MOVEit Transfer Under Siege: Brace for a Cyberstorm!

A surge in scanning activity targeting MOVEit Transfer systems has been detected, suggesting a potential comeback tour of attacks. GreyNoise noted a jump in unique IPs on May 27, 2025, with numbers staying elevated. MOVEit Transfer, you might want to reconsider your security dance moves before the hackers start moshing.

Pro Dashboard

Hot Take:

It seems like the MOVEit Transfer systems are the latest contestants in the “Hackers Got Talent” show, and the judges (a.k.a. cybercriminals) are buzzing in with enthusiasm. With unique IPs scanning like they’re auditioning for a cyber opera, it’s time for MOVEit to MOVEit or lose it!

Key Points:

  • There’s been a significant spike in scanning activity targeting MOVEit Transfer systems, starting May 27, 2025.
  • GreyNoise detected up to 682 unique IPs involved in this surge, with Tencent Cloud leading the charge.
  • The bulk of these scanners are based in the US, hinting at a coordinated effort rather than random attacks.
  • Historical context: Clop ransomware gang previously exploited MOVEit vulnerabilities in 2023.
  • Two SQL injection vulnerabilities have been spotted, but no widespread exploitation has occurred yet.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?