Document server ransom attack.
"This joint (Federal Bureau of Investigation and Cyber Security and Information Security Agency) Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish warnings for network defenders that detail various ransomware variants and this effecting threats through ransomware threat. These #StopRansomware warnings include recently and historically observed tactics, techniques, and procedures and indicators of compromise to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware warning notices and to learn more about other ransomware threats and no-cost resources." (edited)
According to open source information, The USA's Cyber Security and Information Security Agency says, beginning on 27 May, 2023, CL0P Ransomware Gang, also known as TA505, began exploiting a previously unknown SQL injection vulnerability (CVE-2023-34362) in Progress Software's managed file transfer (MFT) solution known as MOVEit Transfer. Internet-facing MOVEit Transfer web applications were infected with a web shell named LEMURLOOT, which was then used to steal data from underlying MOVEit Transfer databases. In similar spates of activity, TA505 conducted zero-day-exploit-driven campaigns against Accellion File Transfer Appliance (FTA) devices in 2020 and 2021, and Fortra/Linoma GoAnywhere MFT servers in early 2023.
The full notice and links to resources are here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a
This is important because many organisations, large and small, use online document transfer services and online document approvals services.
These are used by, for example, tax form preparers, law firms settling terms of a document and more. The confidential nature of the documents in such services is paramount.


