logo

SecurityScorecard Identifies Infrastructure Linked to Widespread MOVEit Vulnerability Exploitation

ID: b2d99a71-be55-5d34-93e3-eaff64a59f7e

STIX ID: report--b2d99a71-be55-5d34-93e3-eaff64a59f7e

Feed Name: SecurityScorecard Blog

Threat Score
80/100

Date Published: 2024-06-28

Date Updated: 2026-04-29

...
...

SecurityScorecard’s STRIKE team analyzes widespread exploitation of the critical MOVEit vulnerability (CVE-2023-34362) attributed to the Cl0p ransomware group, identifying webshells on compromised servers, extensive distributed scanning activity, specific IoCs (scanning and exfiltration IPs), evidence of multi-GB data transfers consistent with exfiltration, and affected organizations across government, healthcare, energy, education, and retail sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.