Critical Vulnerability in Progress MOVEit Transfer:…
ID: a8d9cced-e044-5b2f-a8d9-83b2c44d2a6b
STIX ID: report--a8d9cced-e044-5b2f-a8d9-83b2c44d2a6b
Feed Name: TrustedSec blog
Progress MOVEit Transfer (CVE-2023-34362) suffers a SQL injection vulnerability that has been actively exploited to install an ASPX webshell/backdoor (notably human2.aspx) enabling unauthenticated listing and exfiltration of files and insertion of an administrative backdoor account; the report provides backdoor behavior, IOCs (filenames, HTTP headers, SHA256 hashes, IPs), detection steps, response recommendations (forensic investigation, rebuild from trusted backups) and vendor mitigations (fixed versions, block HTTP/S to MOVEit, rotate Azure storage keys).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
