In February 2024, threat-intelligence reporting linked Black Basta and Bl00dy ransomware activity to exploitation of two flaws in self-hosted ConnectWise ScreenConnect servers. The critical issue, CVE-2024-1709, allowed authentication bypass; CVE-2024-1708 was a path-traversal flaw. Organizations running affected servers should verify patch status and investigate for unauthorized access—not assume that upgrading alone removes an intruder.
What happened, and how were the flaws used?
Check Point reported that both Black Basta and Bl00dy were exploiting CVE-2024-1709 and CVE-2024-1708. Trend Micro later summarized the impact as including system compromise, data theft and operational disruption. The reports concern activity disclosed in 2024; they do not establish that either group is exploiting these flaws now.
Two vulnerabilities, different mechanics
- CVE-2024-1709: an authentication-bypass vulnerability. An attacker could gain access without valid authentication.
- CVE-2024-1708: a path-traversal vulnerability that could allow unauthorized file access and code execution on a vulnerable server.
Government and vendor guidance treated the flaws as urgent because an internet-facing ScreenConnect server could provide a route into an organization’s environment.
ScreenConnect’s role in Black Basta activity
Microsoft’s account of Storm-1811 activity describes a broader intrusion chain: impersonation and voice phishing were used to gain access, followed by tools including Qakbot, ScreenConnect and Cobalt Strike before Black Basta deployment. Microsoft said ScreenConnect was used to establish persistence and move laterally. This is an example of how remote-management software can be abused after access is obtained, not evidence that every ScreenConnect incident followed the same chain.
#1 Best Overall
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Which ScreenConnect versions were affected?
ConnectWise identified self-hosted, on-premises ScreenConnect versions 23.9.7 and earlier as affected. Its 2024 bulletin says, “Partners on version 23.9.8 or higher are considered patched.” That is the remediation threshold for these reported vulnerabilities, not a recommendation to run an old release today: install a currently supported release and verify its status with ConnectWise.
ConnectWise said cloud-hosted instances were remediated by the company. That reduced customers’ responsibility for applying the server-side fix, but administrators should still review their own accounts, roles, settings and access history.
Rank #2
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
For customers who were off maintenance during the 2024 response, ConnectWise offered version 22.4.20001 as an interim patched release. This historical exception should not be treated as a current supported-version recommendation.
How can you check whether a server was compromised?
A patched version tells you the vulnerability was addressed; it does not prove the server was never accessed or that an attacker left no persistence. ConnectWise advised reviewing the server and warned that it might not have been the only entry point.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
- Inventory every self-hosted ScreenConnect server, record its version, and determine whether it was reachable from the internet while vulnerable.
- Review ScreenConnect users and roles for accounts or privileges that administrators did not authorize.
- Check configuration, access logs and installed extensions for changes or activity that cannot be explained by approved administration.
- Investigate the host and the wider environment for other signs of unauthorized access, persistence, lateral movement or data theft. An absence of an obvious ScreenConnect change is not proof that the wider environment is clean.
The available guidance does not define a single log entry or indicator that conclusively proves compromise. Treat unexplained changes or access as a reason for incident investigation rather than relying on a version check alone.
What should an MSP do after finding an affected server?
- Find and prioritize instances. Inventory all self-hosted servers, note versions and exposure, and prioritize internet-facing installations.
- Upgrade. Move to a currently supported, patched release. For the 2024 vulnerabilities, ConnectWise identified 23.9.8 and later as patched; confirm present-day release and support status with the vendor.
- Review for unauthorized changes. Examine users, roles, configuration, access logs and extensions, then investigate the host and connected systems.
- If compromise is suspected, contain and investigate. Isolate the server, preserve evidence, investigate the broader environment, and rotate credentials. Secure or rebuild the host before returning it to service.
- Reduce the chance and impact of another intrusion. Apply the joint CISA, FBI, HHS and MS-ISAC Black Basta advisory’s broader measures, including strong identity protection, network segmentation, tested backups, monitoring and incident-response planning.
Does cloud-hosted ScreenConnect require the same response?
Cloud and self-hosted deployments differ in who controls the server and applies its software updates. The 2024 incident makes that distinction important, but it does not remove the customer’s responsibility to review access and investigate suspicious activity.
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
| Deployment | Patch responsibility for the 2024 flaws | Customer checks |
|---|---|---|
| Self-hosted / on-premises | The organization or service provider operating the server needed to upgrade affected versions. | Verify each server’s version and exposure; review users, roles, settings, logs and extensions. |
| Cloud-hosted | ConnectWise said it remediated cloud-hosted instances. | Review users, roles, configuration and access logs; investigate suspicious activity. |
This comparison describes the responsibility split ConnectWise reported for the 2024 remediation; it is not a substitute for checking current service and support terms.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How serious was the Black Basta threat?
In its 2024 joint advisory, CISA, the FBI, HHS and MS-ISAC said Black Basta had targeted more than 500 private-industry and critical-infrastructure entities in North America, Europe and Australia. The advisory identified the ransomware-as-a-service variant in April 2022. The American Hospital Association, summarizing that federal advisory in 2024, said at least 12 of 16 critical-infrastructure sectors had been affected, including healthcare and public health. These are historical figures from the 2024 advisories, not a current victim count.
Quick Recap
Best Value
- Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
- FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
- Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
- Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
- Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

