powered by Gemini in Google Workspace that are worth using

Uber taps Rivian to build robotaxis in deal worth up to $1.25 billion

Why Wall Street Didn’t Win Nvidia’s Big Conference

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Why Wall Street Didn’t Win Nvidia’s Big Conference

    22 March 2026

    New court filing reveals Pentagon told Anthropic the two sides were nearly aligned — a week after Trump declared his relationship

    21 March 2026

    Microsoft is retiring some of the Copilot AI bloat on Windows

    21 March 2026

    The best AI investment may be in energy technology

    20 March 2026

    Bot traffic to overtake human traffic by 2027, says Cloudflare CEO

    20 March 2026
  • Apps

    The features powered by Gemini in Google Workspace that are worth using

    22 March 2026

    Meta finally decides not to close Horizon Worlds in VR

    22 March 2026

    DoorDash Launches New ‘Tasks’ App That Pays Couriers to Submit Videos to Train AI

    21 March 2026

    Google is introducing a new way for users to download Android apps that still protects against fraud

    21 March 2026

    Meta launches new AI content enforcement systems while reducing reliance on third-party vendors

    20 March 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026

    Nominations for the Startup Battlefield 200 are still open

    19 March 2026

    Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

    17 March 2026

    Fuse raises $25M to disrupt legacy loan origination systems used by US credit unions

    16 March 2026

    India neobank Fi removes banking services on its platform

    11 March 2026
  • Hardware

    Amazon is working on a new smartphone with Alexa at its core, the report says

    20 March 2026

    CEO Carl Pei says nothing about smartphone apps disappearing as they’re replaced by artificial intelligence agents

    18 March 2026

    MacBook Neo, AirPods Max 2, iPhone 17e and everything else Apple announced this month

    18 March 2026

    Oura enters India’s smart ring market with Ring 4

    17 March 2026

    Apple quietly launches AirPods Max 2

    17 March 2026
  • Media & Entertainment

    Tubi joins forces with popular TikTokers to create original streaming content

    19 March 2026

    Patreon CEO calls AI companies’ fair use argument ‘bogus’, says creators should be paid

    18 March 2026

    Meet Vurt, the first mobile streaming platform for indie filmmakers embracing vertical video

    18 March 2026

    BuzzFeed debuts AI applications for new revenue

    17 March 2026

    Facebook makes it easy for creators to report copycats

    14 March 2026
  • Security

    Delve accused of misleading customers with ‘false compliance’

    21 March 2026

    The US accuses the Iranian government of operating a hacktivist group that hacked the Stryker

    20 March 2026

    CISA Urges Companies to Secure Microsoft Intune Systems After Hackers Mass Wipe Stryker Devices

    20 March 2026

    FBI seizes websites of pro-Iranian hacker group after devastating Stryker attack

    19 March 2026

    FBI is buying location data to track US citizens, director confirms

    19 March 2026
  • Startups

    Microsoft hires Sequoia-backed AI collaboration platform team Cove

    21 March 2026

    Consumer-focused privacy firm Cloaked raises $375 million as it expands into the enterprise

    20 March 2026

    Tools for founders to navigate and move past conflicts

    20 March 2026

    Anori, Alphabet’s new X spinout, faces one of the world’s most expensive bureaucratic nightmares

    19 March 2026

    This startup wants to make enterprise software more like a prompt

    19 March 2026
  • Transportation

    Uber taps Rivian to build robotaxis in deal worth up to $1.25 billion

    22 March 2026

    Federal authorities intensify investigation into Tesla’s Full Self-Driving (Supervised) software

    21 March 2026

    Cyberattack on vehicle breathalyzer company leaves drivers stranded in US

    21 March 2026

    Arc expands into electric commercial and defense vessels with $50M raise

    20 March 2026

    Rivian Sacrifices 2027 Profit Target to Push Deeper into Autonomy

    20 March 2026
  • Venture

    AI startups are eating up the venture industry, and the returns, so far, are good

    21 March 2026

    Sequen raised $16 million to bring TikTok-style personalization technology to any consumer company

    19 March 2026

    AI ‘boys club’ could widen wealth gap for women, says Rana el Kaliouby

    18 March 2026

    Billionaires made a promise – now some want to leave

    17 March 2026

    Antonio Gracias Says He Longs For ‘Pre-Entropic’ Startups – Those Built To Survive Chaos

    17 March 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Hackers Exploit ConnectWise Flaws to Deploy LockBit Ransomware, Security Experts Warn
Security

Hackers Exploit ConnectWise Flaws to Deploy LockBit Ransomware, Security Experts Warn

techtost.comBy techtost.com24 February 202403 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Hackers Exploit Connectwise Flaws To Deploy Lockbit Ransomware, Security Experts
Share
Facebook Twitter LinkedIn Pinterest Email

Security experts are warning that a pair of high-risk flaws in a popular remote access tool are being exploited by hackers to develop LockBit ransomware – days after authorities announced they had busted a notorious Russian-linked cybercrime gang.

