CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Surge in MOVEit Transfer Scanning Could Signal Emerging Threat Activity

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1897

As cited

Copy frozen at (site build).

vulnerabilities

Surge in MOVEit Transfer Scanning Could Signal Emerging Threat Activity

GreyNoise detected a sharp increase in scanning activity targeting MOVEit Transfer systems starting May 27, 2025, with daily scanning IPs jumping from fewer than 10 to over 100, and reaching 319 unique IPs by May 29. This surge suggests potential emerging threat activity or reconnaissance efforts against the file transfer platform.

Why it matters: Organizations running MOVEit Transfer should monitor for exploitation attempts and verify their systems are fully patched, as the spike in reconnaissance activity often precedes active attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Surge in MOVEit Transfer Scanning Could Signal Emerging Threat Activity

GreyNoise detected a sharp increase in scanning activity targeting MOVEit Transfer systems starting May 27, 2025, with daily scanning IPs jumping from fewer than 10 to over 100, and reaching 319 unique IPs by May 29. This surge suggests potential emerging threat activity or reconnaissance efforts against the file transfer platform.

Why it matters: Organizations running MOVEit Transfer should monitor for exploitation attempts and verify their systems are fully patched, as the spike in reconnaissance activity often precedes active attacks.

VendorsProgress Software
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary