Hackers are targeting ConnectWise Automate, a RMM (remote monitoring and management) software platform that is popular with IT service providers (MSPs) and technology solution providers (TSPs).

In a tweet, ConnectWise wrote:
“We would like to inform you that there are recent reports of hackers targeting open ports for the ConnectWise Automate on-premises application for the purpose of ransomware infection. Please ensure that your ports are not open to the Internet based on our best practices:http://ow.ly/bmbs30pQG57”
Hackers often target MSP software platforms through malware and ransomware attacks, a tactic that the FBI online users about. In a typical attack, an open port on an MSP company often leads to the breach of multiple partner and customer systems.

MSPs and Cybersecurity
Amid this reality, many IT services companies are embracing the NIST security framework to assess and mitigate risk in their own businesses.
ConnectWise is working to develop an Information Sharing and Analysis Organization (ISAO) for technology solution providers. The Technology Solution Provider ISAO (TSP-ISAO) is essentially a ConnectWise affiliate and will be independently funded to ensure vendor neutrality. MJ Shoer, an MSP industry veteran, is leading this effort.
Meanwhile, most major MSP and RMM software providers now enforce or will soon enforce two-factor authentication as a means of further mitigating internet threats.
