Power Off, Don't Patch: What a Shutdown Directive Actually Tells You
Progress ordered customers to power off production servers. Vendors ship hotfixes and workarounds. They don't do that unless exploitation is active with no viable patch, or containment can't be guaranteed while the service runs. Read it either way and every Storage Zone Controller is compromised until proven otherwise. The precedent is MOVEit. Managed file transfer concentrates your most sensitive third-party data flows, and Cl0p turned that into one of the largest data-extortion events on record. Pure exfiltration. No ransomware at all.
Sequence matters. Shut down first and you destroy the evidence behind any breach-notification decision. Capture logs, memory, and network flow data before pulling the plug. Then hunt 30 days of outbound for large or anomalous transfers. Under GDPR and SOC 2, the clock runs from awareness. A vendor-confirmed 'credible external security threat' arguably starts it.
The same-day mail-tier problem
Stacked on top: a Zimbra Classic Web Client RCE firing via crafted email in user sessions. Low-interaction vector, riding sanctioned mail flow past perimeter controls. A patch exists, so the diff is public. Mass weaponization is days away. Prioritize internet-facing Zimbra with Classic Web Client enabled. Disabling the Classic client where migration is feasible removes the surface entirely.
The vendor-risk line for tonight's board note
This is Progress's second major file-transfer emergency. Commonly placed within three years of MOVEit, though today's sources don't date that campaign. That reads as concentration risk in a category built to hold regulated data in transit. Add ShareFile to the vendor-risk reassessment queue and scope alternatives now, Egnyte and Box, so a forced migration isn't improvised mid-incident. If exfiltration is confirmed, the MOVEit script extrapolates cleanly, and this is our read, not today's sources: leak sites, regulator notifications, class actions. Pre-write communications before attribution lands.
What to do
Inventory all ShareFile Storage Zone Controllers today, preserve logs and network flow data, then execute Progress's shutdown directive and hunt 30 days of egress for exfiltration indicators
Patch all internet-facing Zimbra instances this week and disable Classic Web Client wherever the modern client is viable; hunt mail-server logs for message-triggered process spawns
Add ShareFile to the vendor-risk reassessment queue this quarter and scope managed-file-transfer alternatives before any forced migration