ZeroFox Intelligence Flash Report - Ransomware Collectives Set to Exploit SysAid Zero-Day Vulnerability
|by Alpha Team

ZeroFox Intelligence Flash Report - Ransomware Collectives Set to Exploit SysAid Zero-Day Vulnerability
Product Serial: F-2023-11-10a
TLP:CLEAR
In this Intelligence Flash Report, ZeroFox researchers report on the SysAid zero-day vulnerability (tracked as CVE-2023-47246) being actively exploited by financially-motivated threat actors to deploy ransomware.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Key Findings
- On November 8, 2023, IT Service Management Solution (ITSM) organization SysAid disclosed a zero-day vulnerability targeting its on-premises software, which has led to an unknown amount of ransomware attacks.
- Initial exploitation has been attributed to financially-motivated group Lace Tempest, which is associated with ransomware collective Cl0p. Cl0p has conducted at least two prominent ransomware campaigns in 2023, both targeting managed file transfer solutions (MFTs).
Tags: tlp:clear, dark web, vulnerability/exploit, all industries, DDW Ransomware