Delinea Secret Server - also known as Thycotic Secret Server - is a privileged access management product which allows the storage and rotation of credentials.
Competitors include the likes of CyberArk. It is a Crown Jewels product, designed to manage.
The cloud offering is the Crown Jewels of Crown Jewels for organisations worldwide.
On Saturday they published indicators of compromise for the incident, behind a paywall: https://support.
Delinea Secret Server is a privileged access management solution that helps organizations secure, manage, and monitor privileged.
The vulnerability in that blog applies to Delinea Secret Server on prem - but also cloud.
The vulnerability is serious, as it allows authentication bypass and admin access.
The outage timeline simply says the issue was fixed after a deployment, and that endpoints blocked have been unblocked.
Delinea say they believe no customer data was impacted.
On prem customers need to update, and cloud customers need to hope Delinea understand exactly what happened and are transparent about outcomes.
This Cyber News was published on doublepulsar.com. Publication date: Sun, 14 Apr 2024 08:43:06 +0000