CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

MFT Exploitation and Adversary Operations | Huntress

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1019

As cited

Copy frozen at (site build).

vulnerabilities

MFT Exploitation and Adversary Operations | Huntress

Huntress analyzed CVE-2023-43117, a vulnerability in CrushFTP, as part of a broader trend of adversaries exploiting managed file transfer (MFT) applications to gain unauthorized access and control. The vulnerability and similar MFT exploitation tactics represent an expanding attack surface that organizations commonly overlook. Security teams should prioritize patching and monitoring these file transfer systems due to their privileged access and operational criticality.

Why it matters: Organizations using MFT applications like CrushFTP face immediate risk from active exploitation of CVE-2023-43117 and similar vulnerabilities, requiring urgent patching and detection of suspicious file transfer activities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

MFT Exploitation and Adversary Operations | Huntress

Huntress analyzed CVE-2023-43117, a vulnerability in CrushFTP, as part of a broader trend of adversaries exploiting managed file transfer (MFT) applications to gain unauthorized access and control. The vulnerability and similar MFT exploitation tactics represent an expanding attack surface that organizations commonly overlook. Security teams should prioritize patching and monitoring these file transfer systems due to their privileged access and operational criticality.

Why it matters: Organizations using MFT applications like CrushFTP face immediate risk from active exploitation of CVE-2023-43117 and similar vulnerabilities, requiring urgent patching and detection of suspicious file transfer activities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary