CVE detail
CVE-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
75 source links · newest first
- MOVEit automation flaws could enable full system compromiseSecurity Affairs
Progress fixes critical MOVEit Automation flaws, including an authentication bypass bug that could let attackers gain unauthorized access to systems. Progress Software addressed two vulnerabilities in MOVEit Automation, a critical authentication bypass flaw tracked as CVE-2026-4670 and a privilege escalation issue tracked as CVE-2026-5174. If exploited, these bugs could allow attackers to gain unauthorized access […]
newssecurityaffairs.comMay 4, 2026, 9:32 PM Progress Software has fixed a critical authentication bypass (CVE-2026-4670) and a privilege escalation (CVE-2026-5174) vulnerability in MOVEit Automation, exploitation of which “may lead to unauthorized access, administrative control, and data exposure.” The vulnerabilities were reported privately by Airbus researchers and there’s no mention of them being leveraged by attackers in the wild. Still, performing an upgrade to a fixed version is “strongly” advised. CVE-2026-4670 and CVE-2026-5174 Progress Software’s MOVEit Transfer, an enterprise managed file transfer … More →
newswww.helpnetsecurity.comMay 4, 2026, 2:58 PM- Korean Air discloses data breach after the hack of its catering and duty-free supplierSecurity Affairs
Korean Air employee discloses a data breach after a hack of its catering and duty-free supplier, KC&D, affecting thousands of staff. Korean Air suffered a data breach after its in-flight catering supplier Korean Air Catering & Duty-Free (KC&D) was hacked, exposing personal data of ~30,000 employees of Korean Air employees. Korean Air is South Korea’s […]
newssecurityaffairs.comDec 29, 2025, 2:35 PM The Clop ransomware group is targeting Gladinet CentreStack file servers in a new large-scale extortion campaign. The Clop ransomware group is targeting Gladinet CentreStack file servers in a new large-scale extortion campaign aimed at stealing sensitive data from organizations worldwide. Gladinet CentreStack is a software platform that allows organizations to turn their existing file servers, […]
newssecurityaffairs.comDec 19, 2025, 11:48 AM- Clop Ransomware group claims the breach of The Washington PostSecurity Affairs
The Clop Ransomware group claims the breach of The Washington Post and added the American daily newspaper to its Tor data leak site. The Clop Ransomware group announced the hack of the prestigious American daily newspaper The Washington Post. The cybercrime group created a page for the university on its Tor data leak site and announced it will […]
newssecurityaffairs.comNov 6, 2025, 10:10 PM - Harvard University hit in Oracle EBS cyberattack, 1.3 TB of data leaked by Cl0p groupSecurity Affairs
Harvard University confirmed being targeted in the Oracle EBS campaign after the Cl0p ransomware group leaked 1.3 TB of data. Harvard University confirmed it was targeted in the Oracle E-Business Suite campaign after the Cl0p ransomware group listed it on its leak site. The cybercrime group claimed to have leaked 1.3 TB of data allegedly […]
newssecurityaffairs.comOct 14, 2025, 2:08 PM - Clop Ransomware group claims the hack of Harvard UniversitySecurity Affairs
The notorious Clop Ransomware group claims the hack of Harvard University and added the prestigious institute to its Tor data leak site. The Clop Ransomware group announced the hack of the prestigious Harvard University. The cybercrime group created a page for the university on its Tor data leak site and announced it will leak the […]
newssecurityaffairs.comOct 12, 2025, 3:01 PM It’s the bad news that many customers of Oracle E-Business Suite (EBS) have been dreading: reports of ransomware attacks targeting the software have turned out to be connected to a serious zero-day vulnerability that requires immediate patching. The first indications that something might be awry emerged last week from Halcyon, Google’s Threat Intelligence Group (GTIG), […]
newswww.csoonline.comOct 6, 2025, 6:01 PMZero-day vulnerabilities saw big growth once again in 2024. With no patch available, zero-day flaws give attackers a significant jump on cybersecurity defense teams, making them a critical weapon for attacking enterprise systems. But while all zero-days are essential for CISOs and their team to be aware of, and for vendors to remedy in a […]
newswww.csoonline.comDec 23, 2024, 9:00 AMMost of the top frequently exploited vulnerabilities in 2023 were initially exploited as zero-days, according to data from government agencies.
