Blog / tag

A trivially exploited authentication bypass in ConnectWise ScreenConnect — requiring nothing more than appending a slash to a URL — hands attackers SYSTEM-level control over entire managed IT networks, and ransomware crews are already cashing in.

A perfect CVSS 10.0 vulnerability in Dell RecoverPoint for Virtual Machines ships with hard-coded Tomcat credentials that a Chinese-linked threat group has been exploiting since mid-2024 to deploy backdoors and ransomware.