New Zero-Day Vulnerability in MOVEit Software Exposed on Twitter

Published on

numen cyber focuses on Web3 Security and Threat Detection and Response. They provide industry-leading Web3 Security Solutions, which
can completely cover cybersecurity requirements of all kinds.

John Hammond, a senior researcher at cybersecurity firm Huntress, received information from an anonymous individual on June 15 regarding a new zero-day vulnerability in the MOVEit file-transfer software.

This type of flaw, which lacks a fix or patch, leaves users susceptible to hacker attacks. Adding to the complexity, the anonymous researcher publicly shared intricate details about the flaw on Twitter, potentially enabling attackers to exploit the vulnerability before the software owner could respond.

Such actions deviate from the typical practices of cybersecurity researchers who generally inform organizations about vulnerabilities before making them public, aiming to prevent aiding malicious actors. The US Department of Homeland Security, for instance, grants organizations 45 days to address vulnerability reports before public disclosure.

The revelation further worsened the existing crisis surrounding MOVEit, as it had already fallen victim to an ongoing hacking campaign by the Clop criminal group, primarily composed of Russian-speaking individuals.

Exploiting a different zero-day vulnerability, the group successfully gained unauthorized access to files from numerous companies and organizations. Consequently, the researcher’s discovery only added to the challenges faced by Progress Software Corp., the company behind MOVEit software.

Companies and Organizations Affected by Clop-MOVEit Hack

CLICK HERE TO READ THE FULL STORY

Image

Latest articles

SEC Takes First Enforcement Measure Against NFTs Regulatory Body Concludes Impact Theory’s NFTs Were Marketed as Unregistered Securities

U.S. regulatory authorities have mandated a Los Angeles company, which had previously issued non-fungible tokens (NFTs), to provide compensation to investors who had procured the aforementioned NFTs.

Binance Cuts Ties with Sanctioned Russian Banks Amid Regulatory Compliance Efforts

Binance has severed its affiliations with five Russian banks that were under sanctions, having been previously featured on the exchange's peer-to-peer platform for ruble fund transfers, the native currency of Russia.

Former OpenSea Employee Receives Three-Month Sentence in First NFT Insider Trading Lawsuit

A former employee of the NFT marketplace OpenSea has been sentenced to three months in prison on Tuesday in what federal prosecutors have characterized as the first case of insider trading involving digital tokens.

Crypto Market Takes a Dive, Bitcoin Slumps to Two-Month Low Amid Rate-Hike Concerns

In a dramatic turn of events on Thursday's early afternoon trading session, the cryptocurrency market witnessed a substantial downturn, plunging to its lowest point in two months.

More like this

SEC Takes First Enforcement Measure Against NFTs Regulatory Body Concludes Impact Theory’s NFTs Were Marketed as Unregistered Securities

U.S. regulatory authorities have mandated a Los Angeles company, which had previously issued non-fungible tokens (NFTs), to provide compensation to investors who had procured the aforementioned NFTs.

Binance Cuts Ties with Sanctioned Russian Banks Amid Regulatory Compliance Efforts

Binance has severed its affiliations with five Russian banks that were under sanctions, having been previously featured on the exchange's peer-to-peer platform for ruble fund transfers, the native currency of Russia.

Former OpenSea Employee Receives Three-Month Sentence in First NFT Insider Trading Lawsuit

A former employee of the NFT marketplace OpenSea has been sentenced to three months in prison on Tuesday in what federal prosecutors have characterized as the first case of insider trading involving digital tokens.