Economic news

Hackers use flaw in popular file transfer tool to steal data, U.S. researchers say

2023.06.01 19:56


© Reuters. FILE PHOTO: A computer keyboard lit by a displayed cyber code is seen in this illustration picture taken on March 1, 2017. REUTERS/Kacper Pempel/Illustration

By Zeba Siddiqui

SAN FRANCISCO (Reuters) – Hackers have stolen data from the systems of a number of users of the popular file transfer tool MOVEit Transfer, U.S. security researchers said on Thursday, one day after the maker of the software disclosed that a security flaw had been discovered.

Software maker Progress Software (NASDAQ:), after disclosing the vulnerability on Wednesday, said it could lead to potential unauthorized access into users’ systems.

The managed file transfer software made by Burlington, Massachusetts-based Progress allows organizations to securely transfer files and data between business partners and customers, and according to the company is used by thousands of organizations.

Google (NASDAQ:)’s Mandiant consulting and cybersecurity firm Rapid7 (NASDAQ:) disclosed on Thursday that they had found a number of cases in which the flaw had been exploited to steal user data.

It wasn’t immediately clear how many users were impacted, but Mandiant Consulting said it was investigating “several” intrusions linked to the bug.

It was not known when the flaw was discovered by hackers. A Progress Software spokeswoman didn’t immediately respond to a request for further comment.

“Mass exploitation and broad data theft has occurred over the past few days,” Charles Carmakal, chief technology officer of Mandiant Consulting, said in a statement.

Such “zero-day,” or previously unknown, vulnerabilities in managed file transfer solutions have led to data theft, leaks, extortion and victim shaming in the past, according to Mandiant.

“Although Mandiant does not yet know the motivation of the threat actor, organizations should prepare for potential extortion and publication of the stolen data,” Carmakal added.

Rapid7 said it had noticed an uptick in cases of compromise linked to the flaw since it was disclosed.

Progress, in a statement on Wednesday, outlined steps users at risk can take to mitigate the impact of the security vulnerability.

Source link

Related Articles

Back to top button
bitcoin
Bitcoin (BTC) $ 94,036.19 1.78%
ethereum
Ethereum (ETH) $ 3,339.06 0.40%
tether
Tether (USDT) $ 0.998651 0.01%
xrp
XRP (XRP) $ 2.16 0.51%
bnb
BNB (BNB) $ 692.27 0.72%
solana
Solana (SOL) $ 185.78 1.29%
dogecoin
Dogecoin (DOGE) $ 0.314427 0.49%
usd-coin
USDC (USDC) $ 1.00 0.13%
staked-ether
Lido Staked Ether (STETH) $ 3,338.65 0.36%
cardano
Cardano (ADA) $ 0.887831 3.33%
tron
TRON (TRX) $ 0.259933 3.59%
avalanche-2
Avalanche (AVAX) $ 37.30 0.14%
the-open-network
Toncoin (TON) $ 5.79 1.69%
chainlink
Chainlink (LINK) $ 22.62 0.31%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,957.90 2.77%
shiba-inu
Shiba Inu (SHIB) $ 0.000022 1.80%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 93,913.16 1.56%
sui
Sui (SUI) $ 4.21 0.09%
bitget-token
Bitget Token (BGB) $ 8.00 7.59%
hedera-hashgraph
Hedera (HBAR) $ 0.278884 2.79%
polkadot
Polkadot (DOT) $ 7.00 0.90%
stellar
Stellar (XLM) $ 0.351486 0.77%
weth
WETH (WETH) $ 3,340.22 0.41%
hyperliquid
Hyperliquid (HYPE) $ 27.15 4.80%
bitcoin-cash
Bitcoin Cash (BCH) $ 446.75 2.31%
leo-token
LEO Token (LEO) $ 9.20 0.17%
uniswap
Uniswap (UNI) $ 13.50 4.11%
litecoin
Litecoin (LTC) $ 102.83 0.69%
pepe
Pepe (PEPE) $ 0.000018 3.99%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,522.22 0.31%
near
NEAR Protocol (NEAR) $ 5.21 3.43%
ethena-usde
Ethena USDe (USDE) $ 0.997579 0.02%
usds
USDS (USDS) $ 1.00 0.14%
aptos
Aptos (APT) $ 8.93 0.07%
aave
Aave (AAVE) $ 326.39 2.34%
internet-computer
Internet Computer (ICP) $ 10.27 0.18%
crypto-com-chain
Cronos (CRO) $ 0.150364 0.81%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.486491 1.64%
mantle
Mantle (MNT) $ 1.21 2.88%
ethereum-classic
Ethereum Classic (ETC) $ 26.32 2.23%
vechain
VeChain (VET) $ 0.046666 0.23%
render-token
Render (RENDER) $ 7.14 0.31%
monero
Monero (XMR) $ 192.22 1.55%
whitebit
WhiteBIT Coin (WBT) $ 24.54 0.47%
bittensor
Bittensor (TAO) $ 478.11 1.81%
mantra-dao
MANTRA (OM) $ 3.66 1.23%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.34 6.23%
dai
Dai (DAI) $ 1.00 0.08%
virtual-protocol
Virtuals Protocol (VIRTUAL) $ 3.42 18.19%
arbitrum
Arbitrum (ARB) $ 0.776113 4.34%