Progress Software cleared by SEC for MOVEit exploitation spree incident

August 9, 2024
1 min read



TLDR:

Progress Software reported that the SEC has decided not to take action regarding the MOVEit exploitation incident, after a fact-finding investigation. This decision comes amidst regulatory fallout from other agencies and class action lawsuits.

  • SEC declines to pursue action against Progress Software related to MOVEit exploitation
  • Investigation stemmed from mass exploitation linked to Clop ransomware gang

Progress Software disclosed that the Securities and Exchange Commission (SEC) will not be recommending any enforcement action against the company following the investigation into the MOVEit file-transfer service vulnerability. The incident led to a widespread exploitation spree connected with the Clop ransomware gang, impacting numerous companies and organizations. The SEC subpoenaed Progress in October for a fact-finding probe into how the company handled the attack.

The decision not to pursue enforcement actions from the SEC is a positive development for Progress Software. However, the company still faces regulatory challenges from the Federal Trade Commission, state attorneys general, and ongoing class action lawsuits related to the incident. This news comes shortly after a federal court dismissed most of the civil charges in an SEC case against SolarWinds regarding cybersecurity oversight.

In recent years, federal agencies have been increasingly holding companies and senior executives accountable for their disclosures about cyber risk. Companies like Blackbaud and Uber have faced settlements and convictions for misleading disclosures related to cyber incidents. The SEC’s decision regarding Progress Software is in line with this trend of increased accountability in the cybersecurity realm.


Latest from Blog

Top 20 Linux Admin Tools for 2024

TLDR: Top Linux Admin Tools in 2024 Key points: Linux admin tools streamline system configurations, performance monitoring, and security management. Popular Linux admin tools include Webmin, Puppet, Zabbix, Nagios, and Ansible. Summary

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives

Cyber insurance changes shape of security for good and bad

TLDR: Key Points: Cyber-insurance landscape is shifting to encourage greater cyber resiliency Rising costs of cyberattacks are prompting insurers to re-examine underwriting How Cyber-Insurance Shifts Affect the Security Landscape The article discusses