MoveIt 3rd Vulnerability Exposed!

In a recent turn of events, Progress Software, a global technology firm, has identified a third security vulnerability within its MOVEit Transfer application. This application is typically used for secure data transfer among businesses, and this flaw has been exploited in a wave of cyber attacks by the Cl0p group, notorious for their ransomware attacks.

The vulnerability is a type of bug known as an SQL injection, which could allow unauthorized individuals to gain undue access and privileges. As an immediate response, Progress Software is urging its users to halt specific internet traffic to the MOVEit Transfer until a fix is developed and released.

Interestingly, this is not a one-off incident. A week prior, Progress Software brought to light a similar SQL injection bug. In addition, another vulnerability (CVE-2023-34362) has been identified and was exploited by Cl0p as early as July 2021.

Cl0p has taken responsibility for breaching the security of 27 companies, including multiple U.S. federal agencies, through this vulnerability. The actual number of affected organizations may be much larger than the figures from Cl0p’s previous campaign.

A study by Censys, an internet device search platform, reveals that a significant percentage of the exposed systems (around 31%) belong to the financial services industry, followed by healthcare, IT, and government/military sectors. Furthermore, approximately 80% of these vulnerable servers are based in the U.S. This issue underscores the need for heightened security measures across these sectors as Progress Software diligently works towards a resolution.

Related articles

You may also be interested in

Free mail phishing scam vector

6 Simple Steps to Enhance Your Email Security

Email is a fundamental communication tool for businesses and individuals alike. But it’s also a prime target for cybercriminals. Cyberattacks are increasing in sophistication. This

Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.
Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Hot daily news right into your inbox.