Zero-day vulnerability in MOVEit Transfer tool exploited in data theft attacks.

1 min read
Source: BleepingComputer
Zero-day vulnerability in MOVEit Transfer tool exploited in data theft attacks.
Photo: BleepingComputer
TL;DR Summary

Hackers are exploiting a zero-day vulnerability in the MOVEit Transfer file transfer software to steal data from organizations. The flaw is a SQL injection vulnerability that leads to remote code execution and does not currently have a CVE assigned to it. Cybersecurity firm Rapid7 says that the MOVEit Transfer flaw is a SQL injection vulnerability that leads to remote code execution and does not currently have a CVE assigned to it. The attacks started over the long US Memorial Day holiday when fewer staff were monitoring systems.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

5 min

vs 6 min read

Condensed

92%

1,09587 words

Want the full story? Read the original article

Read on BleepingComputer