Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 1 / 2
22 résultats taggé MOVEit  ✕
Progress Software elevates severity of new MOVEit bug to ‘critical’ as exploit attempts jump https://therecord.media/progress-software-elevates-severity-bug
27/06/2024 08:42:58
QRCode
archive.org
thumbnail

The company updated an advisory about a bug affecting the MOVEit tool, warning a “newly identified vulnerability in a third-party component" had elevated the risks.

therecord.media EN 2024 MOVEit Transfer CVE-2024-5806 bug exploited
Auth. Bypass In (Un)Limited Scenarios - Progress MOVEit Transfer (CVE-2024-5806) https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/
27/06/2024 08:41:16
QRCode
archive.org
thumbnail

Progress un-embargoed an authentication bypass vulnerability in Progress MOVEit Transfer.

Many sysadmins may remember last year’s CVE-2023-34362, a cataclysmic vulnerability in Progress MOVEit Transfer that sent ripples through the industry, claiming such high-profile victims as the BBC and FBI. Sensitive data was leaked, and sensitive data was destroyed, as the cl0p ransomware gang leveraged 0days to steal data - and ultimately leaving a trail of mayhem.

watchtowr.com EN 2024 MOVEit CVE-2024-5806 Analysis PoC
Welltok data breach exposes data of 8.5 million US patients https://www.bleepingcomputer.com/news/security/welltok-data-breach-exposes-data-of-85-million-us-patients/
29/11/2023 11:32:12
QRCode
archive.org
thumbnail

Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack.

bleepingcomputer EN 2023 Clop Data-Breach Health-Services Healthcare MOVEit MOVEit-Transfer Ransomware WellTok healthcare
CCleaner confirms data breach via MOVEit attack https://cybernews.com/news/ccleaner-confirms-data-breach/
27/10/2023 08:58:56
QRCode
archive.org

CCleaner, a popular software for cleaning files and Windows Registry entries, has confirmed that attackers accessed some of its customer data.

cybernews EN 2023 MOVEit CCleaner
Sony confirms data breach impacting thousands in the U.S. https://www.bleepingcomputer.com/news/security/sony-confirms-data-breach-impacting-thousands-in-the-us/#google_vignette
04/10/2023 16:50:10
QRCode
archive.org
thumbnail

Sony Interactive Entertainment (Sony) has notified current and former employees and their family members about a cybersecurity breach that exposed personal information.

bleepingcomputer EN 2023 Clop Data-Breach Data-Leak MOVEit MOVEit-Transfer Ransomware Sony Zero-Day
Decade of newborn child registry data stolen in MOVEit mass-hack https://techcrunch.com/2023/09/25/decade-of-newborn-child-registry-data-stolen-in-moveit-mass-hack/
26/09/2023 15:09:08
QRCode
archive.org
thumbnail

The breach affecting more than 3.4 million people — including newborns and children — is one of the biggest MOVEit-related hacks of the year.

techcrunch EN 2023 canada cyberattack Clop data-leak moveit moveit-mass-hacks
MOVEit, the biggest hack of the year, by the numbers https://techcrunch.com/2023/08/25/moveit-mass-hack-by-the-numbers/
26/08/2023 02:03:04
QRCode
archive.org
thumbnail

The mass-exploitation of MOVEit file transfer servers — the largest hack of the year so far — now affects at least 60 million people.

techcrunch EN 2023 MOVEit cyberattack mass-exploitation Clop
Resecurity | Cl0p Ups the Ante with Massive MOVEit Transfer Supply-Chain Exploit https://www.resecurity.com/blog/article/cl0p-ups-the-ante-with-massive-moveit-transfer-supply-chain-exploit
25/08/2023 07:19:21
QRCode
archive.org

The supply-chain cyberattack that targeted Progress Software’s MOVEit Transfer application has compromised over 963 private and public-sector organizations worldwide. The ransomware group, Cl0p, launched this attack campaign over Memorial Day weekend.

Some higher-profile victims of the hack include Maximus, Deloitte, TIAA, Ernst & Young, Shell, Deutsche Bank, PricewaterhouseCoopers, Sony, Siemens, BBC, British Airways, the U.S. Department of Energy, the U.S. Department of Agriculture, the Louisiana Office of Motor Vehicles, the Colorado Department of Health Care Policy and Financing, and other U.S. government agencies. Thus far, the personal data of over 58 million people is believed to have been exposed in this exploit campaign.

resecurity EN 2023 MOVEit Supply-Chain Exploit cyberattack
Data Theft Via MOVEit: 4.5 Million More Individuals Affected https://www.databreachtoday.com/data-theft-via-moveit-45-million-more-individuals-affected-a-22810
20/08/2023 18:17:34
QRCode
archive.org
thumbnail

The fallout from the Clop cybercrime group's mass theft of data from MOVEit servers continues to increase. Colorado's state healthcare agency alone is now notifying

databreachtoday EN 2023 MOVEit Clop Colorado US healthcare
Analysis: MOVEit hack spawned over 600 breaches but is not done yet -cyber analysts | Reuters https://www.reuters.com/technology/moveit-hack-spawned-around-600-breaches-isnt-done-yet-cyber-analysts-2023-08-08/
13/08/2023 21:16:00
QRCode
archive.org
thumbnail

A hydra-headed breach centered on a single American software maker has compromised data at more than 600 organizations worldwide, according to cyber analyst tallies corroborated by Reuters.

reuters EN 2023 MOVEit breaches
Siemens Energy confirms data breach after MOVEit data-theft attack https://www.bleepingcomputer.com/news/security/siemens-energy-confirms-data-breach-after-moveit-data-theft-attack/
27/06/2023 20:36:59
QRCode
archive.org
thumbnail

Siemens Energy has confirmed that data was stolen during the recent Clop ransomware data-theft attacks using a zero-day vulnerability in the MOVEit Transfer platform.

bleepingcomputer EN 2023 MOVEit Siemens-Energy Cl0p Clop ransomware data-theft
‘Several’ US federal agencies affected by MOVEit breach https://therecord.media/several-us-federal-agencies-affected-by-moveit-breach
16/06/2023 09:34:27
QRCode
archive.org

Top U.S. cybersecurity officials confirmed Thursday that several federal agencies have been impacted by cyberattacks on the widely used MOVEit file transfer tool.

