• Latest
  • Trending
  • All
  • News
  • BUSINESS
  • SCIENCE
  • LIFESTYLE
  • TECH
Hackers launch another wave of mass-hacks targeting company file transfer tools

Hackers launch another wave of mass-hacks targeting company file transfer tools

June 2, 2023

Indulge in Opulence: Punctual’s Exquisite Stretch Limousines

September 22, 2023
Requiem for a Forgotten West Texas Cow Town

Requiem for a Forgotten West Texas Cow Town

September 22, 2023
Zendaya Sets the Record Straight on Tom Holland Engagement Rumors

Zendaya Sets the Record Straight on Tom Holland Engagement Rumors

September 22, 2023
Engadget Podcast: iPhone 15 Pro reviews, Microsoft picks AI over Surface

Engadget Podcast: iPhone 15 Pro reviews, Microsoft picks AI over Surface

September 22, 2023
How We Paid Off $28,000 Of Debt In 15 Months

How We Paid Off $28,000 Of Debt In 15 Months

September 22, 2023
Where to Watch & Stream Online

Where to Watch & Stream Online

September 22, 2023
Sessions to Hold Hearing with U.S. Postmaster General on Postal … – House Committee on Oversight and Reform |

Press Release | Press Releases | Newsroom | U.S. Senator Bill … – Senator Bill Cassidy

September 20, 2023
USA TODAY HSS Super 25 schedule week of Sept. 18

USA TODAY HSS Super 25 schedule week of Sept. 18

September 20, 2023
Check Out These 5 Fall Plus Size Shopping Tips to Help You Shop with Confidence!

Check Out These 5 Fall Plus Size Shopping Tips to Help You Shop with Confidence!

September 20, 2023
Buffalo Chicken Mac and Cheese

Buffalo Chicken Mac and Cheese

September 20, 2023
Suspended UMC Latina bishop accused of financial malfeasance and retaliation

Suspended UMC Latina bishop accused of financial malfeasance and retaliation

September 20, 2023

[4K] CENTURY CITY – Walking Tour of Century City Mall, West Los Angeles, USA – 4K UHD

September 20, 2023
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result
No Result
View All Result
Home TECH

Hackers launch another wave of mass-hacks targeting company file transfer tools

by Minnesota Digital News
June 2, 2023
in TECH
0
Hackers launch another wave of mass-hacks targeting company file transfer tools
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Security researchers are sounding the alarm after hackers were caught exploiting a newly discovered vulnerability in a popular file transfer tool used by thousands of organizations to launch a new wave of mass data exfiltration attacks.

The vulnerability affects the MOVEit Transfer managed file transfer (MFT) software developed by Ipswitch, a subsidiary of U.S.-based Progress Software, which allows organizations to share large files and data sets over the internet. Progress confirmed on Wednesday that it had discovered a vulnerability in MOVEit Transfer that “could lead to escalated privileges and potential unauthorized access to the environment,” and urged users to disable internet traffic to their MOVEit Transfer environment. 

Patches are available and Progress is urging all customers to apply it urgently.

U.S. cybersecurity agency CISA is also urging U.S. organizations to follow Progress’ mitigation steps, apply the necessary updates, and hunt for any malicious activity.

Corporate file-transfer tools have become an increasingly attractive target for hackers, as finding a vulnerability in a popular enterprise system can allow the theft of data from multiple victims.

Jocelyn VerVelde, a spokesperson for Progress via an outside public relations agency, declined to say how many organizations use the affected file transfer tool, though the company’s website states that the software is used by “thousands of organizations around the world.” Shodan, ​​a search engine for publicly exposed devices and databases, reveals more than 2,500 MOVEit Transfer servers discoverable on the internet, most of which are located in the United States, as well as the U.K., Germany, the Netherlands and Canada. 

The vulnerability also impacts customers who rely on the MOVEit Transfer cloud platform, according to security researcher Kevin Beaumont. At least one exposed instance is connected to the U.S. Department of Homeland Security and several “big banks” are also believed to be MOVEIt customers also be affected, according to Beaumont.

Several security companies say they have already observed evidence of exploitation.

Mandiant said it is investigating “several intrusions” related to the exploitation of the MOVEit vulnerability. Mandiant chief technology officer Charles Carmakal confirmed that Mandiant had “seen evidence of data exfiltration at multiple victims.”

Cybersecurity startup Huntress said in a blog post that one of its customers has seen “a full attack chain and all the matching indicators of compromise.”

Security research firm Rapid7, meanwhile, confirmed it had observed signs of exploitation and data theft from “at least four separate incidents.” Caitlin Condon, senior manager of security research at Rapid7, said that the company has seen evidence that attackers may have begun automating exploitation.

While it’s unclear exactly when exploitation began, threat intelligence startup GreyNoise said it has observed scanning activity as early as March 3 and urges users to review systems for any indicators of unauthorized access that may have occurred within the past 90 days.

It’s not known who is yet responsible for the mass exploitation of MOVEit servers.

Rapid7’s Condon told TechCrunch that the attacker’s behavior appears to be “opportunistic rather than targeted,” adding that this “could be the work of a single threat actor throwing one exploit indiscriminately at exposed targets.”

It’s the latest effort by hackers and extortion groups to target enterprise file transfer systems in recent years.

