Close Menu
New York Examiner News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Elon Musk’s Boring Co. is studying a tunnel project to Tesla Gigafactory near Reno

    January 17, 2026

    Democrats Won’t Allow Trump To Rig The Midterm As They Take A Big Step Toward Redistricting In Virginia

    January 17, 2026

    Minnesota judge bars federal officers from tear gas on peaceful protesters

    January 17, 2026
    Facebook X (Twitter) Instagram
    New York Examiner News
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    New York Examiner News
    Home»Technology»Hackers launch another wave of mass-hacks targeting company file transfer tools
    Technology

    Hackers launch another wave of mass-hacks targeting company file transfer tools

    By AdminJune 2, 2023
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Hackers launch another wave of mass-hacks targeting company file transfer tools


    Hackers launch another wave of mass-hacks targeting company file transfer tools

    Security researchers are sounding the alarm after hackers were caught exploiting a newly discovered vulnerability in a popular file transfer tool used by thousands of organizations to launch a new wave of mass data exfiltration attacks.

    The vulnerability affects the MOVEit Transfer managed file transfer (MFT) software developed by Ipswitch, a subsidiary of U.S.-based Progress Software, which allows organizations to share large files and data sets over the internet. Progress confirmed on Wednesday that it had discovered a vulnerability in MOVEit Transfer that “could lead to escalated privileges and potential unauthorized access to the environment,” and urged users to disable internet traffic to their MOVEit Transfer environment. 

    Patches are available and Progress is urging all customers to apply it urgently.

    U.S. cybersecurity agency CISA is also urging U.S. organizations to follow Progress’ mitigation steps, apply the necessary updates, and hunt for any malicious activity.

    Corporate file-transfer tools have become an increasingly attractive target for hackers, as finding a vulnerability in a popular enterprise system can allow the theft of data from multiple victims.

    Jocelyn VerVelde, a spokesperson for Progress via an outside public relations agency, declined to say how many organizations use the affected file transfer tool, though the company’s website states that the software is used by “thousands of organizations around the world.” Shodan, ​​a search engine for publicly exposed devices and databases, reveals more than 2,500 MOVEit Transfer servers discoverable on the internet, most of which are located in the United States, as well as the U.K., Germany, the Netherlands and Canada. 

    The vulnerability also impacts customers who rely on the MOVEit Transfer cloud platform, according to security researcher Kevin Beaumont. At least one exposed instance is connected to the U.S. Department of Homeland Security and several “big banks” are also believed to be MOVEIt customers also be affected, according to Beaumont.

    Several security companies say they have already observed evidence of exploitation.

    Mandiant said it is investigating “several intrusions” related to the exploitation of the MOVEit vulnerability. Mandiant chief technology officer Charles Carmakal confirmed that Mandiant had “seen evidence of data exfiltration at multiple victims.”

    Cybersecurity startup Huntress said in a blog post that one of its customers has seen “a full attack chain and all the matching indicators of compromise.”

    Security research firm Rapid7, meanwhile, confirmed it had observed signs of exploitation and data theft from “at least four separate incidents.” Caitlin Condon, senior manager of security research at Rapid7, said that the company has seen evidence that attackers may have begun automating exploitation.

    While it’s unclear exactly when exploitation began, threat intelligence startup GreyNoise said it has observed scanning activity as early as March 3 and urges users to review systems for any indicators of unauthorized access that may have occurred within the past 90 days.

    It’s not known who is yet responsible for the mass exploitation of MOVEit servers.

    Rapid7’s Condon told TechCrunch that the attacker’s behavior appears to be “opportunistic rather than targeted,” adding that this “could be the work of a single threat actor throwing one exploit indiscriminately at exposed targets.”

    It’s the latest effort by hackers and extortion groups to target enterprise file transfer systems in recent years.

    In January, the Russia-linked Clop ransomware gang claimed responsibility for the mass exploitation of a vulnerability in Fortra’s GoAnywhere managed file transfer software. More than 130 organizations using GoAnywhere were targeted, including Florida-based healthcare company NationBenefits, virtual therapy provider Brightline, and the City of Toronto.

    Clop was also behind another widespread attack on another popular file transfer tool in 2021. The gang breached Accellion’s file-sharing tool to launch attacks against a number of organizations, including Morgan Stanley, the University of California, grocery giant Kroger and law firm Jones Day.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleInside the huge London super sewer designed to fight river pollution
    Next Article Oregon Democrats plan to start fining GOP senators as boycott hits 1-month mark

    RELATED POSTS

    AI cloud startup Runpod hits $120M in ARR — and it started with a Reddit post  

    January 17, 2026

    Ads Are Coming to ChatGPT. Here’s How They’ll Work

    January 16, 2026

    Silicon Valley’s messiest breakup is definitely headed to court

    January 16, 2026

    Why ICE Can Kill With Impunity

    January 15, 2026

    Mira Murati’s startup, Thinking Machines Lab, is losing two of its co-founders to OpenAI

    January 15, 2026

    AI’s Hacking Skills Are Approaching an ‘Inflection Point’

    January 14, 2026
    latest posts

    Elon Musk’s Boring Co. is studying a tunnel project to Tesla Gigafactory near Reno

    Elon Musk’s tunneling startup Boring Company is working with a Nevada state-affiliated group to study…

    Democrats Won’t Allow Trump To Rig The Midterm As They Take A Big Step Toward Redistricting In Virginia

    January 17, 2026

    Minnesota judge bars federal officers from tear gas on peaceful protesters

    January 17, 2026

    AI cloud startup Runpod hits $120M in ARR — and it started with a Reddit post  

    January 17, 2026

    RFK, Jr., shifts focus to questioning whether cell phones are safe. Here’s what the science says

    January 17, 2026

    Next ‘Paranormal Activity’ Movie Lands Summer 2027 Date

    January 17, 2026

    ‘90 Day Fiance’ Big Ed Brown & Rose Vega Reconcile?

    January 17, 2026
    Categories
    • Books (1,006)
    • Business (5,911)
    • Events (29)
    • Film (5,847)
    • Lifestyle (3,957)
    • Music (5,947)
    • Politics (5,912)
    • Science (5,262)
    • Technology (5,841)
    • Television (5,525)
    • Uncategorized (6)
    • US News (5,899)
    popular posts

    Conservative Daily – Live with David and Erin Clements and Joe Hoft: SOROS-BACKED SOS CAUGHT LYING TO LEGISLATURE 27 March 2023

    Joe Hoft is a Radio Host at TNTRadio.live, Author, Former International Corporate Executive in Hong…

    Corbin Bleu & Tori Anderson Spark in Hallmark’s ‘Campfire Christmas’ (VIDEO)

    July 17, 2022

    A Rare Coincidence of La Niña Events Will Weaken Hurricane Season

    August 31, 2024

    Women of the Wildfires – The Poetry of Science

    May 5, 2024
    Archives
    Browse By Category
    • Books (1,006)
    • Business (5,911)
    • Events (29)
    • Film (5,847)
    • Lifestyle (3,957)
    • Music (5,947)
    • Politics (5,912)
    • Science (5,262)
    • Technology (5,841)
    • Television (5,525)
    • Uncategorized (6)
    • US News (5,899)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    Next ‘Paranormal Activity’ Movie Lands Summer 2027 Date

    January 17, 2026

    ‘90 Day Fiance’ Big Ed Brown & Rose Vega Reconcile?

    January 17, 2026

    EVERYDAY CARRY: Margin | FashionBeans

    January 17, 2026
    © 2026 New York Examiner News. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT