/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft: MOVEit hackers are exploiting a zero-day flaw in IT support tool SysAid in “limited” attacks to access corporate servers and deploy Clop ransomware

Threat actors are exploiting a zero-day vulnerability in the service management software SysAid to gain access …

BleepingComputer Bill Toulas

Discussion

  • @msftsecintel @msftsecintel on x
    Microsoft has discovered exploitation of a 0-day vulnerability in the SysAid IT support software in limited attacks by Lace Tempest, a threat actor that distributes Clop ransomware. Microsoft notified SysAid about the issue (CVE-2023-47246), which they immediately patched.
  • @msftsecintel @msftsecintel on x
    After exploiting the vulnerability, Lace Tempest issued commands via the SysAid software to deliver a malware loader for the Gracewire malware. This is typically followed by human-operated activity, including lateral movement, data theft, and ransomware deployment.
  • @msftsecintel @msftsecintel on x
    Lace Tempest (which overlaps with threat actors tracked by other researchers as FIN11 and TA505) similarly exploited a 0-day vulnerability in MOVEit Transfer in June: https://twitter.com/...
  • @lindseyod123 Lindsey O'Donnell Welch on x
    In the attacks that Microsoft and SysAid have seen, the attackers exploited the vulnerability to upload a webshell and other files to the target system. https://duo.com/...
  • @catc0n Caitlin Condon on x
    A small bit of potentially good news on the new SysAid 0day (CVE-2023-47246) — it looks like there are only a few hundred servers exposed to the internet. https://www.rapid7.com/...
  • @zoomeye_team @zoomeye_team on x
    🚨🚨A 0day vulnerability exploited by SysAid On-Prem Software in the wild was discovered by the Microsoft Threat Intelligence Team @sysaid CVE-2023-47246 #ZoomEyeDork app:"SysAid On-Prem Software" About 860 results,mainly distributed in Italy,the United States and other...
  • @jgreigj Jon Greig on x
    Clop is back, now exploiting a new zero-day in SysAid IT support software. A patch has been released for CVE-2023-47246 @TheRecord_Media #SysAid #MoveIt #Clop https://therecord.media/...