daily cyber × ai intelligence

index

tagged

[connectwise]

2 editions · 2 items

September 15, 2026

  • ScreenConnect exploitation is now documented as worm-like. Huntress first saw attacks on August 20 in which social-engineered, modified clients automatically pushed scripts into newly connected sessions, SecurityWeek reports. CVE-2026-84869 affects clients before 26.6.5, not servers; ConnectWise says operators must reinstall host clients and update access agents after upgrading. (earlier coverage) · Exploitation & Vulnerability Research

in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents

September 8, 2026

  • ConnectWise ScreenConnect has an unpatched flaw in file-transfer behaviour affecting both cloud and on-prem, with no CVE assigned and a fix promised later this week. The interim mitigation is to deselect the TransferFiles (or legacy TransferFilesInSession) scoped permission on every role and session group. Shadowserver tracks nearly 6,000 internet-exposed instances (BleepingComputer). Separately, Huntress detailed the worm-like rogue-client activity from three unrelated August incidents: a four-stage VBScript chain (1.vbs4.vbs) where stage one profiles RAM, checks for existing ScreenConnect installs and enumerates Cisco AMP, CrowdStrike, Huntress, Malwarebytes, SentinelOne, Sophos and Symantec into a three-bit state variable in %TEMP%\value.txt (The Hacker News, earlier coverage). · Vulnerabilities & Exploits

in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited