Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers
Overview
Progress Software has disabled access to its ShareFile accounts due to a credible external security threat involving the Storage Zone Controllers (SZC). These controllers are the on-premises servers where organizations store files shared through ShareFile. On July 10, the company alerted customers via email, instructing them to manually shut down their servers hosting these controllers. This measure aims to protect users from potential security breaches. Customers using ShareFile should take immediate action to secure their data and prevent unauthorized access.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: ShareFile, Storage Zone Controllers (SZC)
- Action Required: Customers are advised to manually shut down their Storage Zone Controllers.
- Timeline: Disclosed on July 10, 2023
Original Article Summary
A “credible external security threat” targeting Progress Software’s ShareFile Storage Zone Controllers (SZC) – the on-premises, customer-managed server components where organizations store files shared via this popular enterprise platform – has spurred the company to disable access to ShareFile accounts that are using them. The warning was sent to customers via email on July 10, urging them to manually shut down the server that is hosting their Storage Zone Controllers. The initial email alert from … More → The post Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers appeared first on Help Net Security.
Impact
ShareFile, Storage Zone Controllers (SZC)
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on July 10, 2023
Remediation
Customers are advised to manually shut down their Storage Zone Controllers.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.