MOVEit Transfer has a major security issue - here's what you need to know

Hologram of security padlock operating on the electronic circuit CPU.
(Image credit: Getty Images)

The dust hasn’t even settled properly around the GoAnywhere MFT fiasco, and we already have another enterprise secure file transfer solution breached and abused for data theft. 

This time it’s MOVEit Transfer, a managed file transfer (MFT) solution built by a Ipswitch, a subsidiary of a company called Progress. 

The company has confirmed the discovery of a “critical” vulnerability, and urged its users to apply a workaround immediately in anticipation of an official patch.

Privilege escalation

"Progress has discovered a vulnerability in MOVEit Transfer that could lead to escalated privileges and potential unauthorized access to the environment," the company’s announcement states. 

"If you are a MOVEit Transfer customer, it is extremely important that you take immediate action as noted below in order to help protect your MOVEit Transfer environment, while our team produces a patch."

The company says that users should block external traffic to ports 80 and 443, which will most likely prevent external access to the web UI, as well as some automation tasks. APIs will stop working, as will the Outlook plugin, but customers can still use SFTP and FTP/s protocols to transfer files between endpoints

Furthermore, the users should inspect the 'c:\MOVEit Transfer\wwwroot\' folder for unexpected files, backups or large file downloads, as that seems to be the number one indicator of compromise, BleepingComputer also reported.

The details about the flaw and its abusers itself are still missing. We know it’s a zero-day, and that it can be used to extract sensitive files from the users. Cybersecurity researchers from Rapid7 believe this is an SQL injection flaw that allows for remote code execution. No CVE has yet been assigned. 

We also don’t know the flaw’s impact, but BleepingComputer has said its sources tell it “numerous organizations” have had their data stolen so far. There are at least 2,500 exposed transfer servers, mostly located in the United States. 

It’s safe to assume the attackers will try to extort money from the victims, in exchange for keeping the data private. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Data leak
US utility giant says MOVEit hack exposed stolen data
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
vpn
Ivanti warns another critical security flaw is being attacked
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Top file synchronization tool Rsync security flaws mean up to 660,000 servers possibly affected
An abstract image of padlocks overlaying a digital background.
BeyondTrust says hackers hit its remote support products
Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues