logo

Security alert: MOVEit Transfer exploited vulnerability

ID: 0e783619-7008-5869-a8ec-5631fa6b3e33

STIX ID: report--0e783619-7008-5869-a8ec-5631fa6b3e33

Feed Name: Expel Blog

Threat Score
85/100

Date Published: 2023-06-06

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

Expel observed active exploitation of CVE-2023-34362 in Progress MOVEit Transfer leading to deployment of a webshell (“human2.aspx”) that can create unauthorized accounts (“Health Check Service”) and enable data exfiltration or ransomware; the advisory details IOCs, recommended hunts (EDR, Azure blob/storage), removal steps (delete webshells, unauthorized users, rotate credentials/keys), and urgent patching and access-hardening measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.