HomeSecurityConnectWise changes code signing certificates

ConnectWise changes code signing certificates

ConnectWise is warning its customers that it is replacing the digital code signing certificates used to sign the executable files of ScreenConnect, ConnectWise Automate , and ConnectWise RMM , due to security concerns .

See also: Microsoft Outlook: Blocks other file types to prevent phishing

ConnectWise certificates

Digital certificates are used to sign executable files so that users who download them know that they came from a trusted source. This ensures that the code has not been modified before it reaches the end user.

According to ConnectWise, the decision was made after an independent security researcher alerted them to potential ways in which certain configuration data could be misused by malicious actors. The company emphasizes that the measure is not related to any security incident, and specifically not to the state-level cyberattack it suffered last month.

The certificates in question were issued by DigiCert, which originally intended to revoke them on Tuesday, June 10 at 10:00 PM (EST). However, ConnectWise was able to secure an extension until Friday, June 13, 2025, likely because the new ScreenConnect version 25.4, which uses the new certificates, was not yet available.

This change will affect both users who host applications locally (on-premises) and those who use cloud versions, who must meet the deadline to avoid problems in the operation of their systems.

See also: ManageEngine Exchange Reporter Plus vulnerability allows RCE

According to ConnectWise, the new version of Automate is already available, while the corresponding version of ScreenConnect is expected soon.

ConnectWise changes code signing certificates

Users are advised to visit the vendor's “University” page to download updated versions and find instructions and frequently asked questions (FAQs).

For those using the cloud-hosted versions of Automate, ScreenConnect , or RMM, ConnectWise will automatically install certificate and agent updates, but the process is being rolled out gradually. However, users are advised to check that their agents are up to date by June 13 to ensure uninterrupted service .

Although ConnectWise did not provide specific details about the reason for replacing the certificates, Sophos researcher Andrew Brandthad warned since April that malicious actors were using phishing websites to distribute customized versions of ConnectWise, which were presented as Social Security documents.

See also: PoC exploit released for Apache Tomcat DoS vulnerability

Replacing digital code signing certificates is not just a standard maintenance procedure, but a critical security measure, especially in environments where remote access and IT automation are managed, such as with ConnectWise tools. Malicious actors can exploit older or compromised certificates to pass off malware as legitimate, as Sophos’ findings have shown.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS