Illustrates the widespread impact a single compromised third-party component can have across thousands of organizations.
The 2023 MOVEit data breach, exploited by the Cl0p ransomware group, leveraged a zero-day SQL injection vulnerability in Progress Software's MOVEit managed file transfer software. Discovered in May 2023, the exploit utilized a custom web shell called LEMURLOOT to extract Microsoft Azure Storage Blob data. The breach impacted over 2,700 organizations across government, healthcare, and finance sectors, compromising the personal data of approximately 93.3 million individuals and highlighting severe systemic risks in digital supply chains.
The MOVEit zero-day (CVE-2023-34362) was added to the CISA KEV catalog as an actively exploited vulnerability used by the Cl0p ransomware group to breach 2,700+ organizations.
mass data exfiltration affecting 93.3 million individuals through a single actively exploited vulnerability in a widely deployed file transfer component
CISA KEV cross-referencing is the direct defense against including components with confirmed active exploitation, as demonstrated by MOVEit's devastating supply chain impact.
The MOVEit breach exploited a zero-day SQL injection vulnerability — no patch existed at the time of initial exploitation, leaving all deployed instances vulnerable.
exposure to active exploitation during the window when no patched version is available from the maintainer
tracking vulnerabilities with no available fix is essential for identifying components where the only mitigation is removal or workaround, as was the case during MOVEit's zero-day window.
This zero-day vulnerability enabled attackers to exploit public-facing servers via SQL injection
Risk Guard evaluates all packages equally without understanding their deployment context or whether they expose public-facing network services.
Risk Guard would be better if it categorized packages by their network exposure (e.g., public-facing servers) to appropriately scale the severity of their risks.