Dameware Remote Everywhere Fake Login Site Created to Steal User Credentials.
(CVE-DRE-Advisory)
Summary
In an abundance of caution, we are notifying our customers of a potential security issue. SolarWinds has discovered a fake website is currently being used by bad actors with the goal of stealing Dameware Remote Everywhere customer account login information. SolarWinds has reached out to the organization hosting this site to resolve this issue. While it has not yet been taken down, we will pursue this step until resolution.
The URL being used by the malicious actor is https://admin-swi-dre[.]com
We suggest you add the above URL to your firewall block list to prevent any of your users from accessing it by mistyping the URL.
Advisory Details
Severity
5.0 Medium
Advisory ID
CVE-DRE-Advisory
First Published
04/10/2024