<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: ConnectWise Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving ConnectWise.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT</title><link>https://thehackernews.com/2026/07/seo-poisoned-software-sites-abuse.html</link><guid isPermaLink="false">cst-43</guid><description>Unknown threat actors are distributing malicious installer archives through spoofed websites that mimic legitimate software tools. The campaign uses ScreenConnect remote access software to deploy AsyncRAT malware across multiple domains and languages. Kaspersky identified this as a large-scale operation targeting users seeking common applications like OBS Studio, DNS Jumper, DS4Windows, and Bandicam.</description><pubDate>Wed, 01 Jul 2026 17:53:06 GMT</pubDate></item><item><title>March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day</title><link>https://recordedfuture.com/blog/march-2026-cve-landscape</link><guid isPermaLink="false">cst-1981</guid><description>Insikt Group identified 31 high-impact vulnerabilities actively exploited in March 2026, with 29 rated as very critical. The affected products span major vendors including Cisco, Microsoft, Google, ConnectWise, Citrix, and others, with Microsoft and Apple accounting for approximately 32% of the total. Notable findings include the Interlock ransomware group exploiting a Cisco Firewall Management Center zero-day, the continued exploitation of a nine-year-old Hikvision vulnerability, and public proof-of-concept exploits available for 10 of the 31 vulnerabilities.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>How a Tax Search Leads to Kernel-Mode AV/EDR Kill</title><link>https://huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill</link><guid isPermaLink="false">cst-731</guid><description>Huntress identified a malvertising campaign themed around tax season that uses Google Ads and cloaking techniques to distribute rogue ScreenConnect remote access software. The attackers employ an undocumented Huawei driver to disable antivirus and endpoint detection and response (EDR) security tools at the kernel level.</description><pubDate>Thu, 19 Mar 2026 14:00:00 GMT</pubDate></item><item><title>Rogue RMMs: Common Social Engineering Tactics We Saw in 2025</title><link>https://huntress.com/blog/rogue-screenconnect-social-engineering-tactics-2025</link><guid isPermaLink="false">cst-769</guid><description>Researchers documented social engineering tactics used in attacks involving ScreenConnect remote monitoring and management (RMM) software throughout 2025, including lures referencing Social Security statements. The report details attack patterns using top-affected domains and associated malware hashes that attackers leveraged in campaigns.</description><pubDate>Wed, 31 Dec 2025 06:00:00 GMT</pubDate></item><item><title>SlashAndGrab ConnectWise ScreenConnect Vulnerability</title><link>https://huntress.com/blog/slashandgrab-the-connectwise-screenconnect-vulnerability-explained</link><guid isPermaLink="false">cst-956</guid><description>Huntress researchers identified a vulnerability in ConnectWise ScreenConnect and provided analysis and community support regarding the discovery. The article outlines how the vulnerability was found and Huntress's role in coordinating the response.</description><pubDate>Sat, 03 Aug 2024 20:24:06 GMT</pubDate></item><item><title>MSSQL to ScreenConnect | Huntress</title><link>https://huntress.com/blog/mssql-to-screenconnect</link><guid isPermaLink="false">cst-989</guid><description>Huntress has observed ongoing attacks against MSSQL server systems, identifying patterns across incidents including reuse of living-off-the-land binaries (LOLBins) and consistent IP addresses attributed to threat actors.</description><pubDate>Thu, 28 Mar 2024 00:00:00 GMT</pubDate></item><item><title>SlashAndGrab | Huntress</title><link>https://huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708</link><guid isPermaLink="false">cst-1000</guid><description>Security researchers at Huntress have documented post-exploitation activity following the ScreenConnect vulnerabilities (CVE-2024-1709 and CVE-2024-1708). The report details observed adversary tactics, tradecraft, and techniques deployed after initial compromise through these flaws.</description><pubDate>Fri, 23 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Detection Guidance for ConnectWise CWE-288 | Huntress</title><link>https://huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2</link><guid isPermaLink="false">cst-1001</guid><description>Huntress has published detection guidance for a critical authentication bypass vulnerability (CWE-288) affecting ConnectWise. The vulnerability requires patching to version 23.9.8 or later to remediate the exposure.</description><pubDate>Tue, 20 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Bitter Pill | Huntress</title><link>https://huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack</link><guid isPermaLink="false">cst-1023</guid><description>Huntress discovered unauthorized access incidents at multiple healthcare organizations where a threat actor exploited ScreenConnect, a remote access tool, to gain entry to systems. The investigation revealed the compromise affected several healthcare facilities, highlighting the use of legitimate remote access software as an attack vector.</description><pubDate>Thu, 09 Nov 2023 00:00:00 GMT</pubDate></item><item><title>Overblown Claims of Vulnerabilities, Exploits, &amp; Severity | Huntress</title><link>https://huntress.com/blog/clearing-the-air-overblown-claims-of-vulnerabilities-exploits-severity</link><guid isPermaLink="false">cst-1098</guid><description>Huntress has raised concerns about the severity claims and exploitation allegations regarding ConnectWise Control vulnerabilities, stating that the threat level presented by a security researcher appears overstated. The company's analysis suggests a more measured risk assessment is warranted for these vulnerabilities.</description><pubDate>Wed, 14 Dec 2022 00:00:00 GMT</pubDate></item><item><title>ConnectWise/R1Soft RCE &amp; Supply Chain Risks | Huntress</title><link>https://huntress.com/blog/critical-vulnerability-disclosure-connectwise-r1soft-server-backup-manager-remote-code-execution-supply-chain-risks</link><guid isPermaLink="false">cst-1107</guid><description>Huntress confirmed an authentication bypass and sensitive file disclosure vulnerability in the ZK Java framework used by ConnectWise R1Soft Server Backup Manager SE. The flaw allows unauthorized access and exposure of sensitive data in the backup management software. This represents a supply chain security risk affecting organizations relying on this widely used backup solution.</description><pubDate>Mon, 31 Oct 2022 00:00:00 GMT</pubDate></item><item><title>Validating the Bishop Fox Findings in ConnectWise Control | Huntress</title><link>https://huntress.com/blog/validating-the-bishop-fox-findings-in-connectwise-control</link><guid isPermaLink="false">cst-1224</guid><description>Huntress has validated eight vulnerabilities in ConnectWise Control ranging from low to high severity, based on findings initially disclosed by Bishop Fox. The validation confirms the scope and nature of the security issues in the remote access tool.</description><pubDate>Wed, 22 Jan 2020 00:00:00 GMT</pubDate></item><item><title>CVE-2017-18362: SQL Injection in ManagedITSync Integration | Huntress</title><link>https://huntress.com/blog/cve-2017-18362-arbitrary-sql-injection-in-mangeditsync-integration-ba142ff24f4d</link><guid isPermaLink="false">cst-1231</guid><description>A SQL injection vulnerability, CVE-2017-18362, was identified in the ConnectWise ManagedITSync integration, which synchronizes data between ConnectWise Manage PSA and Kaseya VSA RMM platforms. The flaw was disclosed in late 2017 and could allow attackers to execute arbitrary SQL commands against affected systems.</description><pubDate>Fri, 08 Feb 2019 14:00:00 GMT</pubDate></item><item><title>Huntress Wins ConnectWise IT Nation Partner’s Choice Award!</title><link>https://huntress.com/blog/huntress-wins-connectwise-it-nation-partners-choice-award-c8e06f9d6e10</link><guid isPermaLink="false">cst-1245</guid><description>Huntress received the ConnectWise IT Nation Partner's Choice Award, recognizing its Managed Detection and Response (MDR) service at the industry conference. The award reflects recognition from managed service providers (MSPs) attending the event.</description><pubDate>Mon, 21 Nov 2016 18:00:00 GMT</pubDate></item></channel></rss>