// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
ColdRecon / Breach Radar / ConnectWise
Breach Record

ConnectWise

DISCLOSED 2026-09-07 · UNKNOWN

Attackers are using modified ScreenConnect clients to deliver and execute payloads on newly connected endpoints, spreading in a worm-like manner. The campaign leverages the legitimate remote management tool to propagate and execute malicious code on compromised systems.

The record

What we know

Disclosed
2026-09-07
Sources

Cited reporting

This page is the permanent ColdRecon entry for the ConnectWise disclosure. It updates if new public reporting emerges. All tracked breaches →

ConnectWise just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →