New 2024 MOVEit Transfer Vulnerability: What We Know So Far
ID: 6095f1ae-e285-51de-b2d3-6992fd43adfc
STIX ID: report--6095f1ae-e285-51de-b2d3-6992fd43adfc
Feed Name: ReliaQuest Blog
ReliaQuest advisory (June 25, 2024) describes CVE-2024-5806, a high-severity improper-authentication vulnerability in MOVEit Transfer’s SFTP module that can allow attackers to bypass authentication and access, modify, or delete files. A proof-of-concept exists and researchers report active exploitation in the wild; the advisory urges immediate patching, restricting network access, and monitoring for IOCs due to the risk of data exfiltration and extortion similar to prior Cl0p incidents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