In January, the Russia-linked Clop ransomware gang claimed responsibility for the mass exploitation of a vulnerability in Fortra’s GoAnywhere managed file transfer software. More than 130 organizations using GoAnywhere were targeted, including Florida-based healthcare company NationBenefits, virtual therapy provider Brightline, and the City of Toronto.

Clop was also behind another widespread attack on another popular file transfer tool in 2021. The gang breached Accellion’s file-sharing tool to launch attacks against a number of organizations, including Morgan Stanley, the University of California, grocery giant Kroger and law firm Jones Day.



Source link

Share196Tweet123Share49
Minnesota Digital News

Minnesota Digital News

Saint Paul
◉
75°
Cloudy
6:21 am8:09 pm CDT
Feels like: 75°F
Wind: 9mph ESE
Humidity: 72%
Pressure: 30.19"Hg
UV index: 1
TueWedThuFri
100/79°F
97/72°F
90/68°F
84/61°F
Weather forecast Saint Paul, Minnesota ▸
TRAVEL

Indulge in Opulence: Punctual’s Exquisite Stretch Limousines

by Minnesota Digital News
September 22, 2023
Requiem for a Forgotten West Texas Cow Town
HISTORY

Requiem for a Forgotten West Texas Cow Town

by Minnesota Digital News
September 22, 2023
Zendaya Sets the Record Straight on Tom Holland Engagement Rumors
ENTERTAINMENT

Zendaya Sets the Record Straight on Tom Holland Engagement Rumors

by Minnesota Digital News
September 22, 2023
Engadget Podcast: iPhone 15 Pro reviews, Microsoft picks AI over Surface
GADGET

Engadget Podcast: iPhone 15 Pro reviews, Microsoft picks AI over Surface

by Minnesota Digital News
September 22, 2023
How We Paid Off $28,000 Of Debt In 15 Months
FINANCE

How We Paid Off $28,000 Of Debt In 15 Months

by Minnesota Digital News
September 22, 2023
Where to Watch & Stream Online
MOVIE

Where to Watch & Stream Online

by Minnesota Digital News
September 22, 2023
Sessions to Hold Hearing with U.S. Postmaster General on Postal … – House Committee on Oversight and Reform |
PRESS RELEASE

Press Release | Press Releases | Newsroom | U.S. Senator Bill … – Senator Bill Cassidy

by Minnesota Digital News
September 20, 2023
USA TODAY HSS Super 25 schedule week of Sept. 18
SPORTS

USA TODAY HSS Super 25 schedule week of Sept. 18

by Minnesota Digital News
September 20, 2023
Check Out These 5 Fall Plus Size Shopping Tips to Help You Shop with Confidence!
FASHION

Check Out These 5 Fall Plus Size Shopping Tips to Help You Shop with Confidence!

by Minnesota Digital News
September 20, 2023
Buffalo Chicken Mac and Cheese
FOOD

Buffalo Chicken Mac and Cheese

by Minnesota Digital News
September 20, 2023
Suspended UMC Latina bishop accused of financial malfeasance and retaliation
Religion

Suspended UMC Latina bishop accused of financial malfeasance and retaliation

by Minnesota Digital News
September 20, 2023
Shopping

[4K] CENTURY CITY – Walking Tour of Century City Mall, West Los Angeles, USA – 4K UHD

by Minnesota Digital News
September 20, 2023
Broadcom Stock Sees Another Big Insider Buy
BUSINESS

Broadcom Stock Sees Another Big Insider Buy

by Minnesota Digital News
September 20, 2023
A Pair of Sun Probes Just Got Closer to Solving a Solar Enigma
SCIENCE

A Pair of Sun Probes Just Got Closer to Solving a Solar Enigma

by Minnesota Digital News
September 20, 2023
10 Real Estate Deals in 18 Months After Losing 80% of His Income
REAL ESTATE

10 Real Estate Deals in 18 Months After Losing 80% of His Income

by Minnesota Digital News
September 20, 2023
10 Companies That Hire for Remote Admin Jobs
MONEY

10 Companies That Hire for Remote Admin Jobs

by Minnesota Digital News
September 20, 2023
Steelcase expects ‘significantly improved’ profit, as more employees return to offices
MARKET

Steelcase expects ‘significantly improved’ profit, as more employees return to offices

by Minnesota Digital News
September 20, 2023
USA VeeraSimhaReddy premier Fans Firstday theaters SLOGAN OF THE DAYYYY…..#JAIBALAYYA #Chicago
ARTS & THEATER

USA VeeraSimhaReddy premier Fans Firstday theaters SLOGAN OF THE DAYYYY…..#JAIBALAYYA #Chicago

by Minnesota Digital News
September 20, 2023
The Silly Story Behind The Weirdest Xbox Exclusive
GAMING

The Silly Story Behind The Weirdest Xbox Exclusive

by Minnesota Digital News
September 20, 2023
Minnesota Digital News

Copyright © 2023 Minnesota Digital News

Navigate Site

  • Disclaimer
  • Privacy Policy
  • Copyright Notice
  • Anti Spam Policy
  • Medical Disclaimer
  • DMCA Compliance
  • Terms and Conditions
  • Social Media Disclaimer
  • Amazon Affiliate disclaimer

Follow Us

No Result
View All Result
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds

Copyright © 2023 Minnesota Digital News