Best podcast episodes on the MOVEit hack
Beginning on May 27, 2023, the Cl0p ransomware gang exploited a previously unknown SQL injection flaw (CVE-2023-34362) in Progress Software's MOVEit Transfer file transfer product. Internet-facing MOVEit servers were infected with a web shell called LEMURLOOT, which was used to steal data from the underlying databases.
Sources: cisa.gov
5 episodes from 5 shows. Dates and lengths are from each show's own feed.
- 01
82. The Clop gang’s in love with a special kind of bug
· 24 min · Beginner
A tight narrative on how Clop pulled off the mass theft, and why its method raised eyebrows.
- 02
Right Royal security threats and MOVEit mayhem
· 55 min · Beginner
CyberWire's Dave Bittner joins for a long segment on the hack as victims were still coming forward.
- 03
#5 - MOVEit Transfer 0day vulnerabilities (Special Guest: Scott Piper)
· 34 min · Practitioner
Cloud researcher Scott Piper and the Wiz team on the zero-days and their cloud exposure.
- 04
· 3 min · Practitioner
The CISA and FBI advisory read aloud in three minutes: the primary source, with indicators and mitigations.
- 05
The Defender's Advantage Podcast
Threat Trends: The Implications of the MOVEit Compromise
· 28 min · Expert
Mandiant's Charles Carmakal on how this campaign differed from FIN11's earlier ones and its long tail.