logo

MOVEit Transfer Vulnerability Actively Exploited

ID: bc10f0c2-cf67-5e2f-8b26-b5510e9e7287

STIX ID: report--bc10f0c2-cf67-5e2f-8b26-b5510e9e7287

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2024-09-16

Date Updated: 2026-07-20

...
...

The report documents active exploitation of a critical SQL injection flaw in MOVEit Transfer observed by Cyble Global Sensor Intelligence: attackers uploaded a human2.aspx webshell that authenticates via headers, executes SQL queries to enumerate and exfiltrate files and institutions, and can create or delete a 'Health Check Service' administrative account. The advisory includes technical code-level behavior, multiple SHA256 hashes and attacker IP/CIDR indicators, evidence of scanning and C2 infrastructure, and mitigation recommendations (patching, removing webshells, account resets, logging and segmentation).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.