newswww.securityweek.comNov 13, 2024, 3:46 PMThe personal information of 500,000 Texas Dow Employees Credit Union members was compromised in the MOVEit hack last year.
newswww.securityweek.comAug 26, 2024, 11:34 AMExploitation attempts targeting CVE-2024-5806, a critical MOVEit Transfer vulnerability patched recently, have started.
newswww.securityweek.comJun 26, 2024, 9:10 AMSecurity researchers have published a proof-of-concept (PoC) exploit that chains together two vulnerabilities (CVE-2024-4358, CVE-2024-1800) to achieve unauthenticated remote code execution on Progress Telerik Report Servers. Telerik Report Server is a centralized enterprise platform for report creation, management, storage and delivery/distribution. As noted by Censys earlier this year, “an attacker with remote access and an ability to execute malicious code on such an asset may allow such an attacker to not only interfere with reporting … More →
newswww.helpnetsecurity.comJun 4, 2024, 2:39 PM- The Battle Continues: Mandiant Report Shows Improved Detection But Persistent Adversarial SuccessSecurityWeek
Mandiant’s M-Trends 2024 report shows that defenses are improving – and that may be true. But the reality remains that these same statistics demonstrate that if anything, the attackers still retain the upper hand.
newswww.securityweek.comApr 23, 2024, 1:51 PM We describe the characteristics of malware-initiated scanning attacks. These attacks differ from direct scanning and are increasing according to our data.
vendorunit42.paloaltonetworks.comApr 8, 2024, 10:00 PM- 98% of businesses linked to breached third partiesHelp Net Security
According to the updated SEC regulations on cybersecurity incident disclosure, findings by SecurityScorecard reveal that 98% of companies are associated with a third party that has experienced a breach. It often takes months or longer for breaches to become public knowledge. It may have taken victims weeks or months to discover a breach, which may not appear in public reporting for weeks or months thereafter (if it ever appears at all). Technology supply chain vulnerabilities … More →
newswww.helpnetsecurity.comMar 1, 2024, 4:30 AM Introduction Memory safety issues have plagued the software industry for decades. The Cybersecurity & Infrastructure Security Agency (CISA) has been leading a charge for secure-by-design and encouraging developers and vendors to utilize memory safe languages like Rust to eradicate this vulnerability class. Google Chromium, the engine used by the majority of browsers around the world, […]
exploithorizon3.aiFeb 6, 2024, 9:58 AMAnalysis of ransomware gang leak site data reveals significant activity over 2023. As groups formed — or dissolved — and tactics changed, we synthesize our findings.
vendorunit42.paloaltonetworks.comFeb 5, 2024, 11:00 AMHealthcare organizations recognize they need a preemptive approach to help them discover their truly exploitable vulnerabilities, show them how to fix the issues at hand, then verify their fix worked. Discover the facts about how NodeZero is redefining healthcare security in our comprehensive whitepaper.
exploithorizon3.aiJan 17, 2024, 6:12 PM- Welltok data breach impacted 8.5 million patients in the U.S.Security Affairs
Healthcare services provider Welltok disclosed a data breach that impacted nearly 8.5 million patients in the U.S. Welltok is a company that specializes in health optimization solutions. It provides a platform that leverages data-driven insights to engage individuals in their health and well-being. The platform aims to personalize and optimize health programs for individuals, employers, […]
newssecurityaffairs.comNov 23, 2023, 2:46 PM American retailer and distributor of automotive parts and accessories AutoZone discloses a data breach after a MOVEit attack. AutoZone is an American retailer and distributor of automotive parts and accessories. The company is one of the largest aftermarket automotive parts and accessories retailers in the United States. AutoZone operates 7,140 stores across the United States, […]
newssecurityaffairs.comNov 23, 2023, 8:26 AMCar parts giant AutoZone says nearly 185,000 individuals were impacted by a data breach caused by the MOVEit hack.
newswww.securityweek.comNov 22, 2023, 1:47 PMThe State of Maine disclosed a data breach that impacted about 1.3 million people after an attack hit its MOVEit file transfer install. The State of Maine was the victim of the large-scale hacking campaign that targeted organizations using the MOVEit file transfer tool. The Government organization disclosed a data breach that impacted about 1.3 million individuals. Threat actors […]
newssecurityaffairs.comNov 12, 2023, 3:07 PMA critical zero-day vulnerability (CVE-2023-47246) in the SysAid IT support and management software solution is being exploited by Lace Tempest, a ransomware affiliate known for deploying Cl0p ransomware. Lace Tempest has previously exploited zero-day vulnerability (CVE-2023-34362) in Progress Software’s MOVEit Transfer installations to steal data from many enterprises and public sector organizations. The group has also similarly leveraged zero days in the Accellion file transfer appliance and Fortra’s GoAnywhere file transfer solution. CVE-2023-47246 exploited The … More →
newswww.helpnetsecurity.comNov 9, 2023, 2:50 PM- NetRise releases Trace solution with AI-powered semantic search aimed at protecting firmwareCSO Online
Extended internet of things (XIoT) security platform developer NetRise has released its Trace solution, which the company say allows users to identify and validate compromised and vulnerable third-party and proprietary software assets using an AI-powered semantic search. NetRise, based in Austin, Texas, said Trace introduces intent-driven searches to enhance vulnerability detection and validation in firmware […]
newswww.csoonline.comNov 9, 2023, 11:00 AM Digital supply chain security company Eclypsium has announced the launch of a new supply chain security guide to help IT, security, and procurement teams track risks and incidents. CIOs, CISOs, and supply chain leaders can use the guide to assess their exposure to supply chain cybersecurity threats and make better risk-based purchase decisions, the firm […]
newswww.csoonline.comNov 7, 2023, 1:00 PMProgress Software confirms the SEC has launched its own investigation into costly ransomware zero-days in the MOVEit file transfer software.
newswww.securityweek.comOct 12, 2023, 4:39 PMProgress Software could be staring at fresh litigation over the explosive zero-day found in its file-transfer service, MOVEit, which affected millions of end users globally. The latest probe comes from the US Security and Exchange Commission (SEC), which is seeking information related to the mass hack. “On October 2, 2023, Progress received a subpoena from […]
newswww.csoonline.comOct 12, 2023, 11:43 AM- Sony sent data breach notifications to about 6,800 individualsSecurity Affairs
Sony Interactive Entertainment has notified current and former employees and their family members about a data breach. Sony Interactive Entertainment (SIE) has notified current and former employees and their family members about a data breach that exposed their personal information. Sony notified about 6,800 individuals, it confirmed that the security breach was the result of the […]
newssecurityaffairs.comOct 5, 2023, 6:24 AM This threat brief details the critical vulnerability CVE-2023-34362 found in MOVEit Transfer and includes Unit 42's observations, the current attack scope and interim guidance.
vendorunit42.paloaltonetworks.comOct 4, 2023, 1:00 PM- Cl0p’s MOVEit attack tally surpasses 2,000 victim organizationsHelp Net Security
The number of victim organizations hit by Cl0p via vulnerable MOVEit installations has surpassed 2,000, and the number of affected individuals is now over 60 million. The victim organizations are overwhelmingly based in the US. “The most heavily impacted sectors are finance and professional services and education, which account for 13.8 percent and 51.1 percent of incidents respectively,” Emsisoft researchers have shared on Monday. IT market research company KonBriefing Research shows similar numbers, and links … More →
newswww.helpnetsecurity.comSep 26, 2023, 11:47 AM The Better Outcomes Registry & Network (BORN), the Ontario birth registry disclosed a data breach affecting some 3.4 million people. The Better Outcomes Registry & Network (BORN) is a program and database used in the healthcare sector, particularly in maternal and child health, to collect, manage, and analyze health information for the purpose of improving […]
newssecurityaffairs.comSep 26, 2023, 11:46 AMUS educational nonprofit organization National Student Clearinghouse (NSC) has revealed that the breach of its MOVEit server ended up affecting almost 900 colleges and universities, and resulted in the theft of personal information of their students. The National Student Clearinghouse MOVEit breach notice NSC provides educational reporting, data exchange, verification, and research services to around 3,600 North American colleges and universities and 22,000 high schools. NSC has filed a breach notification letter with the California … More →
