Blog | G5 Cyber Security

Zoho: Patch new ManageEngine bug exploited in attacks ASAP

Zoho’s ManageEngine Desktop Central is a management platform that helps admins deploy patches and software automatically over the network and troubleshoot them remotely. The company patched a critical vulnerability (tracked as CVE-2021-44515) which could allow attackers to bypass authentication and execute arbitrary code on unpatched servers. Zoho also recommends initiating a password reset for all services, accounts, Active Directory, etc. that has been accessed from the service installed machine. State hackers have been using tactics similar to those used by Chinese-backed hacking group APT27.”]

Source: https://www.bleepingcomputer.com/news/security/zoho-patch-new-manageengine-bug-exploited-in-attacks-asap/

Exit mobile version