June 2, 2023, 10:20 p.m. |

BankInfoSecurity.com RSS Syndication www.bankinfosecurity.com

Mandiant Said TTPs of Threat Group Behind Exploiting MOVEit Appear Similar to FIN11
Adversaries have taken advantage of a zero-day vulnerability in Progress Software's managed file transfer product to deploy web shells and steal data, Mandiant found. An unknown threat actor began exploiting the critical SQL injection vulnerability in MOVEit Transfer on May 27.

actor critical data exploiting file file transfer flaw hackers injection managed managed file transfer mandiant moveit moveit transfer product progress shells software sql sql injection steal taken threat threat actor threat group ttps vulnerability web zero-day zero-day vulnerability

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Information Security Specialist, Sr. (Container Hardening)

@ Rackner | San Antonio, TX

Principal Security Researcher (Advanced Threat Prevention)

@ Palo Alto Networks | Santa Clara, CA, United States

EWT Infosec | IAM Technical Security Consultant - Manager

@ KPMG India | Bengaluru, Karnataka, India

Security Engineering Operations Manager

@ Gusto | San Francisco, CA; Denver, CO; Remote

Network Threat Detection Engineer

@ Meta | Denver, CO | Reston, VA | Menlo Park, CA | Washington, DC