APT Expands Attack on ManageEngine With Active Campaign Against ServiceDesk PlusPalo Alto Unit 42·Jun 6, 01:25 UTC · Jun 6, 2024Threat actor in the wildCVE-2021-44077CVE-2021-3361760
Patch your Zoho ManageEngine instance immediately! PoC Exploit for CVE-2022Security Affairs·Jan 19, 19:29 UTC · Jan 19, 2023Exploit / PoCCVE-2022-4796660
Critical ManageEngine vulns affect majority of Fortune 500 companiesCyberScoop·Mar 23, 21:51 UTC · Mar 23, 2018Exploit / PoC in the wild60
Nation-state actors exploit Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus, CISA warnsSecurity Affairs·Sep 8, 12:06 UTC · Sep 8, 2023Threat actor in the wildCVE-2022-47966CVE-2022-42475CVE-2021-4422860
Expert publicly discloses Zoho ManageEngine zeroSecurity Affairs·Mar 9, 14:55 UTC · Mar 9, 2020RansomwareCVE-2020-1018960
Attackers exploit another zero-day in ManageEngine software (CVE-2021-44515)Help Net Security·Dec 21, 09:45 UTC · Dec 21, 2021Exploit / PoCCVE-2021-44515CVE-2021-4407760
Hackers are compromising vulnerable ManageEngine Desktop Central instancesHelp Net Security·Aug 10, 07:29 UTC · Aug 10, 2020Exploit / PoC in the wildCVE-2020-1018960
Experts released PoC exploit for Zoho ManageEngine RCE flawSecurity Affairs·Jan 19, 20:51 UTC · Jan 19, 2023Exploit / PoCCVE-2022-4796660
Hackers are actively exploiting Zoho ManageEngine flawSecurity Affairs·Feb 24, 11:01 UTC · Feb 24, 2023Ransomware in the wildCVE-2022-4796660
PoC for critical ManageEngine bug to be released, so get patching! (CVE-2022-47966)Help Net Security·Feb 21, 17:23 UTC · Feb 21, 2023Exploit / PoC in the wildCVE-2022-4796660
Hackers exploiting vulnerability affecting Zoho ManageEngine products: Rapid7The Record·Feb 3, 00:00 UTC · Feb 3, 2023Vulnerability in the wildCVE-2022-47966CVE-2021-4053960
Zoho ManageEngine PoC Exploit to be Released SoonThe Hacker News·Jan 21, 04:44 UTC · Jan 21, 2023Exploit / PoCCVE-2022-4796660
Researchers Warn Against Zoho ManageEngine Exploit AttacksInfosecurity Magazine·Jan 17, 17:00 UTC · Jan 17, 2023Exploit / PoCCVE-2022-4796660
Determined APT is exploiting ManageEngine ServiceDesk Plus vulnerability (CVE-2021-44077)Help Net Security·Dec 3, 00:00 UTC · Dec 3, 2021Vulnerability in the wildCVE-2021-44077CVE-2021-33617160
CISA Warns of Actively Exploited Zoho ManageEngine ADSelfService VulnerabilityThe Hacker News·Sep 17, 04:49 UTC · Sep 17, 2021Vulnerability in the wildCVE-2021-40539CVE-2021-37421CVE-2021-37417+3 CVEs60
CISA added Zoho ManageEngine RCE (CVE-2022-47966) to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Jan 24, 11:03 UTC · Jan 24, 2023Exploit / PoC in the wildCVE-2022-4796660
Zoho urges fixing a critical SQL Injection flaw in ManageEngineSecurity Affairs·Jan 5, 15:21 UTC · Jan 5, 2023Vulnerability in the wildCVE-2022-47523CVE-2022-3540560
Experts shared PoC exploit code for RCE in Zoho ManageEngine ADAudit Plus toolSecurity Affairs·Jul 2, 19:42 UTC · Jul 2, 2022Exploit / PoCCVE-2022-28219CVE-2020-1018960
Critical ManageEngine ADSelfService Plus RCE flaw patchedHelp Net Security·Aug 10, 00:00 UTC · Aug 10, 2020VulnerabilityCVE-2020-1155260
Simplifying SSH keys and SSL Certs Management across the Enterprise using Key Manager PlusThe Hacker News·Nov 2, 06:52 UTC · Nov 2, 2016Threat actor60
