Sicherheitslücke: MOVEit Transfer ist für Attacken anfällig

Ein Patch schließt eine Schwachstelle in der Dateiübertragungssoftware MOVEit Transfer.

heise online
Critical MOVEit vulnerability puts huge swaths of the Internet at severe risk

A similar flaw last year left 1,800 networks breached. Will the latest one be as potent?

Ars Technica

Progress Software has patched one critical (CVE-2024-5805) and one high-risk (CVE-2024-5806) vulnerability in MOVEit, its widely used managed file transfer (MFT) software product.

WatchTowr has outlined an exploit chain for CVE-2024-5806 and has published a PoC.

https://www.helpnetsecurity.com/2024/06/25/cve-2024-5805-cve-2024-5806/

#Cybersecurity #CVE #MOVEitTransfer

Progress quietly fixes MOVEit auth bypass flaws (CVE-2024-5805, CVE-2024-5806) - Help Net Security

Progress Software has patched one critical (CVE-2024-5805) and one high-risk (CVE-2024-5806) vulnerability in MOVEit MFT.

Help Net Security

Missed my opportunity to dress up as the Progress Software MoveIt logo for #halloween.

Ah, well, I'm sure I'll get my opportunity with another 0-day next year.

#halloween2023 #moveit #moveittransfer

Den Spruch kann die Pan American Life Insurance Group jetzt von der Webseite verbannen. Die Cl0p Hacker haben die ersten Daten veröffentlicht.

#cyberattack #cyberangriff #clop #cl0p #security #vulnerability #moveit #MOVEitTransfer

Great resource for MOVEit timeline, vulns, exploits, research, IOCs, detections, victims, and news.

https://github.com/curated-intel/MOVEit-Transfer

#InfoSec #intel #IR #Incident #IncidentResponse #MOVEit #MOVEitTransfer

GitHub - curated-intel/MOVEit-Transfer: A repository for tracking events related to the MOVEit Transfer Cl0p Campaign

A repository for tracking events related to the MOVEit Transfer Cl0p Campaign - GitHub - curated-intel/MOVEit-Transfer: A repository for tracking events related to the MOVEit Transfer Cl0p Campaign

GitHub
MCKSys Argentina on Twitter

“As promised, here's a pic of the Poc for CVE-2023-35036 (Progress MOVEit Transfer). As soon as I can get RCE, I'll upload the final PoC to github. Any ideas/suggestions are welcomed!”

Twitter
CISA Order Highlights Persistent Risk at Network Edge – Krebs on Security

CISA Order Highlights Persistent Risk at Network Edge – Krebs on Security

CISA Order Highlights Persistent Risk at Network Edge – Krebs on Security