Cybersecurity and Infrastructure Security Agency (CISA) Director Jen Easterly told reporters that her team and the FBI are working to provide assistance to federal agencies that used MOVEit, which is being exploited by the Russia-based Clop ransomware gang in a widespread breach that appears to have compromised dozens of entities.

“We’ve been working closely with Progress Software [which makes MOVEit], the FBI and our federal partners to understand its prevalence within federal agencies,” she said. Earlier in the day, CNN first reported that several government agencies were compromised in the hacks. Easterly said that CISA is providing support to “several agencies that have experienced intrusions of their MOVEit applications.”

therecord EN 2023 MOVEit cl0p US federal agencies affected
Ransomware gang lists first victims of MOVEit mass-hacks, including US banks and universities | TechCrunch https://techcrunch.com/2023/06/15/moveit-clop-mass-hacks-banks-universities/
15/06/2023 13:53:44
QRCode
archive.org
thumbnail

The hackers responsible for exploiting a flaw to target users of a popular file transfer tool has begun listing victims of the mass-attacks

techcrunch EN 2023 ransomware MOVEit cl0p victims
CVE-2023-34362 https://attackerkb.com/topics/mXmV0YpC3W/cve-2023-34362/rapid7-analysis
12/06/2023 17:53:05
QRCode
archive.org
thumbnail

On May 31, 2023, Progress Software disclosed a critical SQL injection vulnerability that was later assigned CVE-2023-34362. Rapid7 has observed exploitation in…

attackerkb EN 2023 MOVEit CVE-2023-34362
MOVEit Transfer and MOVEit Cloud Vulnerability https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability
11/06/2023 14:26:06
QRCode
archive.org
thumbnail

This page provides the latest information on the MOVEit Transfer and MOVEit Cloud vulnerabilities. As we continue our investigation and new details are uncovered, this page will be updated. Please check back frequently for updates.

CVE-PENDING (June 9, 2023)
CVE-2023-34362 (May 31, 2023)

progress.com EN 2023 CVE-2023-34362 MOVEit Cloud
Clop Ransomware Likely Sitting on MOVEit Transfer Vulnerability (CVE-2023-34362) Since 2021 https://www.kroll.com/en/insights/publications/cyber/clop-ransomware-moveit-transfer-vulnerability-cve-2023-34362
08/06/2023 23:28:04
QRCode
archive.org
thumbnail

On June 5, 2023, the Clop ransomware group publicly claimed responsibility for exploitation of a zero-day vulnerability in the MOVEit Transfer secure file transfer web application (CVE-2023-34362). Learn more.

kroll EN 2023 MOVEit CVE-2023-34362 Clop CVE-2023-34362
CVE-2023-34362: MOVEit Transfer SQL Injection Vulnerability Threat Brief https://unit42.paloaltonetworks.com/threat-brief-moveit-cve-2023-34362/
07/06/2023 20:25:16
QRCode
archive.org
thumbnail

On May 31, Progress Software posted a notification alerting customers of a critical Structured Query Language injection (SQLi) vulnerability (CVE-2023-34362) in their MOVEit Transfer product. MOVEit Transfer is a managed file transfer (MFT) application intended to provide secure collaboration and automated file transfers of sensitive data.

paloaltonetworks EN 2023 MOVEit SQL Injection Vulnerability CVE-2023-34362
Mass exploitation of critical MOVEit flaw is ransacking orgs big and small | Ars Technica https://arstechnica.com/information-technology/2023/06/mass-exploitation-of-critical-moveit-flaw-is-ransacking-orgs-big-and-small/
07/06/2023 07:46:55
QRCode
archive.org
thumbnail

SQL injection attacks on MOVEit file-transfer service likely to get worse.

arstechnica EN 2023 CVE-2023-34362 MOVEit
Trustwave Action Response: Zero Day Exploitation of MOVEit (CVE-2023-34362) https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trustwave-action-response-zero-day-exploitation-of-moveit-cve-2023-34362/
06/06/2023 19:42:58
QRCode
archive.org
thumbnail

On May 31, threat actors were discovered targeting a critical zero day in MOVEit Transfer software resulting in escalated privileges and unauthorized data access. The vulnerability being exploited is an SQL injection and has since been patched. Resources links, including one for the patch, are at the bottom of this post.

trustwave EN 2023 0-day MOVEit CVE-2023-34362 analysis
MOVEit hack: BBC, BA and Boots among cyber attack victims https://www.bbc.com/news/technology-65814104
05/06/2023 21:31:05
QRCode
archive.org
thumbnail

Staff at multiple organisations are warned of a payroll data breach after an IT supplier is hacked.

bbc EN 2023 MOVEit databreach BritishAirways UK
page 1 / 2
4350 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio