Mass-Exploitation of ConnectWise CVE02024-1709

Опубликовано: 30 Август 2026
на канале: TrustedSec
541
14

Threat actors are exploiting ConnectWise CVE-2024-1709 across the internet to steal information and deploy malicious software. In this video, Director of Security Intelligence Carlos Perez goes over some of the challenges to quickly patch this vulnerability and how to start looking for IOCs of the attack, based on our experience observing the exploitation.

References:

https://www.huntress.com/blog/a-catas...

https://www.connectwise.com/company/t...

https://docs.connectwise.com/ConnectW...

Chapters:

00:00 Introduction
00:45 Timeline of Events
02:20 Actions to Take
03:37 ConnectWise Syslog Extension Gaps
03:53 Tradecraft in use by attackers
04:08 Dangers of possible malicious extension
06:03 Note for those using a MSP or MSSP