Security alert: MOVEit Transfer exploited vulnerability
ID: 0e783619-7008-5869-a8ec-5631fa6b3e33
STIX ID: report--0e783619-7008-5869-a8ec-5631fa6b3e33
Feed Name: Expel Blog
Threat Score
Expel observed active exploitation of CVE-2023-34362 in Progress MOVEit Transfer leading to deployment of a webshell (“human2.aspx”) that can create unauthorized accounts (“Health Check Service”) and enable data exfiltration or ransomware; the advisory details IOCs, recommended hunts (EDR, Azure blob/storage), removal steps (delete webshells, unauthorized users, rotate credentials/keys), and urgent patching and access-hardening measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
