Lazarus Group exploits ManageEngine and Rockwell ThinManager vulnerabilities, Mississippi hospital attack. Topic includes cyberattacks, rat malware delivery, vulnerable XMPP servers, and new features in Chrome.
Lazarus Group exploits ManageEngine to launch cyberattacks on internet and healthcare, using a new remote access Trojan to remain undetected.
Vulnerabilities in Rockwell ThinManager software could result in denial of service, unauthorized file uploads, and full control of industrial control systems.
Deep dives
Lazarus Group Exploits Manage Engine to Target Internet and Healthcare Organizations
North Korea's Lazarus Group has been observed leveraging a critical vulnerability in Zoho's Manage Engine service desk to launch attacks on internet companies and healthcare providers in the U.S. and the U.K. These attacks involve the deployment of new remote access Trojan malware, known as the collection rat, which helps the group avoid detection. The exploitation of Manage Engine's vulnerability presents challenges for attribution, tracking, and developing effective protective measures.
Rockwell Thin Manager Faces Vulnerability Threatening Industrial Control Systems
Researchers at Tenable have discovered vulnerabilities in Rockwell's Thin Manager Thin Server software, which is primarily used for human machine interfaces in industrial control systems. The identified flaws, tracked as CVE-2023-2914-2915 and 2917, could lead to denial of service, file deletion, and unauthorized file uploads. Exploiting these vulnerabilities grants attackers full control of the Thin Server. Patches have been released, and customers have been notified about the necessary updates.
Lazarus Group exploits ManageEngine to drop new RATS on internet and healthcare
Vulnerabilities in Rockwell ThinManager threaten industrial control systems
Mississippi hospital system suffers cyberattack
Huge thanks to our sponsor, HyperProof
Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit to get started today.
For the stories behind the headlines, head to CISOseries.com.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode