MOVEit Transfer Vulnerability
ID: 37507db8-a609-5057-8177-03f78b6f8de4
STIX ID: report--37507db8-a609-5057-8177-03f78b6f8de4
Feed Name: Censys Blog
A critical SQL-injection vulnerability in Progress MOVEit Transfer (CVE-2023-34362) is being actively exploited in the wild, with observers linking attacks and large-scale data theft to threat actors including the Clop ransomware group; attackers have deployed web-shell backdoors (commonly at /human2.asp(x) that check a specific X-siLock-Comment header) and Censys/Greynoise telemetry indicates thousands of MOVEit instances (predominantly in the U.S. and across finance, healthcare, and government) are exposed and possibly compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
