Search

Hackers Exploit Security Flaw in Popular File Transfer Tool MOVEit to Steal User Data

It was not immediately clear which or how many organizations use the software or were impacted by potential breaches.

Advertisement
Highlights
  • Progress Software had made fixes available
  • It discovered the vulnerability late on May 28
  • The software's eponymous cloud-based service had also been impacted
Hackers Exploit Security Flaw in Popular File Transfer Tool MOVEit to Steal User Data

Software maker Progress Software disclosed the vulnerability on Wednesday

Hackers have stolen data from the systems of a number of users of the popular file transfer tool MOVEit Transfer, US security researchers said on Thursday, one day after the maker of the software disclosed that a security flaw had been discovered.

Software maker Progress Software Corp, after disclosing the vulnerability on Wednesday, said it could lead to potential unauthorized access into users' systems.

The managed file transfer software made by the Burlington, Massachusetts-based company allows organizations to transfer files and data between business partners and customers.

It was not immediately clear which or how many organizations use the software or were impacted by potential breaches. Chief Information Officer Ian Pitt declined to share those details but said Progress Software had made fixes available since it discovered the vulnerability late on May 28.

The software's eponymous cloud-based service had also been impacted by this, he told Reuters.

"As of now we see no exploit of the cloud platform," he said.

Cybersecurity firm Rapid7 and Mandiant Consulting - owned by Alphabet's Google - said they had found a number of cases in which the flaw had been exploited to steal data.

"Mass exploitation and broad data theft have occurred over the past few days," Charles Carmakal, chief technology officer of Mandiant Consulting, said in a statement.

Such "zero-day," or previously unknown, vulnerabilities in managed file transfer solutions have led to data theft, leaks, extortion, and victim-shaming in the past, Mandiant said.

"Although Mandiant does not yet know the motivation of the threat actor, organizations should prepare for potential extortion and publication of the stolen data," Carmakal said.

Rapid7 said it had noticed an uptick in cases of compromise linked to the flaw since it was disclosed.

Progress Software has outlined steps users at risk can take to mitigate the impact of the security vulnerability.

Pitt did not have a comment on who might have been trying to steal data by exploiting the flaw.

"We have no evidence of it being used to spread malware," he said.

MOVEit Transfer was used by a relatively "small" number of customers compared to those of the company's other software products that number more than 20, he said.

"We have forensics partners on board and we are working with them to make sure that we have an ever-evolving grasp of the situation." 

© Thomson Reuters 2023 


Apple's annual developer conference is just around the corner. From the company's first mixed reality headset to new software updates, we discuss all the things we're looking forward to seeing at WWDC 2023 on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Hackers, MOVEit Transfer
 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Razr 60 Ultra, Edge 60 and Edge 60 Pro Price Leaked Online
  2. Vivo X200 Ultra Confirmed to Launch in April; Could Arrive With Vivo X200s
  3. Vivo T4 5G Set to Launch in India Soon; to Be Available on Flipkart
  4. Tecno Camon 40 Series to Get 3 Years of OS, 5 Years of Security Updates
  5. Nothing Adds Camera Capture Feature to Phone 3a's Essential Space
  6. Nothing Announces Phone 3a Community Edition Project
  7. Apple Faces Challenges Designing Plastic Watch SE Model: Report
  1. Airtel IPTV Services With Netflix and Bundled OTT Apps Launched in India: Price, Benefits
  2. New Research Suggests Dark Energy Is Evolving, Challenging Cosmology Models
  3. Pulsar Fusion’s Nuclear Fusion Rockets May Revolutionise Space Travel
  4. 30,000-Year-Old Vulture Feathers Discovered, Uniquely Preserved in Volcanic Ash
  5. ISRO and IIT Madras Unveil Research Centre for Space Thermal Sciences
  6. Google X Introduces Taara Chip to Enable High-Speed Internet via Light Beams
  7. Supernova Remnants Found in Oceanic Samples, Scientists Look to Moon
  8. ESA’s Euclid Telescope Releases First Data, Mapping 26 Million Galaxies
  9. Alien Life May Survive on Planets Orbiting White Dwarfs, Study Finds
  10. NASA Reviews Boeing Starliner’s Future Amid Technical Challenges
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »