Hackers target new MOVEit Transfer critical auth bypass bug
ID: 1fdf28cf-154d-5ec3-ba60-6bb4b46a70ca
STIX ID: report--1fdf28cf-154d-5ec3-ba60-6bb4b46a70ca
Feed Name: Bleeping Computer
A critical authentication bypass (CVE-2024-5806) in Progress MOVEit Transfer's SFTP module has been disclosed and is being actively probed and exploited in the wild; public proof-of-concept code exists and threat actors were observed attempting exploitation shortly after disclosure. Approximately 2,700 internet-exposed MOVEit instances were identified, vendor patches and mitigations have been released for affected versions, and organizations are urged to apply updates or mitigations immediately to prevent unauthorized access, data theft, file modification, or tampering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
