Image: Midjourney The Black Basta and Bl00dy ransomware gangs have joined widespread attacks targeting ScreenConnect servers unpatched against a maximum severity authentication bypass vulnerability. This critical flaw (CVE-2024-1709) allows attackers to create admin accounts on Internet-exposed servers, delete all other users, and take over any vulnerable instance. CVE-2024-1709 has been under active exploitation since last Tuesday, one day after ConnectWise released security updates and proof-of-concept exploits were released by several cybersecurity companies. Last week, ConnectWise also fixed a high-severity path traversal vulnerability (CVE-2024-1708) that can only be abused by threat actors with high privileges. The company removed all license restrictions last week so customers with expired licenses can secure their servers from ongoing attacks given that these two security bugs impact all ScreenConnect versions. On Thursday, CISA also added CVE-2024-1709 to its Known Exploited Vulnerabilities Catalog, ordering U.S. federal agencies to secure their servers by February 29. Shadowserver says that CVE-2024-1709 is now widely exploited in attacks, with dozens of IPs targeting servers exposed online, while Shodan currently tracks over 10,000 ScreenConnect servers (only 1,559 running the ScreenConnect 23.9.8 patched version). While analyzing these ongoing attacks, Trend Micro discovered that the Black Basta and Bl00dy ransomware gangs have also started exploiting the ScreenC...
Black Basta, Bl00dy ransomware gangs join ScreenConnect attacks
BleepingComputer
·Sergiu Gatlan
·Published Feb 27, 2024
·Updated
Affected Software
2 affected components
ConnectWise ScreenConnect
ConnectWise ScreenConnect=23.9.8
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses attacks by the Black Basta and Bl00dy ransomware gangs targeting unpatched ScreenConnect servers.
2
What security implications are discussed in the article?
The article highlights a critical authentication bypass vulnerability (CVE-2024-1709) that is being exploited in these attacks.
3
What products or software are affected by these attacks?
The attacks specifically affect ConnectWise ScreenConnect servers, especially version 23.9.8.
4
Who are the threat actors mentioned in the article?
The article names the Black Basta and Bl00dy ransomware gangs as the threat actors involved in the attacks.
5
What is the severity level of the vulnerability mentioned in the article?
The CVE-2024-1709 vulnerability is classified as a maximum severity authentication bypass flaw.