#sysaid — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #sysaid, aggregated by home.social.
-
CVE Alert: CVE-2025-2776 - SysAid - SysAid On-Prem - https://www.redpacketsecurity.com/cve-alert-cve-2025-2776-sysaid-sysaid-on-prem/
#OSINT #ThreatIntel #CyberSecurity #cve-2025-2776 #sysaid #sysaid-on-prem
-
CVE Alert: CVE-2025-2775 - SysAid - SysAid On-Prem - https://www.redpacketsecurity.com/cve-alert-cve-2025-2775-sysaid-sysaid-on-prem/
#OSINT #ThreatIntel #CyberSecurity #cve-2025-2775 #sysaid #sysaid-on-prem
-
CVE Alert: CVE-2025-2776 - SysAid - SysAid On-Prem - https://www.redpacketsecurity.com/cve-alert-cve-2025-2776-sysaid-sysaid-on-prem/
#OSINT #ThreatIntel #CyberSecurity #cve-2025-2776 #sysaid #sysaid-on-prem
-
CVE Alert: CVE-2025-2775 - SysAid - SysAid On-Prem - https://www.redpacketsecurity.com/cve-alert-cve-2025-2775-sysaid-sysaid-on-prem/
#OSINT #ThreatIntel #CyberSecurity #cve-2025-2775 #sysaid #sysaid-on-prem
-
U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog – Source: securityaffairs.com https://ciso2ciso.com/u-s-cisa-adds-crushftp-google-chromium-and-sysaid-flaws-to-its-known-exploited-vulnerabilities-catalog-source-securityaffairs-com/ #KnownExploitedVulnerabilitiesCatalog #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #sysaid
-
U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog – Source: securityaffairs.com https://ciso2ciso.com/u-s-cisa-adds-crushftp-google-chromium-and-sysaid-flaws-to-its-known-exploited-vulnerabilities-catalog-source-securityaffairs-com/ #KnownExploitedVulnerabilitiesCatalog #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #sysaid
-
CISA Warns of SysAid Vulnerability Exploitation https://www.securityweek.com/cisa-warns-of-sysaid-vulnerability-exploitation/ #Vulnerabilities #exploited #CISAKEV #SysAid
-
CISA Warns of SysAid Vulnerability Exploitation https://www.securityweek.com/cisa-warns-of-sysaid-vulnerability-exploitation/ #Vulnerabilities #exploited #CISAKEV #SysAid
-
Critical vulnerabilities discovered in SysAid's on-premise IT support software
💥 Vulnerability: XML External Entity (XXE) injections that can lead to RCE
⚠️ Impact: Retrieval of sensitive files, full admin access, and arbitrary code execution, risking data breaches and system compromises.
🔍 CVEs: CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778
🔧 Remediation: Update to SysAid version 24.4.60 b16
#cybersecurity #SysAid #vulnerabilitymanagement
https://thehackernews.com/2025/05/sysaid-patches-4-critical-flaws.html
-
Dozens of SysAid Instances Vulnerable to Remote Hacking https://www.securityweek.com/dozens-of-sysaid-instances-vulnerable-to-remote-hacking/ #Vulnerabilities #vulnerability #SysAid #PoC
-
Dozens of SysAid Instances Vulnerable to Remote Hacking https://www.securityweek.com/dozens-of-sysaid-instances-vulnerable-to-remote-hacking/ #Vulnerabilities #vulnerability #SysAid #PoC
-
Dozens of SysAid Instances Vulnerable to Remote Hacking https://www.securityweek.com/dozens-of-sysaid-instances-vulnerable-to-remote-hacking/ #Vulnerabilities #vulnerability #SysAid #PoC
-
Dozens of SysAid Instances Vulnerable to Remote Hacking https://www.securityweek.com/dozens-of-sysaid-instances-vulnerable-to-remote-hacking/ #Vulnerabilities #vulnerability #SysAid #PoC
-
SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version – Source:thehackernews.com https://ciso2ciso.com/sysaid-patches-4-critical-flaws-enabling-pre-auth-rce-in-on-premise-version-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #sysaid
-
SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version – Source:thehackernews.com https://ciso2ciso.com/sysaid-patches-4-critical-flaws-enabling-pre-auth-rce-in-on-premise-version-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #sysaid
-
PoC exploit for SysAid pre-auth RCE released, upgrade quickly! https://www.helpnetsecurity.com/2025/05/07/poc-exploit-for-sysaid-pre-auth-rce-released-upgrade-quickly/ #vulnerability #enterprise #Don'tmiss #WatchTowr #Hotstuff #SysAid #News #ITSM #SMBs #PoC
-
PoC exploit for SysAid pre-auth RCE released, upgrade quickly! https://www.helpnetsecurity.com/2025/05/07/poc-exploit-for-sysaid-pre-auth-rce-released-upgrade-quickly/ #vulnerability #enterprise #Don'tmiss #WatchTowr #Hotstuff #SysAid #News #ITSM #SMBs #PoC
-
Details techniques & IoCs pour la vulnérabilité dans le logiciel de gestion On-prem SysAid CVE-2023-47246 dans ce récit de prise en charge d'incident de sécurité
👇
https://profero.io/posts/sysaidonpremvulnerability/------------
if sophos 😱 🏃♂️ 💨
👇
foreach($s in tasklist) {
if ($s -match '^(Sophos).*\.exe\s') {echo $s; $bp++;}
}
if ($bp) { echo "`nSTOP-PROCs FOUND! Exiting`n" }
------------ -
The write up for our observations and a bit about the POCs the @huntress team got working for the #SysAid #0day used by #clop #cl0p
Awesome work by @JohnHammond Matt Kiely and others
https://www.huntress.com/blog/critical-vulnerability-sysaid-cve-2023-47246
-
The write up for our observations and a bit about the POCs the @huntress team got working for the #SysAid #0day used by #clop #cl0p
Awesome work by @JohnHammond Matt Kiely and others
https://www.huntress.com/blog/critical-vulnerability-sysaid-cve-2023-47246
-
This was a fun one! Great work by @JohnHammond and the rest of the @huntress crew!
-
This was a fun one! Great work by @JohnHammond and the rest of the @huntress crew!
-
Following the exploitation of the vulnerability, Lace Tempest used the compromised SysAid software to issue commands for delivering a malware loader associated with the Gracewire malware.
-
Following the exploitation of the vulnerability, Lace Tempest used the compromised SysAid software to issue commands for delivering a malware loader associated with the Gracewire malware.
-
Clop is back, now exploiting a new zero-day in SysAid IT support software. A patch has been released for CVE-2023-47246
https://therecord.media/clop-ransomware-gang-targets-new-zero-day
-
MOVEit hackers leverage new zero-day bug to breach organizations (CVE-2023-47246) https://www.helpnetsecurity.com/2023/11/09/exploited-cve-2023-47246/ #securityupdate #ransomware #Don'tmiss #extortion #Microsoft #Hotstuff #webshell #exploit #SysAid #0-day #News #ITSM
-
MOVEit hackers leverage new zero-day bug to breach organizations (CVE-2023-47246) https://www.helpnetsecurity.com/2023/11/09/exploited-cve-2023-47246/ #securityupdate #ransomware #Don'tmiss #extortion #Microsoft #Hotstuff #webshell #exploit #SysAid #0-day #News #ITSM
-
New #SysAid 0day (#CVE_2023_47246) exploited by Lace Tempest — good news is there aren't a ton of internet-facing servers. https://www.rapid7.com/blog/post/2023/11/09/etr-cve-2023-47246-sysaid-zero-day-vulnerability-exploited-by-lace-tempest/
-
New #SysAid 0day (#CVE_2023_47246) exploited by Lace Tempest — good news is there aren't a ton of internet-facing servers. https://www.rapid7.com/blog/post/2023/11/09/etr-cve-2023-47246-sysaid-zero-day-vulnerability-exploited-by-lace-tempest/
-
Patch, patch, patch. FIN11/TA505/DEV-0950/Cl0p has another 0day. #SysAid.
https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
-
Patch, patch, patch. FIN11/TA505/DEV-0950/Cl0p has another 0day. #SysAid.
https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
-
Looking for some community input on this one, because I am a bit confused. Could someone explain CVE-2022-23166 to me? I'm not looking to figure out how to exploit it, but I am trying to get a better idea on what could happen. If an endpoint has the Sysaid agent installed, does that mean there is a URL tied that asset? Is that what this CVE is referring to? Any insight would be very helpful because I want to protect against this, but I need to be able to explain this to the team a little better.
-
Does anyone have any recommendations for a solution to remote wipe Windows PCs? Currently these Windows PCs are managed with Sysaid.
I don't believe there is a good solution outside of buying a MDM or software specific solution. Does anyone recommend anything open source or have any other creative solutions for this? Thanks!
#assetmanagement #windows #security #sysaid #MDM #opensource
-
Does anyone have any recommendations for a solution to remote wipe Windows PCs? Currently these Windows PCs are managed with Sysaid.
I don't believe there is a good solution outside of buying a MDM or software specific solution. Does anyone recommend anything open source or have any other creative solutions for this? Thanks!
#assetmanagement #windows #security #sysaid #MDM #opensource
-
Some stuff I'm currently working on as of late:
- Finalizing lists and details for our big campaign in January
- Working through some PCI stuff, finalizing details on that submission
- Rebuild my Kali box because I broke it (oops)
- Cleaning up IR docs to confirm to us
- I have to go into the office this week, not role related, but I'm assisting with some office stuff.
- Working with sysaid support on a chrome patching issueWhy do I share what I do? It helps me think more abstractly about them as I write them here. I also like to share what I as an analyst really does day to day :)
-
We've hit some minor roadblocks in our first phishing campaign primarily because of the person at our SOC misconfiguring it :(
Live and learn.
I've been MIA here lately but that's just because of work and life. I've been cleaning up #AzureAD sync stuff. Making sure that we aren't syncing admins or using any wasted licenses.
I've been working on PCI compliance stuff, vulnerability scanning and remediation and troubleshooting #sysaid patching. Lets go!