logo

MOVEit Transfer Vulnerability

ID: 37507db8-a609-5057-8177-03f78b6f8de4

STIX ID: report--37507db8-a609-5057-8177-03f78b6f8de4

Feed Name: Censys Blog

Threat Score
88/100

Date Published: 2023-06-02

Date Updated: 2026-04-27

Author: Ivonne Francia

...
...

A critical SQL-injection vulnerability in Progress MOVEit Transfer (CVE-2023-34362) is being actively exploited in the wild, with observers linking attacks and large-scale data theft to threat actors including the Clop ransomware group; attackers have deployed web-shell backdoors (commonly at /human2.asp(x) that check a specific X-siLock-Comment header) and Censys/Greynoise telemetry indicates thousands of MOVEit instances (predominantly in the U.S. and across finance, healthcare, and government) are exposed and possibly compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.