menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Cyber Crime News

>

DragonForc...
source image

Cybersafe

4d

read

338

img
dot

Image Credit: Cybersafe

DragonForce exploits SimpleHelp flaws to breach MSP

  • Sophos researchers discovered a cyberattack where DragonForce ransomware exploited three vulnerabilities in SimpleHelp to breach an MSP and its customers.
  • The vulnerabilities (CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726) allowed unauthorized access, arbitrary file downloads, uploads, and privilege escalation.
  • Arctic Wolf observed a targeted campaign exploiting these vulnerabilities shortly after their disclosure, potentially compromising devices using SimpleHelp client software.
  • Sophos found that the attackers used a legitimate SimpleHelp instance to deploy malicious software, compromising multiple customers, with some successfully defended by Sophos MDR and XDR services.

Read Full Article

like

20 Likes

For uninterrupted reading, download the app