Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    This $30 Gadget Keeps My Office and Workspace Organized at All Times – How It Works

    November 7, 2025

    I tried the only agentive browser that runs native AI – and found only one downside

    November 7, 2025

    Get 4 Free iPhone 17 or Galaxy S25 Phones from T-Mobile Right Now – Here’s How

    November 7, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»ConnectWise AITM update fixes automated bug that allowed attacks
    Security

    ConnectWise AITM update fixes automated bug that allowed attacks

    PineapplesUpdateBy PineapplesUpdateOctober 17, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    ConnectWise AITM update fixes automated bug that allowed attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    ConnectWise AITM update fixes automated bug that allowed attacks

    ConnectWise released a security update to address vulnerabilities in the Automate product, including one with critical severity, which could expose sensitive communications to interception and modification.

    ConnectWise Automate is a remote monitoring and management (RMM) platform used by managed service providers (MSPs), IT services companies, and internal IT departments in large enterprises.

    In a typical deployment, it acts as a central management hub with high privileges to control thousands of client machines.

    The most serious defects fixed by the vendor are tracked CVE-2025-11492With a severity rating of 9.6, the vulnerability allows clear text transmission of sensitive information.

    In particular, agents can be configured to communicate over insecure HTTP instead of encrypted HTTPS, which can be used in adversary-in-the-middle (AITM) attacks to intercept or modify traffic, including command, credential, and update payloads.

    “In on-premises environments, agents may be configured to use HTTP or rely on encryption, which could allow a network-based adversary to view or modify traffic or replace malicious updates,” ConnectWise explains,

    Second vulnerability has been identified CVE-2025-11493 (8.8 severity score) and includes the lack of integrity verification (checksum or digital signature) for updated packages along with their dependencies and integrations.

    Combining the two security issues, an attacker can push malicious files (e.g. malware, updates) as legitimate ones by impersonating a legitimate ConnectWise server.

    ConnectWise marks the security update as medium priority. The company has addressed both issues for cloud-based instances, which have been updated to the latest Automate release, 2025.9.

    The vendor’s recommendation for administrators of on-premise deployments is to take action as quickly as possible (within days) and install the new release.

    The security bulletin does not mention active exploitation, but warns that the vulnerabilities have “a higher risk of being targeted by wild exploitation.”

    Threat actors have taken advantage of potentially serious vulnerabilities in ConnectWise products in the past. Earlier this year, nation-state actors directly breached the company’s environment, an attack that affected several ScreenConnect customers downstream.

    The incident forced the vendor to rotate all digital code signing certificates with which it verified executables for a range of products, to reduce the risk of abuse.


    picus blue report 2025

    Passwords were cracked in 46% of environments, almost double from 25% last year.

    Get the Picus Blue Report 2025 now for a comprehensive look at prevention, detection, and more findings on data intrusion trends.

    AITM allowed attacks automated Bug ConnectWise fixes update
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFacebook’s AI can now suggest edits to photos on your phone
    Next Article Codev lets enterprises avoid the vibey coding hangover with a team of agents who generate and document code
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Windows 11 users affected by bizarre Task Manager duplication bug – here’s how to avoid it

    October 31, 2025
    Startups

    This simple Pixel update finally makes my Android calls as good as the iPhone’s

    October 30, 2025
    AI/ML

    The Boox Palma just got a big update

    October 26, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    This $30 Gadget Keeps My Office and Workspace Organized at All Times – How It Works

    November 7, 2025

    I tried the only agentive browser that runs native AI – and found only one downside

    November 7, 2025

    Get 4 Free iPhone 17 or Galaxy S25 Phones from T-Mobile Right Now – Here’s How

    November 7, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.