Todos los fabricantes

Vendor lineage

Progress Software - the company that owns the debugger, the load balancer and MOVEit

An American software company that acquired Telerik, Ipswitch and Kemp, and in 2023 became the origin of one of the largest single data-theft campaigns ever recorded.

Progress Software is an American application and infrastructure software company whose acquisitions include Telerik, maker of the Fiddler debugging proxy, the Kemp load balancer line, and the MOVEit managed file transfer product.

Progress is not a name most practitioners would recognise, and most of them use something it owns. Through acquisition it holds Telerik, and with it Fiddler, the debugging proxy that generations of developers learned to read HTTP with; the Kemp load balancer line, which has its own entry here; and MOVEit, a managed file transfer product used by governments, banks and hospitals to move exactly the files they most need to move securely.

That last one is why the company belongs in this catalogue. Over the American Memorial Day weekend of 2023 - a holiday chosen, on the evidence, because defenders respond slowest then - the CL0P group exploited a previously unknown SQL injection flaw in MOVEit Transfer's web application, catalogued as CVE-2023-34362. The flaw let an unauthenticated attacker reach the database. The group installed a web shell called LEMURLOOT and used it to enumerate and exfiltrate whatever the server held. Progress published its advisory on 31 May; exploitation had been observed from 27 May. A second flaw in the same code was found and patched days later.

The reported scale is what makes it a landmark: over two thousand seven hundred organisations and the personal data of more than ninety-five million people, from a single vulnerability in a single product. And the crucial detail is in the government advisory rather than the coverage: the same actor had run zero-day campaigns against Accellion's file transfer appliance in 2020 and 2021, and against Fortra's GoAnywhere in early 2023. Managed file transfer was not chosen at random. It is the category where organisations concentrate their most sensitive outbound data, usually on an internet-facing server, frequently operated by a team that thinks of it as plumbing.

For a practitioner the lesson is about category rather than vendor. A product whose entire purpose is to hold sensitive files and be reachable from outside is a target of a specific kind, and the question to ask of it is not whether the vendor is careful but what happens when - not if - a pre-authentication flaw is found in it. That is the argument the perfect-code article makes, and MOVEit is its clearest single illustration.

Sources