Qualys Hacked Using Accellion Zero-day Vulnerability
ID: 871cf91e-06b6-593f-b924-0262543565c1
STIX ID: report--871cf91e-06b6-593f-b924-0262543565c1
Feed Name: Cyble Blog
The report documents Clop ransomware's exploitation of Accellion FTA (including a disclosed zero-day and subsequent CVEs) to deploy web shells, exfiltrate sensitive files from multiple organizations, and publish stolen data on a darkweb leak site; it includes technical details (CVE-2021-27101/27102/27103/27104, web-shell file paths), observed victim incidents (Qualys, ExecuPharm, V Cargo, Bombardier, Fugro), and mitigation recommendations such as patching to FTA_9_12_432+, auditing accounts, and increasing access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