newswww.helpnetsecurity.comSep 25, 2023, 11:18 AMU.S. educational nonprofit organization National Student Clearinghouse disclosed a data breach that impacted approximately 900 US schools. The National Student Clearinghouse (NSC) is a nonprofit organization based in the United States that provides educational verification and reporting services to educational institutions, employers, and other organizations The organization has disclosed a data breach that impacted approximately […]
newssecurityaffairs.comSep 24, 2023, 9:14 AM- Clop gang stolen data from major North Carolina hospitalsSecurity Affairs
Researchers at healthcare technology firm Nuance blame the Clop gang for a series of cyber thefts at major North Carolina hospitals. The Microsoft-owned healthcare technology firm Nuance revealed that the Clop extortion gang has stolen personal data on major North Carolina hospitals as part of the Progress MOVEit Transfer campaign. MOVEit Transfer is a managed file transfer that is used […]
newssecurityaffairs.comSep 17, 2023, 1:26 PM - Massive MOVEit campaign already impacted at least 1,000 organizations and 60 million individualsSecurity Affairs
The recent wave of MOVEit attacks conducted by the Cl0p ransomware gang impacted 1,000 organizations, experts say. Cybersecurity firm Emsisoft shared disconcerting details about the recent, massive hacking campaign conducted by the Cl0p ransomware group that targeted the MOVEit Transfer file transfer platform designed by Progress Software Corporation. According to the experts, the attacks impacted approximately 1,000 Organizations and […]
newssecurityaffairs.comAug 28, 2023, 7:32 AM Nearly 1,000 organizations and 60 million individuals are impacted by the MOVEit hack, and the Cl0p ransomware gang is leaking stolen data.
newswww.securityweek.comAug 25, 2023, 9:30 AMA new report from Rapid7 says a ransomware gang like Cl0p would easily be able to afford a bevy of zero-day exploits for vulnerable enterprise software.
newswww.securityweek.comAug 17, 2023, 3:30 PMThe Colorado Department of Health Care Policy & Financing (HCPF) disclose a data breach after MOVEit attack on IBM. The Colorado Department of Health Care Policy & Financing (HCPF) disclosed a data breach that impacted more than four million individuals. The incident is the result of a MOVEit attack on IBM, threat actors accessed the […]
newssecurityaffairs.comAug 14, 2023, 4:39 PMPersonal data of the personnel at the Dublin Airport was compromised due to a MOVEit attack on professional service provider Aon. Data of about 3000 employees of Dublin Airport (DDA) were compromised after professional service provider Aon fell victim to a MOVEit Transfer attack. Dublin Airport notified local authorities and Ireland’s Data Protection Commission. Aon […]
newssecurityaffairs.comJul 4, 2023, 2:32 PMClop ransomware group added five new victims of MOVEit attacks to its dark web leak site, including Schneider Electric and Siemens Energy. The Clop ransomware group added five new victims of MOVEit attacks to its dark web leak site, including the industrial giants Schneider Electric and Siemens Energy. Both Schneider Electric and Siemens Energy provide […]
newssecurityaffairs.comJun 27, 2023, 10:14 AMNorton parent firm, Gen Digital, was the victim of an attack that exploited the recently disclosed MOVEit zero-day vulnerability. Gen Digital Inc. (formerly Symantec Corporation and NortonLifeLock) is a multinational software company that provides cybersecurity software and services. The company owns multiple brands, including Norton, Avast, LifeLock, Avira, AVG, ReputationDefender, and CCleaner. Gen Digital said it was the victim of a cyber attack, threat […]
newssecurityaffairs.comJun 22, 2023, 1:29 PMGen Digital, which owns Avast, Avira, AVG, Norton, and LifeLock, said employee data was compromised in the MOVEit ransomware attack.
newswww.securityweek.comJun 20, 2023, 3:48 PM- A third MOVEit vulnerability fixed, Cl0p lists victim organizations (CVE-2023-35708)Help Net Security
Progress Software has asked customers to update their MOVEit Transfer installations again, to fix a third SQL injection vulnerability (CVE-2023-35708) discovered in the web application in less that a month. Previously, the Cl0p cyber extortion gang exploited CVE-2023-34362 to grab enterprise data, and Huntress researchers discovered CVE-2023-35036 after partnering with Progress to perform a code review of the web app. About CVE-2023-35708 CVE-2023-35708 is a vulnerability that could lead to escalated privileges and unauthorized access. … More →
newswww.helpnetsecurity.comJun 19, 2023, 11:56 AM A critical vulnerability (CVE-2023-35708) in MOVEit software could allow unauthenticated attackers to access database content.
