Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ConnectWise warns of new ScreenConnect flaw without patch

    September 7, 2026

    Hackers exploit new MikroTik RouterOS flaws to hijack routers

    September 7, 2026

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    September 7, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»ConnectWise warns of new ScreenConnect flaw without patch
    News

    ConnectWise warns of new ScreenConnect flaw without patch

    adminBy adminSeptember 7, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    ConnectWise

    ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week.

    ScreenConnect is an on-premises or cloud-hosted remote access platform typically used by managed service providers (MSPs), IT departments, and support teams for troubleshooting, patching, and system maintenance.

    The security flaw affects both cloud and on-premises deployments, and it has not yet received a CVE ID for easy tracking.

    “ConnectWise has identified an issue affecting file transfer behavior in ScreenConnect® Remote Access Support and Access sessions,” the company said in a security advisory issued on Thursday.

    While ConnectWise is still working on a permanent fix for this security issue, it provided temporary mitigation steps designed to help block potential attacks.

    This requires IT administrators to go through the following steps:

    1. Log in to the ScreenConnect Administration page.
    2. Go to Administration > Security > Roles.
    3. Edit user roles and check session groups (in bold)with permissions assigned to them.
    4. In the Scoped Permissions window, deselect the TransferFiles permission (or TransferFilesInSession for legacy) for each session group.
    5. Save changes and repeat for all roles.

    Internet security watchdog Shadowserver currently tracks nearly 6,000 ScreenConnect instances exposed online. However, there is no information regarding how many of these systems are honeyposts or have already been secured.

    Internet-exposed ScreenConnect instances
    Internet-exposed ScreenConnect instances (Shadowserver)

    ​ScreenConnect vulnerabilities are often targeted in the wild by both financially-motivated and state-backed hacking groups.

    For instance, in 2024, ransomware gangs and the Kimsuky North Korean APT hacking group exploited another ScreenConnect flaw (tracked as CVE-2024-1709) to drop malware on vulnerable systems.

    Last year, ConnectWise disclosed that suspected state-sponsored hackers breached its systems via a high-severity ViewState code injection bug (CVE-2025-3935) and gained access to the cloud-based instances of a limited number of customers.

    Earlier this year, in March, ConnectWise also addressed a ScreenConnect cryptographic signature verification vulnerability (tracked as CVE-2026-3564) that could allow attackers to hijack unpatched instances.

    Since February 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three ScreenConnect vulnerabilities to its catalog of actively exploited flaws, two of which were also abused in ransomware attacks.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHackers exploit new MikroTik RouterOS flaws to hijack routers
    admin
    • Website

    Related Posts

    News

    Hackers exploit new MikroTik RouterOS flaws to hijack routers

    September 7, 2026
    News

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    September 7, 2026
    News

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    September 7, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202678 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202678 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    ConnectWise warns of new ScreenConnect flaw without patch

    September 7, 2026

    Hackers exploit new MikroTik RouterOS flaws to hijack routers

    September 7, 2026

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    September 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.