Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • Technology

CISA says hackers are exploiting a new file transfer bug in Citrix ShareFile

  • August 17, 2023
Total
0
Shares
0
0
0

Hackers are exploiting a newly discovered vulnerability in yet another enterprise file transfer software, the U.S. government’s cybersecurity agency has warned.

CISA on Wednesday added a vulnerability in Citrix ShareFile, tracked as CVE-2023-24489, to its Known Exploited Vulnerabilities (KEV) catalog. The agency warned that the flaw poses “significant risks to the federal enterprise,” and mandated that federal civilian executive branch agencies — CISA included — apply vendor patches by September 6.

Citrix first released a warning about the vulnerability back in June. The flaw, which was given a vulnerability severity rating of 9.8 out of 10, is described as an improper access control bug that could allow an unauthenticated attacker to remotely compromise customer-managed Citrix ShareFile storage zones controllers, no passwords needed.

While Citrix ShareFile is predominantly a cloud-based file-transfer tool, it also provides a “storage zones controller” tool that enables organizations to store files on-premise or with supported cloud platforms, such as Amazon S3 and Windows Azure.

According to Dylan Pindur of Assetnote, who first discovered the vulnerability and warned that it stems from small errors in ShareFile’s implementation of AES encryption, as many as 6,000 organizations had publicly exposed instances as of July.

“A search online shows roughly 1,000-6,000 instances are internet accessible,” said Pindur. “This popularity, combined with the software being used to store sensitive data, meant if we found anything it could have quite an impact.”

Threat intelligence startup GreyNoise said it observed a “significant spike” in attacker activity after CISA published its warning about the ShareFile vulnerability.

The identity of the hackers behind the observed in-the-wild attacks is not yet known.

Corporate file-transfer software has become a popular target for hackers as these systems often store huge batches of highly sensitive data.

The Russia-linked Clop ransomware gang alone has claimed responsibility for targeting at least three corporate tools, including Accellion‘s MTA, Fortra’s GoAnywhere MFT, and — most recently — Progress’ MOVEit Transfer.

According to the latest data from cybersecurity company Emsisoft, the ongoing MOVEit mass-attacks have so far claimed 668 victim organizations, affecting more than 46 million individuals. Just this week, it was revealed that more than four million Americans had their sensitive medical and health information stolen after IBM fell victim to the MOVEit hackers.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Apple is reportedly cutting iPhone 15 production due to ‘demand concerns’

  • August 17, 2023
View Post
Next Article
  • News

Baldur’s Gate 3 success means “room for this type of game” says director

  • August 17, 2023
View Post
You May Also Like
View Post
  • Technology

Disability tech startups kill the cynic in me

  • September 23, 2023
View Post
  • Technology

Walmart’s PhonePe launches app store with zero fee in challenge to Google

  • September 23, 2023
View Post
  • Technology

How CFOs can reduce SaaS spend by 30% in these tough times

  • September 22, 2023
View Post
  • Technology

LimeLoop’s sleek reusable mailers seek to replace cardboard boxes

  • September 22, 2023
View Post
  • Technology

AquaLith might have an answer to the US battery material shortage problem

  • September 22, 2023
View Post
  • Technology

Bay Area baby belly beholding Battlefield bounty

  • September 22, 2023
View Post
  • Technology

Unity U-turns on controversial runtime fee and begs forgiveness

  • September 22, 2023
View Post
  • Technology

Pitch Deck Teardown: Transcend’s $20M Series B deck

  • September 22, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.