Malicious hackers are already targeting a new flaw in a popular file-transfer tool
Summary
Why it matters: Roughly 2,500 instances of Progresss MOVEit file-transfer tool are believed to be running online, and malicious hackers are already exploiting the newly discovered security flaw in it. • Charles Carmakal, chief technology officer at Google-owned Mandiant, said in a statement that his company is already investigating "several intrusions related to the exploitation" of MOVEit. • Huntress, a software vendor popular with small to medium-sized businesses, said in a blog post its identified fewer than 10 organizations running this tool in its customer base, and one of them has seen a "full attack chain" already. The intrigue: It remains unclear who is behind the attack, and, thus far, no criminal groups have started extorting victims whose data has been stolen on the dark web, according to a BleepingComputer report. Be smart: Progress has since released fixes for the affected versions of MOVEit, and the company recommends customers disable any web traffic to the program until theyre able to apply the patches.