• New MOVEit Transfer zero-day mass-exploited in data theft attacks

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » New MOVEit Transfer zero-day mass-exploited in data theft attacks

    • This topic has 0 replies, 1 voice, and was last updated 4 months ago.
    Author
    Topic
    #2563540

    https://www.bleepingcomputer.com/news/security/new-moveit-transfer-zero-day-mass-exploited-in-data-theft-attacks/

    Hackers are actively exploiting a zero-day vulnerability in the MOVEit Transfer file transfer software, tracked as CVE-2023-34362, to steal data from organizations.

    MOVEit Transfer is a managed file transfer (MFT) solution developed by Ipswitch, a subsidiary of US-based Progress Software Corporation, that allows the enterprise to securely transfer files between business partners and customers using SFTP, SCP, and HTTP-based uploads…

    Yesterday, Progress released a security advisory warning customers of a “Critical” vulnerability in MOVEit MFT, offering mitigations until patches are installed.

    “Progress has discovered a vulnerability in MOVEit Transfer that could lead to escalated privileges and potential unauthorized access to the environment,” reads a security advisory from Progress.

    “If you are a MOVEit Transfer customer, it is extremely important that you take immediate action as noted below in order to help protect your MOVEit Transfer environment, while our team produces a patch.”

    To prevent exploitation, the developers warn admins to block external traffic to ports 80 and 443 on the MOVEit Transfer server…

    1 user thanked author for this post.
    Reply To: New MOVEit Transfer zero-day mass-exploited in data theft attacks

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: