Progress Software discloses a critical vulnerability in MOVEit's SFTP module; hackers exploited a similar flaw in MOVEit in 2023 to breach almost 1,800 networks
A similar flaw last year left 1,800 networks breached. Will the latest one be as potent? — A critical vulnerability …
Ars TechnicaDan Goodin
Context & Ripple Effects
MOVEit’s 2023 zero-day was actively exploited to steal data, and subsequent reporting tracked its spread to more than 1,000 known victim organizations across a broad victim base. That history makes a newly disclosed critical issue in the same product family unusually consequential even before the extent of any new abuse is known.
The episode also follows Progress’s patching of critical WS_FTP Server flaws, underscoring that secure file-transfer software remains a high-value target because it sits on sensitive data-transfer paths.
First-order effects
Organizations using the affected MOVEit SFTP component must assess whether their deployments are exposed and prioritize Progress’s remediation guidance; Progress faces renewed pressure to communicate scope and mitigation clearly.
Security teams will likely increase monitoring of MOVEit-related systems for suspicious access or data movement, given the prior exploitation history.
Second-order effects
Customers and insurers may subject managed file-transfer products to tighter vendor-risk reviews, because a flaw in one shared product can create exposure across many organizations.
Rival file-transfer vendors and service providers face a higher bar to demonstrate patch responsiveness, secure configuration, and incident support as buyers reassess concentration risk.
Third-order effects
If critical flaws continue to recur in widely deployed transfer tools, enterprises may shift from treating them as routine infrastructure toward stricter segmentation, continuous exposure management, and more resilient data-exchange architectures.
The pattern strengthens the case that software suppliers’ security practices and disclosure response are commercial and governance issues, not solely technical support matters.
The trend: Recurring flaws in shared enterprise data-transfer software are pushing vulnerability management and vendor assurance closer to the core of operational risk management.
Very shortly after vulnerability details were published today we started observing Progress MOVEit Transfer CVE-2024-5806 POST /guestaccess.aspx exploit attempts. If you run MOVEit & have not patched yet - please do so now: https://community.progress.com/ ... NVD: https://nvd.nis…
2/3 ⚠️ Shadowserver Foundation reports active exploitation attempts, with ~2,700 internet-exposed MOVEit instances identified by Censys. With PoC exploit code available, attacks are expected to rise. Organizations should check logs and apply security updates immediately #Infosec
The coincidence in all of this is that it was exactly one year ago to date when we had the massive MoveIT attack that started over the 2023 Memorial Day Holiday. This same advice was given, yet it led to this software being the largest attacked vulnerability of 2023. Heed.
3/3 🔒 #Progress released patches for #CVE20245806 in MOVEit Transfer versions 2023.0.11, 2023.1.6, and 2024.0.2. MOVEit Cloud customers are already protected. Additional mitigations include blocking RDP access and restricting outbound connections. Stay vigilant! #PatchNow
Background on CVE-2024-5806: https://labs.watchtowr.com/... You can track Progress MOVEit Transfer exposed instances here: https://dashboard.shadowserver.org/ ... IP Data shared daily in https://www.shadowserver.org/ ... (please note this is a population count, not on a vulnerabi…
I love seeing real bugs that people would think are too stupid and unrealistic if they showed up in a CTF. This looks like it was a lot of fun to exploit