As MOVEit developer Progress Software alerted customers to another newly discovered vulnerability, the Clop ransomware gang began disclosing the names of organizations affected by the recent data theft campaign.
Although it has not yet received a CVE, the new bug is rated Critical and “can lead to privilege escalation and potentially unauthorized access to your environment,” Progress warned in yesterday’s update.
For more information on the original MOVEit flaw, see Critical Zero-Day Flaw Exploited in MOVEit Transfer.
While the vendor has patched MOVEit Cloud and fully restored all clusters, MOVEit Transfer customers are requesting all HTTP and You have been asked to immediately disable HTTPS traffic.
This is the third vulnerability discovered in the popular managed file transfer software in recent weeks, following the SQLi bug CVE-2023-34362, which the Clop gang has exploited to infect hundreds of customers worldwide. infringed.
This vulnerability was patched by Progress on May 31st, and a second SQLi vulnerability, CVE-2023-35036, was fixed on June 9th.
With the ransom payment overdue, Klopp started publishing the names of the victims on a dedicated leak site yesterday, as promised.
Emsisoft Threat Analyst Brett Callow said: claimed As of late Thursday, there were 47 confirmed victims, plus an unspecified number of US government agencies.
Energy giant Shell and the University of Georgia are among the new names Klopp has revealed. They joined well-known names such as BA, Boots, BBC and Irish Health Service (HSE).
Charl Van Der Walt, head of security research at Orange Cyberdefense, argued that extortionists would likely try to heighten tensions by dripping victim details.
“It is very likely that not all data will come to light at once in this hack. As we do, we may come up with something eye-catching that the industry and regulators will stand up and take notice of,” he explained. .
“These actors often try to construct a narrative about what they have leaked in their best efforts to justify their actions or to elicit a response from the victim. .”
The US Cybersecurity and Infrastructure Security Agency (CISA) is believed to be helping victims of government attacks.