Hackers are using this flaw to gather server passwords from the unpatched instances of ConnectWise Automate, a source says. One MSP encrypted in mid-May using this vulnerability prompted the company to release the hotfix and notify users. Security experts say the flaw has other vectors of attack so at least one other method of exploiting the flaw remains. The company says it is creating more ways to keep partners abreast of the latest security developments with its products. The vulnerability was announced on June 10 using a site meant to give partners up-to-the-minute security bulletins.”]
Source: https://www.crn.com/news/channel-programs/connectwise-partners-hit-by-ransomware-via-automate-flaw