SecurityScorecard Identifies Infrastructure Linked to Widespread MOVEit Vulnerability Exploitation
ID: b2d99a71-be55-5d34-93e3-eaff64a59f7e
STIX ID: report--b2d99a71-be55-5d34-93e3-eaff64a59f7e
Feed Name: SecurityScorecard Blog
Threat Score
SecurityScorecard’s STRIKE team analyzes widespread exploitation of the critical MOVEit vulnerability (CVE-2023-34362) attributed to the Cl0p ransomware group, identifying webshells on compromised servers, extensive distributed scanning activity, specific IoCs (scanning and exfiltration IPs), evidence of multi-GB data transfers consistent with exfiltration, and affected organizations across government, healthcare, energy, education, and retail sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
