MOVEit Transfer
Lace Tempest Exploits SysAid Zero-Day Flaw
In a recent revelation, SysAid, a leading IT management software provider, has unveiled a critical security threat affecting its on-premises software. The threat actor, identified as DEV-0950 or Lace Tempest by Microsoft, ...

CISA Warning: MOVEit Has Yet Another Zero-Day SQL Injection RCE Bug [updated]
Once is happenstance. Twice is coincidence. Three times is sheer incompetence ...

CISA Order Highlights Persistent Risk at Network Edge
The U.S. government agency in charge of improving the nation's cybersecurity posture is ordering all federal civilian agencies to take new measures to restrict access to Internet-exposed networking equipment. The directive comes ...
MOVEit! An Overview of CVE-2023-34362
On May 31st, 2023, Progress disclosed a serious vulnerability in its MOVEit Transfer software. The vulnerability is remotely exploitable, does not require authentication, and impacts versions of the software that are 2023.0.1 ...