About a week ago, the U.S. Cybersecurity and Infrastructure Security Agency and the FBI sent out a joint advisory warning that a file-transfer product called MOVEit contained a dangerous flaw, one that could allow hackers to steal data from affected systems.
It turned out the problem hit close to home. On Thursday, the agency — called CISA for short — provided an update: The very same flaw in MOVEit had been used to breach several U.S. agencies.
CISA Director Jen Easterly said the agency is providing support to departments affected by the MOVEit attack. She said that “as far as we know” the hackers are only stealing information stored on the MOVEit service, and that the intrusions weren’t being leveraged to gain further access to other parts of networks.