Economic news

Hackers use flaw in popular file transfer tool to steal data, U.S. researchers say

2023.06.01 19:56


© Reuters. FILE PHOTO: A computer keyboard lit by a displayed cyber code is seen in this illustration picture taken on March 1, 2017. REUTERS/Kacper Pempel/Illustration

By Zeba Siddiqui

SAN FRANCISCO (Reuters) – Hackers have stolen data from the systems of a number of users of the popular file transfer tool MOVEit Transfer, U.S. security researchers said on Thursday, one day after the maker of the software disclosed that a security flaw had been discovered.

Software maker Progress Software (NASDAQ:), after disclosing the vulnerability on Wednesday, said it could lead to potential unauthorized access into users’ systems.

The managed file transfer software made by Burlington, Massachusetts-based Progress allows organizations to securely transfer files and data between business partners and customers, and according to the company is used by thousands of organizations.

Google (NASDAQ:)’s Mandiant consulting and cybersecurity firm Rapid7 (NASDAQ:) disclosed on Thursday that they had found a number of cases in which the flaw had been exploited to steal user data.

It wasn’t immediately clear how many users were impacted, but Mandiant Consulting said it was investigating “several” intrusions linked to the bug.

It was not known when the flaw was discovered by hackers. A Progress Software spokeswoman didn’t immediately respond to a request for further comment.

“Mass exploitation and broad data theft has occurred over the past few days,” Charles Carmakal, chief technology officer of Mandiant Consulting, said in a statement.

Such “zero-day,” or previously unknown, vulnerabilities in managed file transfer solutions have led to data theft, leaks, extortion and victim shaming in the past, according to Mandiant.

“Although Mandiant does not yet know the motivation of the threat actor, organizations should prepare for potential extortion and publication of the stolen data,” Carmakal added.

Rapid7 said it had noticed an uptick in cases of compromise linked to the flaw since it was disclosed.

Progress, in a statement on Wednesday, outlined steps users at risk can take to mitigate the impact of the security vulnerability.

Source link

Related Articles

Back to top button
bitcoin
Bitcoin (BTC) $ 102,616.49 3.87%
ethereum
Ethereum (ETH) $ 2,227.25 18.83%
tether
Tether (USDT) $ 1.00 0.03%
xrp
XRP (XRP) $ 2.32 7.01%
bnb
BNB (BNB) $ 626.95 3.06%
solana
Solana (SOL) $ 162.81 8.50%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.196699 10.70%
cardano
Cardano (ADA) $ 0.771186 10.08%
tron
TRON (TRX) $ 0.255722 2.48%
staked-ether
Lido Staked Ether (STETH) $ 2,228.12 20.00%
sui
Sui (SUI) $ 3.94 9.72%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 102,608.49 4.01%
chainlink
Chainlink (LINK) $ 15.86 10.76%
avalanche-2
Avalanche (AVAX) $ 22.37 11.39%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,669.18 19.93%
stellar
Stellar (XLM) $ 0.295299 10.63%
shiba-inu
Shiba Inu (SHIB) $ 0.000014 9.70%
bitcoin-cash
Bitcoin Cash (BCH) $ 419.79 4.57%
hedera-hashgraph
Hedera (HBAR) $ 0.194987 8.15%
leo-token
LEO Token (LEO) $ 8.86 0.36%
usds
USDS (USDS) $ 1.00 0.01%
the-open-network
Toncoin (TON) $ 3.20 4.64%
hyperliquid
Hyperliquid (HYPE) $ 23.36 9.28%
litecoin
Litecoin (LTC) $ 95.77 4.59%
polkadot
Polkadot (DOT) $ 4.53 9.74%
weth
WETH (WETH) $ 2,225.52 19.46%
monero
Monero (XMR) $ 301.24 5.95%
bitget-token
Bitget Token (BGB) $ 4.52 5.63%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,368.66 19.69%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999542 0.10%
pi-network
Pi Network (PI) $ 0.676197 6.33%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 102,630.50 3.91%
ethena-usde
Ethena USDe (USDE) $ 0.999617 0.33%
pepe
Pepe (PEPE) $ 0.000011 27.99%
whitebit
WhiteBIT Coin (WBT) $ 30.35 6.04%
uniswap
Uniswap (UNI) $ 6.24 23.64%
bittensor
Bittensor (TAO) $ 427.94 11.79%
aptos
Aptos (APT) $ 5.61 13.83%
near
NEAR Protocol (NEAR) $ 2.81 18.17%
dai
Dai (DAI) $ 1.00 0.02%
okb
OKB (OKB) $ 52.75 3.06%
ondo-finance
Ondo (ONDO) $ 0.995445 9.36%
susds
sUSDS (SUSDS) $ 1.05 0.03%
aave
Aave (AAVE) $ 206.98 15.35%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
crypto-com-chain
Cronos (CRO) $ 0.099597 5.89%
ethereum-classic
Ethereum Classic (ETC) $ 18.61 10.97%
official-trump
Official Trump (TRUMP) $ 13.91 23.87%
internet-computer
Internet Computer (ICP) $ 5.25 10.37%