Progress Software elevates severity of new MOVEit bug to ‘critical’ as exploit attempts jump
ID: 0c007b18-fcb3-54a3-9d19-fcf3924957da
STIX ID: report--0c007b18-fcb3-54a3-9d19-fcf3924957da
Feed Name: The Record from Recorded Future News
Progress Software disclosed CVE-2024-5806 in MOVEit Transfer (and MOVEit Gateway) and warned that a newly identified third-party component vulnerability elevates the risk if left unpatched; the vendor issued a patch on June 11, but published proof-of-concept code and subsequent scanning/exploit attempts were reported by researchers and organizations (Shadowserver, Censys, German government), with thousands of MOVEit instances exposed and potential for data exfiltration reminiscent of the large-scale 2023 Clop campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
