Ofcom Latest MOVEit Victim as Exploit Code Released
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-34362 | Unauthenticated SQL Injection in Progress MOVEit Transfer CVE-2023-34362 is an unauthenticated SQL injection flaw (CWE-89) in Progress MOVEit Transfer that allows an attacker with no credentials to gain unauthorized access to the product's database. It is triggered remotely via crafted input submitted to the MOVEit Transfer web application, with the impact varying by the backend database engine in use (MySQL, Microsoft SQL Server, or Azure SQL). A successful attacker can infer the structure and contents of the database and, depending on the engine, execute SQL statements that alter or delete database elements, exposing data handled by the file-transfer service. Any organization running an internet-reachable MOVEit Transfer instance is affected; public internet-exposure scans around disclosure identified on the order of a few thousand servers, each typically serving enterprise or government user bases. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2023-06-02 with known ransomware use and an EPSS exploitation probability of 99.9% (100th percentile), while no public PoC is known. Do: Apply the vendor's updates immediately, per Progress instructions and CISA's required action. Until patched, restrict internet exposure of MOVEit Transfer and check the backend database for unexpected structure or content changes and deletions. Because in-the-wild exploitation and ransomware use are confirmed, treat any unpatched, internet-facing instance as potentially compromised and review stored transfer data and access logs for anomalies. | 9.8 | 100% | KEV ransomware PoC |
| large≈2,000-3,000 internet-exposed MOVEit Transfer servers (public internet-exposure scans) |
Full article352 words · extracted from infosecurity-magazine.com · click to collapse

UK communications regulator Ofcom has become the latest organization to be impacted by the Clop extortion campaign targeting a zero-day bug in MOVEit software.
Ofcom confirmed the news in a brief statement yesterday. Although its own systems were not compromised during the attack, threat actors managed to access information of both the organizations it regulates and its own staff.
Read more on the MOVEit zero day bug: Critical Zero-Day Flaw Exploited in MOVEit Transfer.
“A limited amount of information about certain companies we regulate – some of it confidential – along with personal data of 412 Ofcom employees, was downloaded during the attack,” Ofcom explained.
“We took immediate action to prevent further use of the MOVEit service and to implement the recommended security measures. We also swiftly alerted all affected Ofcom-regulated companies, and we continue to offer support and assistance to our colleagues.”
The news follows an admission by the Irish health service (HSE) late last week that it was also impacted by the data-stealing campaign.
“The HSE became aware yesterday evening (June 8) that an external partner (EY) working with us on a project to automate part of our recruitment process was alerted to a cyber-attack on the technology product MOVEit which they were using to support this work,” it explained in a statement.
“This analysis has determined that is it likely that information relating to no more than 20 individuals involved in recruitment processes was accessed. The data on these recruitment panels is comprised of names, addresses, mobile number, place on the panel and more general information on the posts being recruited. Importantly no other personal identification data or financial data is included.”
Attributed to an affiliate of the Clop ransomware group, the campaign exploited a zero-day vulnerability (CVE-2023-34362) in the popular file transfer software to exfiltrate data from a large number of global companies.
The chances of copycat attacks has theoretically grown in recent days after the release of a proof-of-concept exploit last Friday. Any organizations still running unpatched internet-exposed servers would be advised to urgently update their systems.
Editorial image credit: T. Schneider / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ofcom-latest-moveit-victim-exploit/