#SysAid
After last week example (ERNW), here’s another infosec company (WatchTowr) which refused to abide by the vendor’s vulnerability disclosure terms

labs.watchtowr.com/sysowned-you...
May 11, 2025 at 4:38 PM
We are sharing SysAid instances likely vulnerable to CVE-2025-2775, CVE-2025-2776, CVE-2025-2777 (XXEs) any of which combined with CVE-2025-2778 allows for RCE.

77 IPs found unpatched so far (version check).

Install updates from SysAid (from March!) documentation.sysaid.com/docs/24-40-60
May 7, 2025 at 2:16 PM
SysAid flaw lets hackers hijack admin accounts — CISA confirms active attacks.

Attackers are exploiting two critical bugs (CVSS 9.3) to steal data & possibly execute code.

Patches are out. Deadline: Aug 12.
#CyberSecurity #CyberAttacks thehackernews.com/2025/07/cisa...
CISA Warns: SysAid Flaws Under Active Attack Enable Remote File Access and SSRF
SysAid bugs exploited in the wild; CISA mandates federal patching to stop potential admin takeovers.
thehackernews.com
July 23, 2025 at 4:35 PM
A 0-day vulnerability in SysAid IT Service Software was recently exploited to deploy ransomware. This underscores the urgency of maintaining strong cybersecurity measures, including timely patching, backups, and employee education to mitigate such risks effectively.

h4ckers.news/sysaid-it-se...
November 11, 2023 at 6:01 AM
-NY sets cybersecurity standards for water utilitie
-White House calls for an AI-ISAC
-Romania detains FTP gang members
-NoName057(16) returns with new DDoS attacks
-Amazon Q wiping incident
-SangTrap extortion campaign continues
-ESXi ransomware variants rise
-SysAid exploitation underway
July 25, 2025 at 8:19 AM
No login. Full access. One POST request.

A newly revealed exploit chain in on-prem SysAid lets attackers go from XXE injection to admin takeover—and that’s before combining it with OS-level command injection.
#cybersecurity
thehackernews.com/2025/05/sysa...

Admins, don’t wait—patch now.
SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
SysAid fixed 4 critical pre-auth flaws in March 2025; chained bugs allow full admin access and RCE.
thehackernews.com
May 7, 2025 at 9:41 PM
⭐️ Career opportunity!

Senior Product Designer (Full Time)
🌎 Tel Aviv, Israel

Learn more: https://uiuxjobsboard.com/job/1553426-senior-product-designer-tel-aviv-israel

#design #productdesign #careers #tech
Senior Product Designer at SysAid in Tel Aviv Israel
SysAid is hiring a Senior Product Designer in Tel Aviv Israel (August 2026). Description
uiuxjobsboard.com
August 12, 2026 at 12:00 PM
SysAid RCE (@SinSinology + @watchtowrcyber), defendnot (@es3n1n), iOS widget hacks (@brycebostwick.bsky.social), Sword of Secrets (@GiliYankovitch), and more!

blog.badsectorlabs.com/last-week-in...
Last Week in Security (LWiS) - 2025-05-12
SysAid RCE (@SinSinology + @watchtowrcyber), defendnot (@es3n1n), iOS widget hacks (@brycebostwick1), Sword of Secrets (@GiliYankovitch), and more!
blog.badsectorlabs.com
May 12, 2025 at 11:31 PM
SysAid and Splashtop Partner to Revolutionize Remote Support in ITSM#None#SysAid#ITSM#Splashtop
SysAid and Splashtop Partner to Revolutionize Remote Support in ITSM
SysAid has partnered with Splashtop to enhance secure remote support through its AI-native ITSM platform, improving issue resolution for IT teams.
third-news.com
March 23, 2026 at 11:07 AM
SysAid Achieves Notable Recognition in Gartner's 2025 Magic Quadrant for IT Service Management AI Applications#Canada#Toronto#Gartner#SysAid#IT_Service_Management
SysAid Achieves Notable Recognition in Gartner's 2025 Magic Quadrant for IT Service Management AI Applications
SysAid has garnered attention by being included in the 2025 Gartner Magic Quadrant for ITSM AI Applications, lauded for its customer satisfaction and innovation.
third-news.com
September 11, 2025 at 4:11 PM
CVE-2025-2775: PoC Released for SysAid On-Premises Pre-Auth RCE Vulnerability arcticwolf.com/resources/bl...
CVE-2025-2775 | Arctic Wolf
watchTowr publicly disclosed technical details and a proof-of-concept exploit for a pre-authenticated Remote Code Execution (chain affecting SysAid On-Premises, a self-hosted IT service management pla...
arcticwolf.com
May 8, 2025 at 2:49 AM
ITSM und KI

