Another MOVEit vulnerability found, as state and federal agencies reveal breaches

General News

Summary

"Our analysis identified multiple files shared via MOVEit Transfer that were accessed by unauthorized actors before we received the security alert," the department said in a statement Thursday. "As far as we know, these actors are only stealing information that is specifically stored on the file transfer application at the precise time that the intrusion occurred," Easterly said. However, Martin did note that MOVEit adheres to the Federal Information Processing Standards, so it likely has a prevalent user base across "government, financial, educational, and other industries that need a FIPS 140-2 compliant file transfer solution." Thus far, CISAs assessment is that the majority of intrusions occurred in the days shortly after the incident was disclosed at the end of May, as the threat actor moved quickly to compromise vulnerable organizations before they could deploy mitigations. The agency moved quickly to limit the federal exposure to the MOVEit campaign, an official said, which resulted in the mitigation of many vulnerable instances before intrusion occurred.

Classifications

industries
Government, Public sector
applications
Business Planning / Continuity

AskAI Classifications

Labels
Enterprise Software SaaS Developer Tools

Linked Companies