CISA adds Zoho ManageEngine flaw to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Sep 23, 15:13 UTC · Sep 23, 2022Exploit / PoC in the wildCVE-2022-3540560
Critical ManageEngine RCE flaw is being exploited (CVE-2022-35405)Help Net Security·Sep 23, 00:00 UTC · Sep 23, 2022Vulnerability in the wildCVE-2022-3540560
CISA Warns of Actively Exploited Critical Zoho ManageEngine ServiceDesk VulnerabilityThe Hacker News·Dec 3, 13:34 UTC · Dec 3, 2021Vulnerability in the wildCVE-2021-44077CVE-2021-4053960
ManageEngine expands Endpoint Central with EDR and secure accessHelp Net Security·Mar 25, 09:52 UTC · Mar 25, 2026Ransomware60
Critical vulnerability in ManageEngine could lead to file creation, dozens of other vulnerabilities disclosed by Talos to start 2024Cisco Talos·Jan 18, 13:56 UTC · Jan 18, 2024VulnerabilityCVE-2023-47211CVE-2023-38618CVE-2023-38621+52 CVEs60
ManageEngine launches PAM360, a privileged access security solution for enterprise ITHelp Net Security·Dec 14, 12:39 UTC · Dec 14, 2023Data breach60
Lazarus APT exploits Zoho ManageEngine flaw to target an Internet backbone infrastructure providerSecurity Affairs·Aug 24, 17:50 UTC · Aug 24, 2023Threat actorCVE-2022-4796660
Vulnerability Spotlight: Vulnerability in ManageEngine OpManager could lead to XXE attackCisco Talos·Mar 30, 19:00 UTC · Mar 30, 2023Vulnerability in the wildCVE-2022-4347360
Zoho Releases Patch for Critical Flaw Affecting ManageEngine Desktop CentralThe Hacker News·Jan 18, 10:03 UTC · Jan 18, 2022VulnerabilityCVE-2021-44757CVE-2021-40539CVE-2021-44077+1 CVEs60
Experts Detail Malicious Code Dropped Using ManageEngine ADSelfService ExploitThe Hacker News·Nov 9, 03:15 UTC · Nov 9, 2021Exploit / PoC in the wildCVE-2021-4053960
Multiple zero-day vulnerabilities found in ManageEngine productsHelp Net Security·Jan 31, 00:00 UTC · Jan 31, 2018Exploit / PoC60
ManageEngine unveils ML-powered exploit triad analytics featureHelp Net Security·Feb 20, 00:00 UTC · Feb 20, 2024Data breach60
Experts Sound Alarm Over Growing Attacks Exploiting Zoho ManageEngine ProductsThe Hacker News·Feb 24, 05:28 UTC · Feb 24, 2023RansomwareCVE-2022-4796660
CISA Warns of Hackers Exploiting Recent Zoho ManageEngine VulnerabilityThe Hacker News·Sep 26, 04:47 UTC · Sep 26, 2022Vulnerability in the wildCVE-2022-3540560
Week in review: Revolut data breach, ManageEngine RCE flaw, free Linux security training coursesHelp Net Security·Sep 25, 00:00 UTC · Sep 25, 2022Data breach in the wildCVE-2007-4559CVE-2022-35405CVE-2022-31671+4 CVEs60
Nation-state actors are exploiting Zoho zero-day CVE-2021Security Affairs·Dec 20, 21:25 UTC · Dec 20, 2021Exploit / PoC in the wildCVE-2021-4451560
FBI, CISA, and CGCYBER warn of nation-state actors exploiting CVE-2021Security Affairs·Sep 16, 22:07 UTC · Sep 16, 2021Threat actor in the wildCVE-2021-4053960
Lazarus Group Exploits Critical Zoho ManageEngine Flaw to Deploy Stealthy QuiteRAT MalwareThe Hacker News·Aug 25, 06:26 UTC · Aug 25, 2023MalwareCVE-2022-4796660
Lazarus Group exploited ManageEngine vulnerability to target critical infrastructureHelp Net Security·Aug 25, 00:00 UTC · Aug 25, 2023Vulnerability in the wildCVE-2022-4796660
CISA warns of Zoho server zeroThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Advisory in the wildCVE-2021-40539CVE-2020-1018960