Progress tells ShareFile customers to shut down servers over 'credible' security threat

Progress Software has taken the unusual step of emailing customers of its ShareFile file-sharing platform and instructing them to immediately shut down on-premises servers, citing a “credible external security threat” targeting ShareFile Storage Zone Controllers, BleepingComputer reports. The company has also temporarily disabled access to ShareFile accounts that use the affected component.

Storage Zone Controllers are Windows servers deployed by organizations that want their files hosted on their own storage while still using ShareFile’s cloud platform for authentication, sharing, and collaboration. Because these controllers broker file transfers between the cloud and customer-managed storage, they are typically exposed to the internet — precisely the kind of target that has drawn extortion groups in the past.

In its notice, titled “Service Disruption. Immediate Action Required,” Progress said it currently has no indication of unauthorized access to ShareFile accounts or data, but stressed that customers must manually power down the servers hosting their Storage Zone Controllers as a critical precaution — suggesting that cutting cloud access alone is not sufficient to mitigate the threat. The company said it is working with internal and external cybersecurity experts and promised further updates.

Progress has not said whether the threat involves a zero-day vulnerability or whether any controllers have already been compromised. The episode echoes the 2023 mass exploitation of Progress’ MOVEit Transfer product, in which the Clop extortion gang exploited a zero-day flaw to steal data from thousands of organizations worldwide — a campaign that made internet-facing managed file transfer platforms a favorite target for data-theft extortion ever since.

Read the original report →