newswww.securityweek.comJun 19, 2023, 10:52 AM- US govt offers $10 million bounty for info linking Clop ransomware gang to a foreign government.Security Affairs
The U.S. government announced up to a $10 million bounty for information linking the Clop ransomware gang to a foreign government. The US goverment is offering up to a $10 million bounty for information linking CL0P Ransomware Gang or any other threat actors targeting U.S. critical infrastructure to a foreign government. The bounty is covered […]
newssecurityaffairs.comJun 18, 2023, 12:49 PM Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Building a culture of security awareness in healthcare begins with leadership In this Help Net Security interview, Ken Briggs, General Counsel at Salucro, discusses how fostering a culture of security awareness has become paramount for healthcare organizations. Building a hyper-connected future with 6G networks In this Help Net Security interview, Shamik Mishra, Capgemini‘s CTO of Connectivity, delves into the emerging … More →
newswww.helpnetsecurity.comJun 18, 2023, 8:00 AMA new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Law enforcement shutdown a long-standing DDoS-for-hire service A Russian national charged for committing LockBit Ransomware attacks […]
newssecurityaffairs.comJun 18, 2023, 12:05 AMBritish multinational oil and gas company Shell has confirmed that it has suffered a ransomware attack conducted by the Clop group. Oil and Gas giant Shell has confirmed that it is one of the victims of the recent large-scale ransomware campaign conducted by the Clop gang exploiting a MOVEit zero-day vulnerability Threat actors are actively exploiting the zero-day vulnerability, tracked […]
newssecurityaffairs.comJun 16, 2023, 2:44 PM- Progress fixed a third flaw in MOVEit Transfer softwareSecurity Affairs
Progress Software addressed a third vulnerability impacting its MOVEit Transfer application that could lead to privilege escalation and information disclosure. Progress Software disclosed a new SQL injection vulnerability impacting its MOVEit Transfer application, it is the third issue fixed by the company after: “Progress has discovered a vulnerability in MOVEit Transfer that could lead to escalated privileges […]
newssecurityaffairs.comJun 16, 2023, 10:55 AM The Cl0p ransomware gang has listed more than two dozen victims of the MOVEit zero-day attack on its leak website.
newswww.securityweek.comJun 16, 2023, 8:34 AM- INSIGHT – MOVEit Zero-Day Reminds Us Yet Again to Be Diligent in Monitoring Our IT InfrastructureHorizon3.ai
Over the last week, the widely reported critical security flaw in the Progress MOVEit Transfer application (CVE-2023-34362) reminded us yet again to remain vigilant in securing our IT infrastructure from potential cyber threat actors.
exploithorizon3.aiJun 15, 2023, 7:53 PM The developer of the recently exploited MOVEit Transfer application issued new updates after a third-party security audit identified additional SQL injection vulnerabilities. Customers are advised to deploy the new patches as soon as possible since attackers are clearly interested in exploiting this and other enterprise secure file transfer solutions. “In addition to the ongoing investigation […]
newswww.csoonline.comJun 13, 2023, 5:50 PMAs more victim organizations of Cl0p gang’s MOVEit rampage continue popping up, security researchers have released a PoC exploit for CVE-2023-34362, the RCE vulnerability exploited by the Cl0p cyber extortion group to plunder confidential data. CVE-2023-34362 PoC exploit released Horizon3 security researchers have released proof-of-concept (PoC) exploit code for CVE-2023-34362, as well as technical root cause analysis of the flaw. Rapid7 has released an analysis of the vulnerability and a full exploit chain for CVE-2023-34362. … More →
newswww.helpnetsecurity.comJun 13, 2023, 11:17 AMUK communications regulator Ofcom suffered a data breach after a Clop ransomware attack exploiting the MOVEit file transfer zero-day. UK’s communications regulator Ofcom disclosed a data breach after a Clop ransomware attack. The threat actors exploited the zero-day flaw (CVE-2023-34362,) in MOVEit file transfer and access the infrastructure of the regulator. A spokesperson for Ofcom […]
