Attackers exploits MOVEit vulnerability to target government agencies 

Share post:

Government institutions and prominent organizations throughout the world have been subjected to a wave of cyberattacks after a critical vulnerability in the MOVEit file-transfer tool was exploited by hackers.

The Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to that effect, indicating that the attacks are still ongoing, and that the full breadth of the breach is unknown. On May 31, Progress Software uncovered a vulnerability that allows unauthorized access to MOVEit systems, letting attackers to steal private data, install malicious software, or disrupt vital operations.

Investigations have revealed that several prominent organizations, including the Minnesota Department of Education, Ofcom (the United Kingdom’s telecommunications regulator), Nova Scotia’s health authority, British Airways, the BBC, John Hopkins, the Boots pharmacy chain, and the Department of Energy, have fallen prey to this attack.

Jen Easterly, the CISA’s director, noted that the CISA, Progress Software, the FBI, and government partners are collaborating closely to assess the effect of the vulnerability, and that the CISA is now assisting multiple impacted agencies with MOVEit application invasions. Easterly further assured that it is not as large as the SolarWinds campaign and does not represent an immediate danger to national security or the country’s network.

The sources for this piece include articles in Axios and TheRegister.

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday May 17, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, May 17th,...

Cyber Security Today, May 17, 2024 – Malware hiding in Apache Tomcat servers

Malware hiding in Apache Tomcat servers, new backdoors found, and more Welcome to Cyber Security Today. It's Friday, May...

MIT students exploit blockchain vulnerability to steal 25 million dollars

Two MIT students have been implicated in a highly sophisticated cryptocurrency heist, where they reportedly exploited a vulnerability...

Cyber Security Today, May 15, 2024 – Ebury botnet still exploits Linux servers, Microsoft, SAP and Apple issue security updates

The Ebury botnet continues to exploit Linux servers, Microsoft, SAP and Apple issue security updates, and more. Welcome to...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways