The FBI, CISA, and the Coast Guard Cyber Command have issued a joint security advisory on a security flaw in Zoho single sign-on and password management solution. The vulnerability tracked as CVE-2021-40539 was found in the Zoho ManageEngine ADSelfService Plus software. Zoho’s customer list includes Apple, Intel, Nike, PayPal, HBO, and many more. The agencies urge organizations to immediately apply the software update and ensure the software is not directly accessible from the Internet.”]

