MOVEit Transfer Vulnerabilities: Experts Discover New Flaws and Warn of Lingering Impact.

TL;DR Summary
Progress Software has released security updates to fix new SQL injection vulnerabilities in the MOVEit Transfer application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. All versions of MOVEit Transfer are affected by these vulnerabilities. The vulnerabilities were discovered by researchers from the cybersecurity firm Huntress. The Clop ransomware gang claims to have hacked hundreds of companies by exploiting a previous MOVEit Transfer vulnerability. Progress Software is not aware of attacks in the wild exploiting these new vulnerabilities.
- Experts found new MOVEit Transfer SQL Injection flaws Security Affairs
- Progress issues new patch for MOVEit Transfer after more vulnerabilities found SC Media
- New Critical MOVEit Transfer SQL Injection Vulnerabilities Discovered - Patch Now! The Hacker News
- Impact of MOVEIt file-transfer vulnerability will linger for months to come, researchers warn Axios
- Extreme Networks emerges as victim of Clop MOVEit attack ComputerWeekly.com
Reading Insights
Total Reads
0
Unique Readers
1
Time Saved
1 min
vs 2 min read
Condensed
66%
248 → 85 words
Want the full story? Read the original article
Read on Security Affairs