logo

The MOVEit Zero-Day Vulnerability: How to Respond | UpGuard

ID: c3a9025a-31b3-5018-83bd-1075d0ae007d

STIX ID: report--c3a9025a-31b3-5018-83bd-1075d0ae007d

Feed Name: UpGuard Blog

Threat Score
90/100

Date Published: 2025-07-11

Date Updated: 2026-05-01

...
...

This report describes an actively exploited zero-day SQL injection in Progress MOVEit Transfer used by the Cl0p ransomware gang and other actors to exfiltrate sensitive data from numerous organizations (including private sector and federal agencies). It documents observed IoCs (human2.aspx, *.cmdline, APP_WEB_*.dll), attack timeline, mitigation steps (disable HTTP/S, remove malicious files/accounts, rotate keys, patch), and monitoring recommendations to limit further data theft and ransomware impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.