MOVEit Transfer Vulnerability Actively Exploited
ID: bc10f0c2-cf67-5e2f-8b26-b5510e9e7287
STIX ID: report--bc10f0c2-cf67-5e2f-8b26-b5510e9e7287
Feed Name: Cyble Blog
The report documents active exploitation of a critical SQL injection flaw in MOVEit Transfer observed by Cyble Global Sensor Intelligence: attackers uploaded a human2.aspx webshell that authenticates via headers, executes SQL queries to enumerate and exfiltrate files and institutions, and can create or delete a 'Health Check Service' administrative account. The advisory includes technical code-level behavior, multiple SHA256 hashes and attacker IP/CIDR indicators, evidence of scanning and C2 infrastructure, and mitigation recommendations (patching, removing webshells, account resets, logging and segmentation).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
