SysAid disclosed that the Cl0p ransomware group exploited a previously unknown flaw in its on-premise IT service management software, later tracked as CVE-2023-47246. The company issued a security notification for affected on-prem deployments, confirming active exploitation of the vulnerability and prompting customers to investigate for compromise and apply vendor guidance.
Follow-on research from SecurityScorecard found 576 internet-exposed IP addresses associated with 330 organizations in 36 countries that may have hosted vulnerable SysAid instances. Despite that broad exposure, the observed exploitation footprint appeared comparatively limited: researchers identified only one IP address that overlapped between potentially vulnerable-instance discovery and traffic linked to SysAid’s published indicators of compromise, suggesting a narrower campaign than some previous Cl0p zero-day operations while underscoring the group’s continued ability to weaponize newly discovered flaws.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
SysAid disclosed that the Cl0p ransomware group had exploited a previously unknown vulnerability in its on-premise IT Service Management software. The flaw was tracked as CVE-2023-47246, and SysAid provided indicators of compromise tied to the campaign.
SecurityScorecard analyzed Attack Surface Intelligence and partner NetFlow data to estimate exposure and victimization related to CVE-2023-47246. It identified 576 internet-exposed IP addresses across 330 organizations in 36 countries that may host affected SysAid instances, with only one IP overlapping with traffic to SysAid IoC-linked infrastructure in the reviewed sample.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.