CuraSec

tag: Screenconnect · 2 items

2026-09-07 · The Hacker News · source ↗ #screenconnect#rmm-abuse#vbscript-malware
  • Engineer — Act: Three confirmed incidents show worm-like spread via ScreenConnect to newly connected hosts — if you run ScreenConnect, audit your relay configuration for unauthorized clients and review logs for unexpected new-host onboarding activity since the worm spreads automatically on connection.
  • SOC/IR — Act: Hunt for VBScript execution chains spawned from ScreenConnect parent processes across your estate, and sweep RMM logs for abnormal new-client connection events; initial access spans tech-support scam lures, phishing MSIs, and at least one other vector, so assume diverse entry points.
  • Leader — Plan: RMM tool abuse as a worm vector is a growing pattern — use this quarter to review governance of ScreenConnect and similar remote-access tools (access restrictions, audit logging, approved-relay allowlists) before an incident forces the conversation.
  • Engineer — Act: ScreenConnect is a high-value exploitation target with a documented history of rapid weaponization; apply ConnectWise’s published temporary mitigations now and schedule patch deployment as soon as it releases later this week.
  • SOC/IR — Plan: No active exploitation or IOCs yet, but ScreenConnect has been abused repeatedly as an initial-access vector; build or tune detections for anomalous ScreenConnect session activity before exploitation emerges.
  • Leader — Plan: Confirm whether ScreenConnect is in your environment, verify mitigations have been applied by your team, and track the patch release this week — ScreenConnect flaws have historically triggered rapid, widespread exploitation that can prompt customer inquiries.