Researchers at cybersecurity firms Huntress and Sophos told TechCrunch on Thursday that both had observed LockBit attacks after exploiting a set of vulnerabilities affecting ConnectWise ScreenConnect, a widely used remote access tool used by IT technicians to provide remote technical support on client systems.

Defects consist of two errors. CVE-2024-1709 is an authentication bypass vulnerability considered “annoyingly easy” to exploit that has been in active exploitation since Tuesday, shortly after ConnectWise released security updates and urged organizations to patch. The other bug, CVE-2024-1708, is a path traversal vulnerability that can be used in conjunction with the other bug to remotely install malicious code on an affected system.

In a post on Mastodon On Thursday, Sophos said it had observed “several LockBit attacks” exploiting ConnectWise vulnerabilities.

“Two things of interest here: first, as noted by others, ScreenConnect vulnerabilities are actively exploited in the wild. Second, despite the enforcement operation against LockBit, it appears that some affiliates are still operating,” Sophos said, referring to the enforcement operation earlier this week that claimed to have taken down LockBit’s infrastructure.

Christopher Budd, director of threat research at Sophos X-Ops, told TechCrunch via email that the company’s observations show that, “ScreenConnect was the start of the observed execution chain, and the version of ScreenConnect used was vulnerable.”

Max Rogers, senior director of threat operations at Huntress, told TechCrunch that the cybersecurity firm has also seen the development of LockBit ransomware in attacks that exploit the ScreenConnect vulnerability.

Rogers said Huntress has seen LockBit ransomware deployed on customer systems spanning a range of industries, but declined to name the customers affected.

The LockBit ransomware infrastructure was seized earlier this week as part of a sweeping international law enforcement operation led by the UK’s National Crime Agency. The operation took down LockBit’s public websites, including the dark leak site, which the gang used to post data stolen from victims. The leak site now hosts information leaked by the UK-led firm that reveals LockBit’s features and functionality.

The operation, known as “Operation Cronos,” also saw the takedown of 34 servers across Europe, the United Kingdom, and the United States, the seizure of more than 200 cryptocurrency wallets, and the arrest of two alleged LockBit members in Poland and Ukraine.

“We can’t perform [the ransomware attacks abusing the ConnectWise flaws] directly to the larger LockBit group, but it’s clear that LockBit has a large reach that spans tools, various affiliate groups, and offshoots that haven’t been completely wiped out even with the big takedown by law enforcement,” Rogers told TechCrunch via e-mail.

When asked if the growth of ransomware was something ConnectWise was also noticing internally, ConnectWise’s chief information security officer Patrick Beggs told TechCrunch that “that’s not something we’re seeing today.”

It remains unknown how many ConnectWise ScreenConnect users have been affected by this vulnerability, and ConnectWise declined to provide numbers. The company’s website claims that the organization provides remote access technology to more than one million small and medium-sized businesses.

According to the Shadowserver Foundation, a nonprofit organization that collects and analyzes data on malicious Internet activity, the ScreenConnect flaws are “widely exploited.” The nonprofit organization said Thursday in a post on Xformerly of Twitter, that so far it had observed 643 IP addresses exploiting the vulnerabilities — adding that more than 8,200 servers remain vulnerable.

binders ConnectWise Deploy experts exploit flaws hackers lockbit ransomware security vulnerability Warn
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTechstars CEO defends changes, says physical presence in a city not necessary for investment
Next Article Humane pushes Ai Pin ship date to mid-April
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Delve accused of misleading customers with ‘false compliance’

21 March 2026

The US accuses the Iranian government of operating a hacktivist group that hacked the Stryker

20 March 2026

CISA Urges Companies to Secure Microsoft Intune Systems After Hackers Mass Wipe Stryker Devices

20 March 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

The features powered by Gemini in Google Workspace that are worth using

22 March 2026

Uber taps Rivian to build robotaxis in deal worth up to $1.25 billion

22 March 2026

Why Wall Street Didn’t Win Nvidia’s Big Conference

22 March 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Amid legal turmoil, Kalshi is temporarily banned in Nevada

20 March 2026

Nominations for the Startup Battlefield 200 are still open

19 March 2026

Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

17 March 2026
Startups

Microsoft hires Sequoia-backed AI collaboration platform team Cove

Consumer-focused privacy firm Cloaked raises $375 million as it expands into the enterprise

Tools for founders to navigate and move past conflicts

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.