home.social

#connectwise — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #connectwise, aggregated by home.social.

fetched live
  1. ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security

    Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...

    Pulse ID: 6a722d8bdafe1dfae681f87b
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:20:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #ConnectWise #CyberSecurity #Encryption #HTML #ICS #InfoSec #Mac #MacOS #NET #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #SocialEngineering #Troll #VBS #Windows #Zoom #bot #AlienVault

  2. Imagine a trusted IT tool letting hackers intercept crucial data and swap out updates like tampered packages. What does this mean for the safety of your systems? Dive into the story behind ConnectWise Automate’s vulnerabilities and the rising threat in RMM security.

    thedefendopsdiaries.com/connec

    #connectwise
    #rmmsecurity
    #supplychainattack
    #cybersecurity2025
    #aitmattacks

  3. What a wonderful thing to find out while on vacation that my phone is blowing up because a news article about #ConnectWise published yesterday (bleepingcomputer.com/news/secu) referenced something I posted here in April (infosec.exchange/@threatresear). (Thanks, Bill ❤️ & @BleepingComputer)

  4. Nutzt wer #ConnectWise Produkte? Die wechseln die Zertifikate zum 10.6.2025, also updaten (wobei die Produkte noch nicht alle aktuell sind).

    borncity.com/blog/2025/06/09/c