RnD Research Lab

Cyber Security => IT News => Topic started by: ixsky on

Title: Zero-Day Alert: Lace Tempest Exploits SysAid IT Support Software Vulnerability
Post by: ixsky on
Zero-Day Alert: Lace Tempest Exploits SysAid IT Support Software Vulnerability

The threat actor known as Lace Tempest has been linked to the exploitation of a zero-day flaw in SysAid IT support software in limited attacks, according to new findings from Microsoft.
Lace Tempest, which is known for distributing the Cl0p ransomware, has in the past leveraged zero-day flaws in MOVEit Transfer and PaperCut servers.
The issue, tracked as CVE-2023-47246, concerns a path traversal

Source: Zero-Day Alert: Lace Tempest Exploits SysAid IT Support Software Vulnerability (https://thehackernews.com/2023/11/zero-day-alert-lace-tempest-exploits.html)