Security Alert: Progress turns off the Storage Zone Controllers for a credible external threat

Author: Published 4 min de lectura 149 reading

The images in this article were generated with artificial intelligence. How we publish

Progress Software has ordered its ShareFile customers to turn off Windows servers that run their Storage Zone Controllers (SZC), an instruction that the company justifies by a "credible external threat". Although the measure has been taken by caution and Progress claims to have no indication of unauthorized access to accounts or data, the decision to completely disconnect these servers, rather than only apply patches, reveals the potential gravity of the incident and leaves key questions unanswered: what kind of threat is, who is behind and if there was intrusion.

The SZC is an on-premises component that allows you to keep the files in the organization's own storage and use the ShareFile cloud to share and manage those data. This architecture is useful, but it makes the controller an attractive goal: it is usually on the edge of the network and is accessible from the Internet, which increases its exposure to exploits, web shells and control and control traffic. That's why. follow the order to turn off the drivers and keep them off-line until the supplier authorizes is the first and most prudent recommendation.

Security Alert: Progress turns off the Storage Zone Controllers for a credible external threat
Image generated with IA.

From an operational security perspective, treat any Internet-accessible controller as a potential incident. Preserve the logs and activate the incident response process: capture records of IIS / HTTP, Windows events, ShareFile / Storage Zone and network devices; make forensic images if available; and document each action to maintain the chain of custody. Do not restart or change credentials in a hasty manner: if the system is compromised, certain actions (such as starting services or disassembling evidence) can erase signs or activate malicious loads.

In addition to following the Progress instruction, confirm the driver's version: the 5.x branches must be in the 5.12.4 or later and, if appropriate, in a 6.x release, because these versions close the vulnerabilities previously covered. However, do not interpret the version as a sausages; Progress has not yet said that the known updates remove the current threat, so the simple update should not be a reason to re-put the server on the Internet until explicit notice is received.

Look for concrete engagement indicators on affected servers: unknown .aspx files on web directories and storage routes, artifacts that can be web shells, suspicious processes, outgoing connections to PIs or unusual domains and changes to service accounts or programmed tasks. Use EDR / AV tools to identify abnormal behaviors and correlate with network records. A server that "seems clean" does not guarantee the absence of intrusion: many modern threats use persistent, difficult to detect without a deep analysis.

Security Alert: Progress turns off the Storage Zone Controllers for a credible external threat
Image generated with IA.

This is not the first time this technology has appeared in serious incidents: in 2023 a vulnerability was exploited in Storage Zone Controller (CVE-2023-24489) and CISA described it as being exploited in nature; in parallel, Progress inherited the history of the file transfer ecosystem following the MOVEit crisis in 2023, which affected thousands of organizations. This context underlines the need for robust procedures: network segmentation, strict remote access control, continuous updating and proven recovery plans. Previous lessons show that attackers seek similar vectors and that coordination with the supplier and authorities is critical to mitigating impact.

Immediate practical actions: keep the SZC offline until Progress indicates otherwise; contact your Progress support team and record the incident; preserve telemetry and evidence; perform a forensic analysis if you suspect commitment; and prepare internal and, if appropriate, external communication for customers and regulators according to their legal obligations. Consider also notifying your national CERT or agencies such as CISA to get guidance and share IOC if you have them. Official resources and historical measures are available on the supplier's and cybersecurity sites, for example at Progress Software and on the page of the US Infrastructure and Cybersecurity Agency. United States. CISA and for technical journalistic coverage in The Hacker News.

In the medium term, organizations should review their external exposure of controllers, apply strict segmentation, strengthen monitoring and apply minimum privilege principles. It is also prudent to integrate incident response exercises that simulate controlled closures and restorations, and to verify that the backups are resilient and not accessible from the compromised environment. Until Progress does not detail the nature of the threat and confirms the cleaning, caution and forensic evidence should guide all decisions.

Coverage

Related

More news on the same subject.