Hackers Exploit Zero-Day Vulnerability in MOVEit Transfer for Data Theft

1 min read
Source: BleepingComputer
Hackers Exploit Zero-Day Vulnerability in MOVEit Transfer for Data Theft
Photo: BleepingComputer
TL;DR Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch their systems by June 23 to fix an actively exploited SQL injection vulnerability in Progress MOVEit Transfer, a managed file transfer solution. The flaw allows remote attackers to access the database and execute arbitrary code. Threat actors have been exploiting the vulnerability since at least May 27, with mass exploitation and data theft occurring. Private companies are also advised to prioritize securing their systems against the flaw. Progress advises all customers to patch their MOVEit Transfer instances or disable HTTP and HTTPS traffic to remote the attack surface.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

80%

511102 words

Want the full story? Read the original article

Read on BleepingComputer