Hacker Group Exploits Zero-Day Bug to Target ITSM Platform

1 min read
Source: Help Net Security
Hacker Group Exploits Zero-Day Bug to Target ITSM Platform
Photo: Help Net Security
TL;DR Summary

A critical zero-day vulnerability (CVE-2023-47246) in the SysAid IT support and management software solution is being exploited by the ransomware affiliate Lace Tempest, known for deploying Cl0p ransomware. This is not the first time Lace Tempest has exploited zero-day vulnerabilities, having previously targeted Progress Software's MOVEit Transfer installations, Accellion file transfer appliance, and Fortra's GoAnywhere file transfer solution. The vulnerability allows unauthorized access to affected systems and execution of arbitrary code. SysAid has released a patch (v23.3.36) and advised customers to update their systems and check for evidence of compromise.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

84%

54990 words

Want the full story? Read the original article

Read on Help Net Security