Economic news

Hackers use flaw in popular file transfer tool to steal data, U.S. researchers say

2023.06.01 19:56


© Reuters. FILE PHOTO: A computer keyboard lit by a displayed cyber code is seen in this illustration picture taken on March 1, 2017. REUTERS/Kacper Pempel/Illustration

By Zeba Siddiqui

SAN FRANCISCO (Reuters) – Hackers have stolen data from the systems of a number of users of the popular file transfer tool MOVEit Transfer, U.S. security researchers said on Thursday, one day after the maker of the software disclosed that a security flaw had been discovered.

Software maker Progress Software (NASDAQ:), after disclosing the vulnerability on Wednesday, said it could lead to potential unauthorized access into users’ systems.

The managed file transfer software made by Burlington, Massachusetts-based Progress allows organizations to securely transfer files and data between business partners and customers, and according to the company is used by thousands of organizations.

Google (NASDAQ:)’s Mandiant consulting and cybersecurity firm Rapid7 (NASDAQ:) disclosed on Thursday that they had found a number of cases in which the flaw had been exploited to steal user data.

It wasn’t immediately clear how many users were impacted, but Mandiant Consulting said it was investigating “several” intrusions linked to the bug.

It was not known when the flaw was discovered by hackers. A Progress Software spokeswoman didn’t immediately respond to a request for further comment.

“Mass exploitation and broad data theft has occurred over the past few days,” Charles Carmakal, chief technology officer of Mandiant Consulting, said in a statement.

Such “zero-day,” or previously unknown, vulnerabilities in managed file transfer solutions have led to data theft, leaks, extortion and victim shaming in the past, according to Mandiant.

“Although Mandiant does not yet know the motivation of the threat actor, organizations should prepare for potential extortion and publication of the stolen data,” Carmakal added.

Rapid7 said it had noticed an uptick in cases of compromise linked to the flaw since it was disclosed.

Progress, in a statement on Wednesday, outlined steps users at risk can take to mitigate the impact of the security vulnerability.

Source link

Related Articles

Back to top button
bitcoin
Bitcoin (BTC) $ 103,022.60 3.78%
ethereum
Ethereum (ETH) $ 2,339.85 19.47%
tether
Tether (USDT) $ 1.00 0.03%
xrp
XRP (XRP) $ 2.39 8.01%
bnb
BNB (BNB) $ 638.56 3.99%
solana
Solana (SOL) $ 172.06 11.00%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.207116 12.62%
cardano
Cardano (ADA) $ 0.792946 9.75%
tron
TRON (TRX) $ 0.261338 4.35%
staked-ether
Lido Staked Ether (STETH) $ 2,339.97 19.35%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 102,905.57 3.59%
sui
Sui (SUI) $ 3.97 4.58%
chainlink
Chainlink (LINK) $ 16.18 8.60%
avalanche-2
Avalanche (AVAX) $ 23.42 11.85%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,803.08 18.82%
stellar
Stellar (XLM) $ 0.299372 9.05%
shiba-inu
Shiba Inu (SHIB) $ 0.000015 12.79%
hedera-hashgraph
Hedera (HBAR) $ 0.200342 7.66%
bitcoin-cash
Bitcoin Cash (BCH) $ 415.10 1.02%
hyperliquid
Hyperliquid (HYPE) $ 24.64 14.10%
the-open-network
Toncoin (TON) $ 3.28 5.13%
leo-token
LEO Token (LEO) $ 8.73 0.69%
usds
USDS (USDS) $ 1.00 0.01%
litecoin
Litecoin (LTC) $ 99.15 8.32%
polkadot
Polkadot (DOT) $ 4.66 9.86%
weth
WETH (WETH) $ 2,343.45 19.77%
monero
Monero (XMR) $ 298.84 1.71%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,497.87 19.31%
pepe
Pepe (PEPE) $ 0.000013 35.58%
bitget-token
Bitget Token (BGB) $ 4.49 3.98%
pi-network
Pi Network (PI) $ 0.74077 19.07%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.03%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.15%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 103,059.61 3.83%
whitebit
WhiteBIT Coin (WBT) $ 30.33 3.66%
uniswap
Uniswap (UNI) $ 6.32 21.10%
bittensor
Bittensor (TAO) $ 429.96 7.95%
near
NEAR Protocol (NEAR) $ 2.92 16.72%
aptos
Aptos (APT) $ 5.67 11.81%
dai
Dai (DAI) $ 1.00 0.03%
ondo-finance
Ondo (ONDO) $ 1.03 10.94%
okb
OKB (OKB) $ 53.65 3.68%
aave
Aave (AAVE) $ 209.24 11.58%
susds
sUSDS (SUSDS) $ 1.05 0.01%
ethereum-classic
Ethereum Classic (ETC) $ 19.12 10.43%
crypto-com-chain
Cronos (CRO) $ 0.100954 6.39%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
official-trump
Official Trump (TRUMP) $ 14.22 16.45%
internet-computer
Internet Computer (ICP) $ 5.33 9.41%