No systemic risk to government networks from latest breach, CISA says
Summary
CISA and the FBI issued a joint cybersecurity advisory last week warning that hackers were capable of exploiting a vulnerability to steal data from underlying MOVEit databases developed by Progress Software. The official said that CISA had not identified any impact on military or IC networks, and was not aware of any federal agencies still running unmitigated versions of the MOVEit application. Progress Software filed a disclosure report about the exploit with the Securities and Exchange Commission on May 30 indicating the company first got word of the zero day vulnerability on May 28. While it remains unclear who was behind the cyberattack impacting federal agencies, CISAs advisory said that one of the largest phishing and ransomware groups worldwide had begun exploiting the MOVEit vulnerability. The Russian-linked ransomware gang called CL0P, or TA505, has previously leveraged similar exploits to conduct campaigns that targeted popular file transfer and software databases earlier this year.