newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: ConnectWise screenconnectRotate code signing certificate for security risk
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > ConnectWise screenconnectRotate code signing certificate for security risk
Technology

ConnectWise screenconnectRotate code signing certificate for security risk

June 15, 2025 3 Min Read
Share
ConnectWise screenconnectRotate code signing certificate for security risk
SHARE

ConnectWise has revealed that due to security concerns it plans to rotate the digital code signing certificate used to sign Remote Monitoring and Management (RMM) executables for ScreenConnect, ConnectWise Automate and ConnectWise.

The company said it is doing so “due to concerns raised by third-party researchers about how ScreenConnect handled certain configuration data in previous versions.”

The company has not publicly explained the nature of the issue, but it is shedding more light with private FAQs that only customers can access (and later shared on Reddit) –

The concern comes from screenconnect using the ability to store configuration data in the available space of the installer that is not signed but is part of the installer. This feature allows you to pass configuration information for connections (between the agent and server), such as URLs that the agent calls back without disabling the signature. Unsigned areas are used by software and others for customization, but when combined with the capabilities of remote control solutions, today’s security standards allow for insecure design patterns to be created.

In addition to issuing new certificates, the company said it is releasing an update designed to improve the way the aforementioned configuration data is managed by ScreenConnect.

The digital certificate revocation is scheduled to take place at 8pm on June 13th (12am on June 14th, UTC). Connectwise emphasizes that this issue does not involve system or certificate compromises.

It is worth noting that on all cloud instances of Automate and RMM, ConnectWise is in the process of automatically updating certificates and agents.

See also  Apple Zero-Clock flaws in messages abused by journalist spies using Paragon Spyware

However, anyone using an on-premises version of ScreenConnect or Automate should update to the latest build and verify that all agents are updated before the cutoff date to avoid service disruption.

“We had already planned to increase certificate management and product hardening, but these efforts are now implemented in an accelerated timeline,” Connectwise said. “We understand that this can pose challenges and are committed to supporting you through the transition.”

The development comes days after it revealed that by leveraging CVE-2025-3935 to implement a code injection attack on viewing states, the threat actor suspected of a nation-state threat has breached the system and affected a small number of customers.

It also allows attackers to rely more and more on legal RMM software such as Screenconnect to obtain permanent remote access in stealth and infiltrate and fly under the radar.

This attack method, called Live-Off-The-Land (LOTL), allows you to hijack software’s unique features for remote access, file transfers, and command execution.

Share This Article
Facebook Twitter Copy Link
Previous Article Helldivers2 Challenger Jump Ship is one of the biggest Steam Next Fest winners Helldivers2 Challenger Jump Ship is one of the biggest Steam Next Fest winners
Next Article “Brussels, my love?” The EU extends the special status of Ukrainian refugees “Brussels, my love?” The EU extends the special status of Ukrainian refugees
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

A vulnerability containing Microsoft Patch 67 Webdav Zero-Day has been exploited in the wild
Technology

A vulnerability containing Microsoft Patch 67 Webdav Zero-Day has been exploited in the wild

12 Min Read
Researchers have discovered over 20 composition risks, including five CVEs, in the Salesforce industry cloud
Technology

Researchers have discovered over 20 composition risks, including five CVEs, in the Salesforce industry cloud

5 Min Read
AI and national security: a new battlefield
Technology

AI and national security: a new battlefield

7 Min Read
Moving from monitoring alerts to measuring risk
Technology

Moving from monitoring alerts to measuring risk

7 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?