Massive authentication vulnerability risks compromising much of the internet

Hackers are already exploiting the flaw.
By Matt Binder  on 
Hacker on laptop
A new exploit found in the enterprise software MOVEit Transfer can have serious consequences for large swaths of the web. Credit: GETTY Images

Another day, another newly discovered exploit. But this vulnerability has the potential to be a really big problem.

This week, Progress Software announced that it had discovered two new items for the common vulnerabilities and exposures (CVE) list of the enterprise product MOVEit Transfer, a popular way for businesses to securely transfer and exchange sensitive files and data. 

This most recent MOVEit vulnerability, known as CVE-2024-5806, allows hackers to bypass authentication protocols and access the potentially sensitive information being transferred.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

While many readers may not be familiar with Progress Software or MOVEit, this vulnerability could result in serious consequences. As Ars Technica points out, a MOVEit vulnerability affected millions of people last year. Thousands of organizations, including the US Department of Energy and Shell, were compromised. The 2023 exploit's effects on the Canadian province of Ontario’s government birth registry alone left 3.4 million people compromised.

Currently, MOVEit is installed on as many as 2,700 networks globally. Bad actors, such as at least one ransomware gang, have already made attempts to exploit this most recent vulnerability, according to cybersecurity researchers with The Shadowserver Foundation and the security firm Censys.

Progress Software has since released a patch to close the exploit, which can be found here.

Topics Cybersecurity


Recommended For You
'The Exorcism' creators on the sins of the film industry
(left to right) Co-writer and director Joshua John Miller, and actors Adam Goldberg, Ryan Simpkins, and David Hyde Pierce smile against a 'The Exorcism' backdrop

The 10 best dating apps for men who know what they want
By Leah Stodart
illustration of man looking at dating app screens


BeReal just got acquired for a huge chunk of change
BeReal in App Store

Crypto scam victims are being scammed double by fake law firms, FBI warns
Money and Bitcoin wallet

Trending on Mashable
NYT Connections today: See hints and answers for July 6
A phone displaying the New York Times game 'Connections.'

This is likely the biggest password leak ever: nearly 10 billion credentials exposed
Login screen

'Wordle' today: Here's the answer hints for July 6
a phone displaying Wordle

NYT Connections today: See hints and answers for July 5
A phone displaying the New York Times game 'Connections.'

How to watch Euro 2024 online for free
General view of the Euro 2024 stadium in Düsseldorf
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!