home.social

#sysaid — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sysaid, aggregated by home.social.

fetched live
  1. Critical vulnerabilities discovered in SysAid's on-premise IT support software

    💥 Vulnerability: XML External Entity (XXE) injections that can lead to RCE

    ⚠️ Impact: Retrieval of sensitive files, full admin access, and arbitrary code execution, risking data breaches and system compromises.

    🔍 CVEs: CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778

    🔧 Remediation: Update to SysAid version 24.4.60 b16

    #cybersecurity #SysAid #vulnerabilitymanagement

    thehackernews.com/2025/05/sysa

  2. Details techniques & IoCs pour la vulnérabilité dans le logiciel de gestion On-prem SysAid CVE-2023-47246 dans ce récit de prise en charge d'incident de sécurité
    👇
    profero.io/posts/sysaidonpremv

    ------------
    if sophos 😱 🏃‍♂️ 💨
    👇
    foreach($s in tasklist) {
    if ($s -match '^(Sophos).*\.exe\s') {echo $s; $bp++;}
    }
    if ($bp) { echo "`nSTOP-PROCs FOUND! Exiting`n" }
    ------------

    #Cyberveille #SysAid

  3. The write up for our observations and a bit about the POCs the @huntress team got working for the #SysAid #0day used by #clop #cl0p

    Awesome work by @JohnHammond Matt Kiely and others

    #dfir

    huntress.com/blog/critical-vul

  4. The write up for our observations and a bit about the POCs the @huntress team got working for the #SysAid #0day used by #clop #cl0p

    Awesome work by @JohnHammond Matt Kiely and others

    #dfir

    huntress.com/blog/critical-vul

  5. Following the exploitation of the vulnerability, Lace Tempest used the compromised SysAid software to issue commands for delivering a malware loader associated with the Gracewire malware.

    #Cybersecurity #Vulnerability #Exploit #ZeroDay #SysAid

    cybersec84.wordpress.com/2023/

  6. Following the exploitation of the vulnerability, Lace Tempest used the compromised SysAid software to issue commands for delivering a malware loader associated with the Gracewire malware.

    #Cybersecurity #Vulnerability #Exploit #ZeroDay #SysAid

    cybersec84.wordpress.com/2023/

  7. Clop is back, now exploiting a new zero-day in SysAid IT support software. A patch has been released for CVE-2023-47246

    #SysAid #MoveIt #Clop

    therecord.media/clop-ransomwar

  8. Looking for some community input on this one, because I am a bit confused. Could someone explain CVE-2022-23166 to me? I'm not looking to figure out how to exploit it, but I am trying to get a better idea on what could happen. If an endpoint has the Sysaid agent installed, does that mean there is a URL tied that asset? Is that what this CVE is referring to? Any insight would be very helpful because I want to protect against this, but I need to be able to explain this to the team a little better.

    #security #CVE202223166 #Sysaid #confused

  9. Does anyone have any recommendations for a solution to remote wipe Windows PCs? Currently these Windows PCs are managed with Sysaid.

    I don't believe there is a good solution outside of buying a MDM or software specific solution. Does anyone recommend anything open source or have any other creative solutions for this? Thanks!

    #assetmanagement #windows #security #sysaid #MDM #opensource

  10. Does anyone have any recommendations for a solution to remote wipe Windows PCs? Currently these Windows PCs are managed with Sysaid.

    I don't believe there is a good solution outside of buying a MDM or software specific solution. Does anyone recommend anything open source or have any other creative solutions for this? Thanks!

    #assetmanagement #windows #security #sysaid #MDM #opensource

  11. Some stuff I'm currently working on as of late:
    - Finalizing lists and details for our big campaign in January
    - Working through some PCI stuff, finalizing details on that submission
    - Rebuild my Kali box because I broke it (oops)
    - Cleaning up IR docs to confirm to us
    - I have to go into the office this week, not role related, but I'm assisting with some office stuff.
    - Working with sysaid support on a chrome patching issue

    Why do I share what I do? It helps me think more abstractly about them as I write them here. I also like to share what I as an analyst really does day to day :)

    #security #phishing #PCI #sysaid #ir

  12. We've hit some minor roadblocks in our first phishing campaign primarily because of the person at our SOC misconfiguring it :(

    Live and learn.

    I've been MIA here lately but that's just because of work and life. I've been cleaning up #AzureAD sync stuff. Making sure that we aren't syncing admins or using any wasted licenses.
    I've been working on PCI compliance stuff, vulnerability scanning and remediation and troubleshooting #sysaid patching. Lets go!