newssecurityaffairs.comJun 13, 2023, 7:42 AMSecurity firm Horizon3 released proof-of-concept (PoC) exploit code for the remote code execution (RCE) flaw CVE-2023-34362 in the MOVEit Transfer MFT. MOVEit Transfer is a managed file transfer that is used by enterprises to securely transfer files using SFTP, SCP, and HTTP-based uploads. The vulnerability is a SQL injection vulnerability, it can be exploited by […]
newssecurityaffairs.comJun 13, 2023, 5:29 AM- 12th June – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 12th June, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES Cl0p ransomware gang claimed responsibility for a major exploitation of a managed file transfer tool – The gang leveraged zero-day SQL injection vulnerability (CVE-2023-34362) that potentially exposed the data of hundreds of companies. […]
vendorresearch.checkpoint.comJun 12, 2023, 2:29 PM - It’s time to patch your MOVEit Transfer solution again!Help Net Security
Progress Software customers who use the MOVEit Transfer managed file transfer solution might not want to hear it, but they should quickly patch their on-prem installations again: With the help of researchers from Huntress, the company has uncovered additional SQL injection vulnerabilities that could potentially be used by unauthenticated attackers to grab data from the web application’s database. The vulnerabilities are yet to receive a CVE number, but patches/fixed versions have been provided. “The investigation … More →
newswww.helpnetsecurity.comJun 12, 2023, 1:33 PM Researchers discover new MOVEit vulnerabilities related to the zero-day, just as more organizations hit by the attack are coming forward.
newswww.securityweek.comJun 12, 2023, 10:26 AMA new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Experts found new MOVEit Transfer SQL Injection flaws The University of Manchester suffered a cyber attack […]
newssecurityaffairs.comJun 11, 2023, 12:39 PM- Experts found new MOVEit Transfer SQL Injection flawsSecurity Affairs
Progress Software released security updates to fix several new SQL injection vulnerabilities in the MOVEit Transfer application. Progress Software has released security updates to address new SQL injection vulnerabilities in the MOVEit Transfer application. An attacker can exploit the SQL injection vulnerabilities in the MOVEit Transfer solution to steal sensitive information. “SQL Injection (CVE pending […]
newssecurityaffairs.comJun 10, 2023, 8:20 PM On May 31, 2023, Progress released a security advisory for their MOVEit Transfer application which detailed a SQL injection leading to remote code execution and urged customers to update to the latest version. The vulnerability, CVE-2023-34362, at the time of release was believed to have been exploited in-the-wild as a 0-day dating back at least […]
exploithorizon3.aiJun 9, 2023, 1:48 PM- Clop ransomware gang was testing MOVEit Transfer bug since 2021Security Affairs
Researchers discovered that the Clop ransomware gang was looking for a zero-day exploit in the MOVEit Transfer since 2021. Kroll security experts discovered that the Clop ransomware gang was looking for a zero-day exploit in the MOVEit Transfer since 2021. Kroll investigated the exploitation attempts for the MOVEit Transfer vulnerability and discovered that Clop threat […]
newssecurityaffairs.comJun 9, 2023, 12:49 PM Evidence suggests that the Cl0p ransomware group has known about and conducted tests with the recently patched MOVEit zero-day since mid-2021.
newswww.securityweek.comJun 9, 2023, 11:44 AM- Clop ransomware gang claims the hack of hundreds of victims exploiting MOVEit Transfer bugSecurity Affairs
Clop ransomware group claims to have hacked hundreds of companies globally by exploiting MOVEit Transfer vulnerability. The Clop ransomware group may have compromised hundreds of companies worldwide by exploiting a vulnerability in MOVEit Transfer software. MOVEit Transfer is a managed file transfer that is used by enterprises to securely transfer files using SFTP, SCP, and […]
newssecurityaffairs.comJun 7, 2023, 6:20 PM telemetry indicated that other victims may include banks and areas of the US government. The vulnerability, tracked as CVE-2023-34362, has been added to CISA’s known exploited vulnerabilities list which compels federal agencies to apply available patches expeditiously. Every version of MOVEit Transfer is thought to be affected by the vulnerability and
newswww.itpro.comJun 7, 2023, 11:09 AMMajor companies have confirmed being impacted by the recent MOVEit zero-day attack, including BBC, British Airways and Zellis.
