New MOVEit Transfer critical flaws found after security audit
Progress Software, the company behind the MOVEit secure managed file transfer (MFT) tool, has warned users it has found a separate vulnerability that can also be used to steal their sensitive data with malware, and urged them to apply the newly released patch – immediately.
Earlier this month, it was revealed that MOVEit carried a high severity flaw that allowed threat actors to exfiltrate data from an undisclosed number of users, highly likely in the hundreds.
The vulnerability is tracked as CVE-2023-34362. Soon after news broke, a threat actor known as Clop, a hacking group allegedly affiliated with the Russian government, assumed responsibility for the attack, saying data samples will soon appear on its data leak site, and that the negotiations with affected clients are ongoing.
Code audit
MOVEit is a file transfer tool used by enterprises, as well as small and medium-sized businesses (SMB), to share sensitive data, such as personally identifiable information, banking data, health information, and similar, in a secure manner. That helps businesses prevent incidents that can lead to identity theft, wire fraud, and more.
In response to the incident, Progress conducted a detailed code review with the help of the cybersecurity firm Huntress, which is when the new bug was discovered. It’s described as an SQL injection flaw that can enable data exfiltration and theft. All versions of MOVEit are affected, it was added.
“An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content,” Progress said. “All MOVEit Transfer customers must apply the new patch, released on June 9, 2023. The investigation is ongoing, but currently, we have not seen indications that these newly discovered vulnerabilities have been exploited,” the company added.
MOVEit Cloud has already been patched, the company added.
Via: BleepingComputer
Progress Software, the company behind the MOVEit secure managed file transfer (MFT) tool, has warned users it has found a separate vulnerability that can also be used to steal their sensitive data with malware, and urged them to apply the newly released patch – immediately. Earlier this month, it was…
Recent Posts
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- NordVPN Coupons and Deals: 77% Off in June 2026
- You don’t need to spend a fortune on good audio — these 20 headphones under AU$100 have hundreds of 5-star user reviews
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023