Progress Urges Customers To Shut Down ShareFile Servers Amid Active Cyber Threat
By CU Today Staff —
BURLINGTON, Mass.--Progress Software is urging organizations using self-managed ShareFile Storage Zone Controllers to immediately shut down their on-premises servers after identifying what it called a "credible external security threat" targeting the file-transfer platform, according to Data Breach Today.
Data Breach Today reported the warning came as independent security researchers detected active attempts to exploit a critical authentication bypass vulnerability that Progress patched earlier this year. While the company said it has found no evidence that ShareFile accounts or customer data have been compromised, it has temporarily disabled access to all customer-managed Storage Zone Controllers as a precaution.
The affected controllers allow organizations to store files on their own infrastructure while using ShareFile's collaboration tools. According to Data Breach Today, Progress has not disclosed the exact nature of the threat, but security researchers believe attackers may have found a way to bypass patches released in February for two critical vulnerabilities that could be chained together to gain unauthorized access and execute malicious code on vulnerable servers.
Threat intelligence firm watchTowr previously identified about 30,000 internet-facing ShareFile Storage Zone Controllers, though that number had dropped to roughly 1,000 by Monday, Data Breach Today reported. The Shadowserver Foundation also confirmed it began detecting active exploitation attempts Friday, prompting Progress to advise all customers running on-premises ShareFile Storage Zone Controllers to power down their systems until further guidance is issued.
Originally reported by CU Today.