CuraSec

tag: File-Sharing · 2 items

2026-07-15 · BleepingComputer · source ↗ #zero-day#sharefile#file-sharing
  • Engineer — Act: If you run ShareFile Storage Zone Controllers on-premises, apply the released security updates immediately — Progress shutting down the hosted service is a strong implicit signal of active exploitation risk, mirroring their MOVEit pattern.
  • SOC/IR — Plan: No IOCs or TTPs are available yet, but queue a hunt workflow for once Progress or third-party researchers publish exploitation indicators; given Progress’s MOVEit history, details will likely emerge quickly.
  • Leader — Act: Confirm whether your organization runs ShareFile Storage Zone Controllers on-prem, then check with Progress for breach attestations this week — an emergency service shutdown from this vendor warrants a fast exposure check before board or customer questions arrive.
2026-07-11 · BleepingComputer · source ↗ #sharefile#progress-software#file-sharing
  • Engineer — Act: If you run ShareFile Storage Zone Controllers on-premises, shut them down immediately per Progress’s emergency guidance — this is the same vendor that disclosed the MoveIt zero-day. Monitor Progress’s advisory channel for patch availability before bringing servers back online.
  • SOC/IR — Act: Progress issuing an emergency shutdown recommendation implies an unpatched, actively targeted vulnerability; treat any org running on-prem ShareFile Storage Zone Controllers as potentially exposed. Initiate a sweep for anomalous file-transfer or lateral-movement activity from those hosts since at least 72 hours prior to today.
  • Leader — Act: Progress Software — the MoveIt vendor — is issuing emergency shutdown orders for ShareFile on-premises deployments, a pattern consistent with imminent or in-progress exploitation. This week: confirm whether your org or any critical SaaS vendors run on-prem ShareFile Storage Zone Controllers and request attestations; brief leadership before this surfaces in news as a repeat of the MoveIt incident.