By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: ConnectWise Hit by Cyberattack; Nation-State Actor Suspected in Targeted Breach
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > ConnectWise Hit by Cyberattack; Nation-State Actor Suspected in Targeted Breach
Computing

ConnectWise Hit by Cyberattack; Nation-State Actor Suspected in Targeted Breach

News Room
Last updated: 2025/06/08 at 12:15 PM
News Room Published 8 June 2025
Share
SHARE

May 30, 2025Ravie LakshmananVulnerability / Data Breach

ConnectWise, the developer of remote access and support software ScreenConnect, has disclosed that it was the victim of a cyber attack that it said was likely perpetrated by a nation-state threat actor.

“ConnectWise recently learned of suspicious activity within our environment that we believe was tied to a sophisticated nation-state actor, which affected a very small number of ScreenConnect customers,” the company said in a brief advisory on May 28, 2025.

The company said it has engaged the services of Google Mandiant to conduct a forensic probe into the incident and that it has notified all affected customers. The incident was first reported by CRN.

However, it did not reveal the exact number of customers who were impacted by the hack, when it happened, or the identity of the threat actor behind it.

It’s worth noting that the company, in late April 2025, patched CVE-2025-3935 (CVSS score: 8.1), a high-severity vulnerability in ScreenConnect versions 25.2.3 and earlier that could be exploited for ViewState code injection attacks using publicly disclosed ASP.NET machine keys – a technique Microsoft disclosed earlier this February as being actively exploited by bad actors.

Cybersecurity

The issue was addressed in ScreenConnect version 25.2.4. That said, it’s currently not known if the cyber attack is linked to the exploitation of the vulnerability.

ConnectWise said it has implemented enhanced monitoring and hardening measures across its environment to prevent such attacks from happening again in the future.

“We have not observed any further suspicious activity in any customer instances,” it added, stating it’s closely monitoring the situation.

In early 2024, security flaws in ConnectWise ScreenConnect software (CVE-2024-1708 and CVE-2024-1709) were exploited by both cybercrime and nation-state threat actors, including those from China, North Korea, and Russia, to deliver a variety of malicious payloads.

ConnectWise Confirms Activity Linked to CVE-2025-3935

In a statement shared with The Hacker News, ConnectWise confirmed that the malicious activity is linked to the exploitation of CVE-2025-3935, for which a patch was released on April 24, 2025.

“We have not seen any suspicious ScreenConnect activity since releasing the patch on April 24,” the company said in an updated advisory. “All ScreenConnect customers, including on-premise ScreenConnect customers, should patch their systems, even if not on maintenance.”

CISA Adds CVE-2025-3935 to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2025, added CVE-2025-3935, along with four other flaws affecting ASUS routers and (CVE-2021-32030, CVE-2023-39780) and Craft CMS (CVE-2024-56145, CVE-2025-35939), to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by June 23.

(The story was updated after publication to include a response from ConnectWise confirming the exploitation of CVE-2025-3935.)

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article What is a Strawberry Moon? Best time and how to see full moon in the UK
Next Article Snowflake ups its AI game, Circle IPO blasts off, and Elon splits with Trump – News
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Black Ops 7 Dives Back Into the Shadows With Mason and Menendez
News
US reportedly orders top EDA firms to halt services to China · TechNode
Computing
Ukraine’s IT sector offers opportunities for pragmatic partnership with the US
News
7 Benefits of Lawn Aeration: Improving Soil Health and Grass Growth
Gadget

You Might also Like

Computing

US reportedly orders top EDA firms to halt services to China · TechNode

1 Min Read
Computing

The Top 8 Social Listening Tools in 2024

3 Min Read
Computing

Using AI for Social Media Content: Can AI Tools Match Your Brand Voice?

16 Min Read
Computing

Czech Republic Blames China-Linked APT31 Hackers for 2022 Cyberattack

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?