Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

New MOVEit Transfer critical flaws found after security audit

  • June 12, 2023
Total
0
Shares
0
0
0


Progress Software, the company behind the MOVEit secure managed file transfer (MFT) tool, has warned users it has found a separate vulnerability that can also be used to steal their sensitive data with malware, and urged them to apply the newly released patch – immediately.

Earlier this month, it was revealed that MOVEit carried a high severity flaw that allowed threat actors to exfiltrate data from an undisclosed number of users, highly likely in the hundreds. 

The vulnerability is tracked as CVE-2023-34362. Soon after news broke, a threat actor known as Clop, a hacking group allegedly affiliated with the Russian government, assumed responsibility for the attack, saying data samples will soon appear on its data leak site, and that the negotiations with affected clients are ongoing.

Code audit

MOVEit is a file transfer tool used by enterprises, as well as small and medium-sized businesses (SMB), to share sensitive data, such as personally identifiable information, banking data, health information, and similar, in a secure manner. That helps businesses prevent incidents that can lead to identity theft, wire fraud, and more.

In response to the incident, Progress conducted a detailed code review with the help of the cybersecurity firm Huntress, which is when the new bug was discovered. It’s described as an SQL injection flaw that can enable data exfiltration and theft. All versions of MOVEit are affected, it was added. 

“An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content,” Progress said. “All MOVEit Transfer customers must apply the new patch, released on June 9, 2023. The investigation is ongoing, but currently, we have not seen indications that these newly discovered vulnerabilities have been exploited,” the company added.

MOVEit Cloud has already been patched, the company added.

Via: BleepingComputer


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Canon PowerShot concept suggests it’s preparing to take on Insta360

  • June 12, 2023
View Post
Next Article
  • News

Google wants to help provide faster AI photo editing for all

  • June 12, 2023
View Post
You May Also Like
View Post
  • News

Say goodbye to Google Podcasts, you’ll be forced to use YouTube Music by 2024

  • September 26, 2023
View Post
  • News

Microsoft Paint is getting its biggest upgrade in over a decade thanks to Windows Copilot

  • September 26, 2023
View Post
  • News

NFT marketplace OpenSea has been hacked, again

  • September 26, 2023
View Post
  • News

LG drops ATSC 3.0 4K tuners from its 2024 OLED TVs and Samsung or Sony could be next

  • September 26, 2023
View Post
  • News

CISOs are spending more on cybersecurity – but it might not be enough

  • September 26, 2023
View Post
  • News

iPhone 15 delays: latest delivery estimates for every model

  • September 26, 2023
View Post
  • News

Hideki Kamiya thanks fans for their support after leaving PlatinumGames and says he will keep making games

  • September 26, 2023
View Post
  • News

SAP goes all-in on AI with new Joule copilot

  • September 26, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.