Tag: zoho

Lazarus Group Exploits Critical Zoho ManageEngine Flaw to Deploy Stealthy QuiteRAT Malware
News

Lazarus Group Exploits Critical Zoho ManageEngine Flaw to Deploy Stealthy QuiteRAT Malware

A significant security weakness affecting Zoho ManageEngine ServiceDesk Plus that has since been patched has been seen being used by the Lazarus Group, a threat actor with ties to North Korea, to spread a remote access trojan known as QuiteRAT. Healthcare organizations in Europe and the United States are among the targets, according to a two-part research by cybersecurity company Cisco Talos. A new threat known as CollectionRAT has also been found after a deeper look at the adversary's recycling attack infrastructure in its cyberattacks on businesses. Talos noted that the Lazarus Group's continued reliance on the same tradecraft in spite of the components' extensive historical documentation demonstrates the threat actor's confidence in their operations read more Lazarus Group Exp...
Zoho ManageEngine PoC Exploit to be Released Soon – Patch Before It’s Too Late!
Risk, Security

Zoho ManageEngine PoC Exploit to be Released Soon – Patch Before It’s Too Late!

Before a proof-of-concept (PoC) exploit code is released, Zoho ManageEngine users are recommended to patch their instances against a critical security vulnerability. The problem is CVE-2022-47966, a remote code execution vulnerability that affects a number of products because it is caused by the use of an obsolete third-party dependency called Apache Santuario. In a late-year alert, Zoho stated that the vulnerability "allows an unauthenticated adversary to execute arbitrary code," noting that it impacts all ManageEngine configurations that have the SAML single sign-on (SSO) capability enabled or have previously had it enabled read the complete article Zoho ManageEngine PoC Exploit to be Released Soon. For recent and trending cybersecurity news follow ReconBee.com.