Wer von Euch nutzt ITSM-Software? Es gibt ein kostenfreies Webinar von Consist Software Solutions GmbH zu SysAid Copilot mit Künstlicher Intelligenz.

Details und den Link zur Anmeldung findet Ihr hier:
www.informatik-aktuell.de/aktuelle-mel...
Webinar SysAid Copilot: Kostenfreies Webinar
Lass generative KI die schwere Arbeit übernehmen, damit das Admin-Team außergewöhnlichen Service bieten kann, während deine End-User einen benutzerfreundlichen Support genießen und schneller zu den wi...
www.informatik-aktuell.de
March 19, 2025 at 7:40 AM
🚨 Design opportunity alert!

Senior Product Designer position at SysAid
🌎 Tel Aviv, Israel
⚡️ Full Time
✨ Ready to create amazing user experiences?

Apply now: https://uiuxjobsboard.com/job/1553426-senior-product-designer-tel-aviv-israel

#design #ux #careers #tech
Senior Product Designer at SysAid in Tel Aviv Israel
SysAid is hiring a Senior Product Designer in Tel Aviv Israel (August 2026). Description
uiuxjobsboard.com
August 12, 2026 at 5:00 AM
SANS Stormcast Thursday, May 8th: Modular Malware; Sysaid Vuln; Cisco Wireless Controller Patch; Unifi Protect Camera Patch
https://isc.sans.edu/podcastdetail/9442
May 8, 2025 at 3:25 AM
I asked someone that’s more up with tech stuff and they said SysAid. Is this what you meant or am I missing something obvious between the lines?

www.sysaid.com/lp/ai-help-d...
SysAid Help Desk Software
Meet the SysAid Help Desk. It does all the tasks you need, all on its own. No more manually sorting tickets or searching for assets.
www.sysaid.com
January 26, 2025 at 3:26 AM
SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version buff.ly/iG513lu
SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
SysAid fixed 4 critical pre-auth flaws in March 2025; chained bugs allow full admin access and RCE.
buff.ly
May 10, 2025 at 12:42 PM
millions of dollars go into researching and analyzing help desk software just to give you dogshit like sysaid and zendesk
April 29, 2025 at 4:31 PM
According to Microsoft, the CL0P ransomware found a zero-day vulnerability in SysAid On-Premise (CVE-2023-47246) and is exploiting it.

Hide your data.
SysAid On-Prem Software CVE-2023-47246 Vulnerability - SysAid
Written by Sasha Shapirov CTO @ SysAid & Profero Incident Response Team On Nov 2nd, a potential vulnerability in our on-premise software came to our security team’s attention. We immediately initiat...
www.sysaid.com
November 9, 2023 at 3:12 AM
Until we know what kind of stipulations SysAid demanded it's tough to assign any fault here.

Vendors in general have to be cognizant that they have to be nice to companies that are generously providing them free research, otherwise the best public good choice is to disclose the vuln.
May 11, 2025 at 5:04 PM
SysAid zero-day flaw exploited by Cl0p hacker gang
SysAid zero-day flaw exploited by Cl0p hacker gang
MOVEit hackers leverage new zero-day bug to breach organizations (CVE-2023-47246)
beyondmachines.net
November 9, 2023 at 9:12 PM
SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version

Cybersecurity researchers have disclosed multiple security flaw in the on-premise version of SysAid IT support software that could be exploited to achieve pre-authenticated remote code execution with…

#hackernews #ml #news
SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
Cybersecurity researchers have disclosed multiple security flaw in the on-premise version of SysAid IT support software that could be exploited to achieve pre-authenticated remote code execution with elevated privileges. The vulnerabilities, tracked as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777, have all been described as XML External Entity (XXE) injections, which occur when an attacker is
thehackernews.com
May 8, 2025 at 8:43 AM