newswww.securityweek.comJun 6, 2023, 11:29 AMThe fallout of the MOVEit Transfer hack via CVE-2023-34362 by the Cl0p gang is expanding, as several UK-based companies have now confirmed that some of their data has been stolen. Victimized organizations The confirmed victims so far are Zellis, “UK and Ireland’s leading provider of payroll and HR solutions for large enterprises and public sector organisations,” and, through it (as it handles data belonging to other companies) British Airways, the BBC, Aer Lingus and Boots. … More →
newswww.helpnetsecurity.comJun 6, 2023, 10:37 AMMore information is coming to light after news last week that a critical vulnerability in a secure file transfer Web application called MOVEit Transfer was being exploited by hackers. Microsoft tied some of the attacks to a threat actor associated with the Clop ransomware gang. “Microsoft is attributing attacks exploiting the CVE-2023-34362 MOVEit Transfer zero-day […]
newswww.csoonline.comJun 5, 2023, 8:55 PMMicrosoft attributes the recent campaign exploiting a zero-day in the MOVEit Transfer platform to the Clop ransomware gang. The Clop ransomware gang (aka Lace Tempest) is credited by Microsoft for the recent campaign that exploits a zero-day vulnerability, tracked as CVE-2023-34362, in the MOVEit Transfer platform. Microsoft is attributing attacks exploiting the CVE-2023-34362 MOVEit Transfer […]
newssecurityaffairs.comJun 5, 2023, 3:00 PM- 5th June – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 5th June, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES One of the United States’ largest dental insurers, MCNA, has notified regulators that information of 8.9 million of the company’s customers has been leaked as a result of a ransomware attack. Notorious ransomware […]
vendorresearch.checkpoint.comJun 5, 2023, 1:56 PM ness-critical file transfers for major banks, credit unions, and federal agencies. Hackers exploited a flaw, tracked as CVE-2023-34362, to obtain access to the database of MOVEit Transfer, a widely-used secure managed file transfer application. Microsoft Threat Intelligence said the attack pattern matched that of the Lace Tempest group, also known as F
newswww.itpro.comJun 5, 2023, 1:41 PM- MOVEit Transfer zero-day was exploited by Cl0p gang (CVE-2023-34362)Help Net Security
The zero-day vulnerability attackers have exploited to compromise vulnerable Progress Software’s MOVEit Transfer installations finally has an identification number: CVE-2023-34362. Based on information shared by Mandiant, Rapid7 and other security researchers, the attackers seem to have opportunistically targeted as many exposed organizations as possible, including US government agencies and banks. Microsoft is attributing the initial attacks to the Cl0p ransomware group (aka FIN11, or Lace Tempest – according to its new threat actor taxonomy). Mandiant … More →
newswww.helpnetsecurity.comJun 5, 2023, 11:56 AM The recent MOVEit zero-day attack has been linked to a known ransomware group, which reportedly stole data from dozens of organizations.
newswww.securityweek.comJun 5, 2023, 10:20 AM- CISA adds Progress MOVEit Transfer zero-day to its Known Exploited Vulnerabilities catalogSecurity Affairs
US CISA added actively exploited Progress MOVEit Transfer zero-day vulnerability to its Known Exploited Vulnerabilities catalog. US Cybersecurity and Infrastructure Security Agency (CISA) added a Progress MOVEit Transfer SQL injection vulnerability, tracked as CVE-2023-34362, to its Known Exploited Vulnerabilities Catalog. Threat actors are actively exploiting a zero-day vulnerability in the Progress MOVEit Transfer file transfer product […]
newssecurityaffairs.comJun 2, 2023, 9:37 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-42660CVSS 8.8 · High
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified…
- CVE-2023-40043CVSS 7.2 · High
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified…
- CVE-2023-36934CVSS 9.1 · Critical
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerab…
- CVE-2023-36932CVSS 8.1 · High
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection v…
- CVE-2023-35708CVSS 9.8 · Critical
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identi…
- CVE-2023-35036CVSS 9.1 · Critical
In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found…