Coverage Advisory for MOVEit
ID: 1d7a34ae-3eb5-5b6c-81d5-a016d799132b
STIX ID: report--1d7a34ae-3eb5-5b6c-81d5-a016d799132b
Feed Name: Zscaler Security Research Blog
**Executive Summary:** The advisory documents a critical SQL-injection vulnerability in MOVEit Transfer (CVE-2023-34362) that allows unauthenticated attackers to implant a webshell (commonly human2.aspx/LEMURLOOT), gain access to backend databases, perform data reconnaissance/exfiltration, and has been actively exploited by ransomware/data-theft actors (e.g., CL0P); it provides attack sequence details, IOCs (files, endpoints, custom headers), affected versions, mitigation steps, and vendor/CISA guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
