Skip to content

Podcasts/Best episodes

Best podcast episodes on the MOVEit hack

Beginning on May 27, 2023, the Cl0p ransomware gang exploited a previously unknown SQL injection flaw (CVE-2023-34362) in Progress Software's MOVEit Transfer file transfer product. Internet-facing MOVEit servers were infected with a web shell called LEMURLOOT, which was used to steal data from the underlying databases.

Sources: cisa.gov

5 episodes from 5 shows. Dates and lengths are from each show's own feed.

  1. 01

    Click Here

    82. The Clop gang’s in love with a special kind of bug

    · 24 min · Beginner

    A tight narrative on how Clop pulled off the mass theft, and why its method raised eyebrows.

  2. 02

    Smashing Security

    Right Royal security threats and MOVEit mayhem

    · 55 min · Beginner

    CyberWire's Dave Bittner joins for a long segment on the hack as victims were still coming forward.

  3. 03

    Crying Out Cloud

    #5 - MOVEit Transfer 0day vulnerabilities (Special Guest: Scott Piper)

    · 34 min · Practitioner

    Cloud researcher Scott Piper and the Wiz team on the zero-days and their cloud exposure.

  4. 04

    CyberWire Daily

    CISA Alert AA23-158A: #StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability.

    · 3 min · Practitioner

    The CISA and FBI advisory read aloud in three minutes: the primary source, with indicators and mitigations.

  5. 05

    The Defender's Advantage Podcast

    Threat Trends: The Implications of the MOVEit Compromise

    · 28 min · Expert

    Mandiant's Charles Carmakal on how this campaign differed from FIN11's earlier ones and its long tail.