惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
V
V2EX
T
The Blog of Author Tim Ferriss
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Hugging Face - Blog
Hugging Face - Blog
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Last Week in AI
Last Week in AI
Recent Announcements
Recent Announcements
Vercel News
Vercel News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tailwind CSS Blog
美团技术团队
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Decoding CVE-2023-34362: Unmasking the MOVEit Transfer Vu...
Intel 471 · 2023-06-08 · via Intel 471 Blog

What is CVE-2023-34362?

CVE-2023-34362 is a critical zero-day vulnerability discovered in MOVEit Transfer, a managed file transfer (MFT) software developed by Progress Software. Used widely for secure file transfers, MOVEit Transfer counts approximately 1,700 software companies as users, including the US Department of Homeland Security. This vulnerability is a SQL injection flaw, opening the gates for unauthorized access and manipulation of the database and its content.

Threat Summary

The Lace Tempest group, notorious for ransomware operations and operating the Clop extortion site, has been attributed by Microsoft for exploiting the CVE-2023-34362 vulnerability. The exploitation leads to the deployment of a web shell named "human2.aspx", inserted into the "wwwroot" directory. This web shell is capable of listing all folders, files, and users within MOVEit, downloading any file within the software, and establishing an administrative backdoor user, allowing attackers to maintain persistence. The aftermath of this exploitation has been alarming, with mass exploitation and data exfiltration observed by Mandiant, a leading cybersecurity firm.

Technical Overview

Once the SQL injection vulnerability is successfully exploited, the attackers deploy the web shell "human2.aspx" in the "wwwroot" directory. This web shell is a tool of persistence, helping the attackers maintain access and evade detection by inserting an administrative backdoor user and adding a new admin user account session named "Health Check Service." Various malicious actions can be executed based on the value of the 'X-siLock-Step1', 'X-siLock-Step1', and 'X-siLock-Step3' network request headers.

The exploitation has resulted in significant data exfiltration, indicating widespread attacks. The attackers managed to exploit the vulnerability even before Progress Software could release patches, making it essential for impacted organizations to thoroughly review their environments for any indicators of compromise.

Given the risk, it is strongly advised that organizations using MOVEit Transfer take immediate mitigation measures, including installing patches, monitoring for signs of exploitation, and conducting thorough investigations. This includes checking for the presence of the "human2.aspx" web shell, unusual outbound network transfers, and the unauthorized "Health Check Service" user account.

To arm yourself against such a threat and to leverage the power of knowledge, why not consider getting the free hunting content for this vulnerability? Our dedicated detection engineering and research teams at Cyborg Security are actively developing Hunt Packages to aid in the detection of this threat. Sign up for a free account here, and gain access to hunting content for this vulnerability, along with other insightful resources. Stay a step ahead in your cybersecurity journey.

GET THE FREE HUNT PACKAGES!

CHECK OUT OTHER EMERGING THREATS >