logo

New MOVEit Vulnerability: What to Do NOW to Protect Your Organization

ID: e910bc3d-fef6-5dce-8bd7-a4ee63afa2bf

STIX ID: report--e910bc3d-fef6-5dce-8bd7-a4ee63afa2bf

Feed Name: Fidelis Security

Threat Score
90/100

Date Published: 2023-06-16

Date Updated: 2026-04-27

Author: admin_fidelis

...
...

On May 31, 2023 Progress disclosed CVE-2023-34362, a critical (CVSS 9.8) SQL injection in MOVEit Transfer that has been exploited in the wild by the Cl0p (TA505) ransomware group for data exfiltration; CISA added it to the Known Exploited Vulnerabilities catalog and FBI/CISA published an advisory. The report provides affected versions, exploitation details, IOCs and TTPs, and vendor and Fidelis guidance to immediately patch, block HTTP/S access, and review detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.