#manageengine

2025-05-23

#BSI WID-SEC-2025-1131: [NEU] [mittel] #Zoho #ManageEngine #ServiceDesk #Plus: Schwachstelle ermöglicht Offenlegung von Informationen

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Zoho ManageEngine ServiceDesk Plus ausnutzen, um Informationen offenzulegen.

wid.cert-bund.de/portal/wid/se

Marco Ciappelli🎙️✨:verified: :donor:Marcociappelli@infosec.exchange
2025-05-07

🎙️ In cybersecurity today, it’s not just about flashy innovation — it’s about smart integration that actually builds trust. In this On Location Briefing from #RSAC2025, we explore why connecting the dots matters more than chasing the next big thing.

🚀 New Briefing from #RSAC 2025: From Tools to Trust — Why Integration Beats Innovation Hype in Cybersecurity

At RSA Conference 2025, Sean Martin, CISSP caught up with Vivin Sathyan, Senior Technology Evangelist at ManageEngine, to discuss why integration, simplicity, and a trust-first approach are redefining effective cybersecurity programs.

🔐 Why is layering more and more tools no longer the answer?

Find out how ManageEngine is helping organizations focus on seamless security integration to drive real resilience and smarter risk management.

🎙️ Watch, listen, or read the full conversation here:
👉 itspmagazine.com/their-stories

📌 Learn more about ManageEngine’s work:
👉 itspmagazine.com/directory/man

🛰️ See all our RSAC 2025 coverage:
👉 itspmagazine.com/rsac25

🌟 Discover more On Location Conversations, Brand Stories, and Briefings:
👉 itspmagazine.com/brand-story

🎥🎙️ This is just one of the many incredible conversations we recorded On Location in San Francisco, as Sean Martin and Marco Ciappelli covered the event as official media partners for the 11th year in a row.

Stay tuned for more Briefings, Brand Stories, and candid conversations from RSAC 2025!

🎤 Looking ahead:
If your company would like to share your story with our audiences On Location, we’re gearing up for #InfosecurityEurope in June and #BlackHatUSA in August!

⚡ RSAC 2025 sold out fast — we expect the same for these next events.
🎯 Reserve your full sponsorship or briefing now: itspmagazine.com/purchase-prog

#cybersecurity #infosec #infosecurity #technology #tech #society #business #securityintegration #trustbasedsecurity #cyberresilience #manageengine

Pineriumpinerium
2025-04-19

During our visit to Zoho Corp Headquarters, we had the chance to meet the ManageEngine team.

It was a great opportunity to learn more about their work in IT management, security, and automation. Their focus on building reliable, effective solutions for businesses stood out throughout our discussions.

2025-03-28

Hey Mastodon, question for my #sysadmin and #DevOps types. Has anyone used #Pester and #PSScriptAnalyzer to set up unit testing for test driven development, particularly on (relatively) simple #PowerShell scripts like you might use for application detection, installation, and uninstallation from a system like #SCCM #Intune or #ManageEngine ?

Apologies for the buzzword bingo, but I’m trying to reach folks who may be following the hashtags, but not necessarily have a connection otherwise.

#TDD #unittests

Fringed Crow :battery_ok:Fringedcrow@infosec.exchange
2025-03-05

The flaw, discovered in builds 6510 and earlier, could enable attackers to bypass authentication safeguards and access sensitive user enrollment data, potentially leading to account takeovers.

The company resolved the issue in build 6511, released on February 26, 2025, and urges immediate patching for all affected systems.

cybersecuritynews.com/zoho-ads

#ZoHo #ZohoSoftware #ManageEngine

2024-09-05

#BSI WID-SEC-2024-2054: [NEU] [hoch] #Zoho #ManageEngine #Endpoint #Central: Schwachstelle ermöglicht Umgehung von Sicherheitsvorkehrungen und Offenlegung von Informationen

Ein entfernter, authentifizierter Angreifer kann eine Schwachstelle in Zoho ManageEngine Endpoint Central ausnutzen, um vertrauliche Informationen offenzulegen und Sicherheitsvorkehrungen zu umgehen, um so einen Ransomware-Angriff durchzuführen.

wid.cert-bund.de/portal/wid/se

2024-08-23

#BSI WID-SEC-2024-1915: [NEU] [niedrig] #Zoho #ManageEngine #ServiceDesk #Plus: Schwachstelle ermöglicht Cross-Site Scripting

Ein Angreifer kann eine Schwachstelle in Zoho ManageEngine ServiceDesk Plus ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.

wid.cert-bund.de/portal/wid/se

Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:youranonriots@kolektiva.social
2024-04-20

🛑 Hackers are using fake domains of popular IP scanners like Advanced IP Scanner & #ManageEngine in a #Google Ads malvertising scheme to spread the MadMxShell backdoor – 45+ domains created since November 2023.

thehackernews.com/2024/04/mali

#cybersecurity

🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2023-12-12

"🚨 Lazarus Group Unleashes CollectionRAT in Sophisticated Campaigns 🚨"

Lazarus Group, a North Korean state-sponsored actor, has been utilizing infrastructure reuse to launch sophisticated cyber attacks. Their latest campaign exploits CVE-2022-47966, a vulnerability in ManageEngine ServiceDesk, to deploy multiple threats including a new malware, CollectionRAT. This RAT showcases capabilities such as executing arbitrary commands and managing files on infected systems. Intriguingly, Lazarus Group is increasingly leveraging open-source tools like the DeimosC2 framework, marking a strategic shift in their attack methodologies. CollectionRAT, along with other tools like the malicious PuTTY Link (Plink), indicates a refined approach in their cyber warfare tactics.

Details: Cisco Talos Blog

Authors: Asheer Malhotra, Vitor Ventura, Jungsoo An

Tags: #Cybersecurity #LazarusGroup #APT #CollectionRAT #DeimosC2 #CVE202247966 #ManageEngine #Plink #NorthKorea #StateSponsoredCyberAttacks 💻🌍🔐

Mitre - Lazarus Group

2023-07-02

Pulling SYSTEM out of #Windows GINA — #Authentication #Bypass to SYSTEM shell in #ManageEngine #ADSelfService Plus Windows GINA Client

// by @pedrib1337@twitter.com

github.com/pedrib/PoC/blob/mas

Pre-auth SYSTEM shell
stickus - VA7GMZstickus@mstdn.ca
2023-05-17

Chilling here in Toronto right now, waiting for the ManageEngine UserConf to begin. My body is still on Pacific time so as far as it's concerned it's too damn early to be awake. On my second cup of ☕ for the day 👀

#ManageEngine #UserConf #IT #tech #technology #conference

A screen showing the logo and name of the ManageEngine UserConf 2023 in Toronto, CanadaA plate of breakfast food, including pancakes, bacon, eggs, sausage and potato wedges.
Mustafa Kaan Demirhanmstfknn
2023-04-15

🚨New Vulnerability Alert: ADManager Plus (CVE-2023-29084)! Update to version 7181 to stay secure. Details: eu1.hubs.ly/H03thkB0

2023-02-27

Kritische #Schwachstellen in #VMware CBAC & Zoho #ManageEngine, #Cyberangriffe auf Dole, Bayrischer Rundfunk, Feuerwehr Hamburg, sowie Landratsamt Böblingen und #EU Kommission setzt #TikTok auf Firmengeräten aus – das sind die #Hacker #News der Woche.

lastbreach.de/blog/die-weekly-

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst