Zoho’s ManageEngine Desktop Central is a management platform that helps admins deploy patches and software automatically over the network and troubleshoot them remotely. The company patched a critical vulnerability (tracked as CVE-2021-44515) which could allow attackers to bypass authentication and execute arbitrary code on unpatched servers. Zoho also recommends initiating a password reset for all services, accounts, Active Directory, etc. that has been accessed from the service installed machine. State hackers have been using tactics similar to those used by Chinese-backed hacking group APT27.”]

