logo

How File Transfer Software Became the #1 Third-Party Breach Vector

ID: 087b0c5a-3f97-50a2-907a-69f14f1f60a2

STIX ID: report--087b0c5a-3f97-50a2-907a-69f14f1f60a2

Feed Name: SecurityScorecard Blog

Threat Score
82/100

Date Published: 2025-08-22

Date Updated: 2026-04-29

...
...

SecurityScorecard reports that file transfer software has become the top exploited vector in third-party breaches in 2025, highlighting the MOVEit zero-day (CVE-2023-34362) and Cleo vulnerabilities (CVE-2024-50623, CVE-2024-55956) exploited by the C10p ransomware group; these campaigns accounted for a large share of vulnerability-driven third-party breaches and underscore the systemic supply-chain risk and need for vendor transparency, patching, and continuous vendor attack-surface monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.