Infosecurity

Progress Software Flags ‘External Security Threat’ Targeting ShareFile Storage

Published

on

What Happened?

Progress Software has told some customers that its flagship enterprise file-sharing service, ShareFile, is facing a “credible external security threat.” The warning, issued on July 10, specifically targets Storage Zone Controllers — the component that gives ShareFile clients private data storage.

The company’s email, later posted on its official ShareFile Community forum, confirmed that access to certain accounts had been temporarily disabled as a precaution. There’s no evidence yet of unauthorized access to any customer data, but Progress is urging users to manually shut down the servers hosting their Storage Zone Controllers.

That’s a strong ask. It essentially tells admins to pull the plug on their own infrastructure while the company investigates.

What Is Storage Zone Controller?

For those unfamiliar, Storage Zone Controller is what makes ShareFile different from a run-of-the-mill cloud drive. Instead of storing everything on Progress’s servers, organizations can keep their data in their own data centers or in a cloud environment they control. That’s a big selling point for regulated industries like healthcare and legal services.

But it also means a vulnerability in this component could expose sensitive data at the customer’s location, not just at Progress’s central cloud.

Timeline of the Incident

Here’s what we know so far, based on the company’s statements and user reports:

  • July 10: Progress sends emails to affected customers, warning of the threat and disabling access.
  • July 10: Company says users will hear an update within 24 hours.
  • July 12 (5 p.m. ET): Progress claims all ShareFile customers with Storage Zone Controllers have been notified that cloud access is restored.
  • July 13: Reddit users report three days of silence. The status portal still shows the July 10 update as the latest.

That gap between promise and delivery hasn’t sat well with some users. One Reddit thread from July 13 is full of admins asking the same question: what’s actually going on?

Progress, for its part, said in a statement to Infosecurity that Storage Zone Controllers “must remain turned off while we complete our investigation.” So cloud access is back, but the on-premise piece is still frozen.

Is This Connected to MOVEit?

It’s impossible to talk about Progress Software security without mentioning the elephant in the room: MOVEit Transfer. In 2023, a critical vulnerability in that product was exploited in widespread ransomware attacks that hit hundreds of organizations. The fallout was massive, and it put a spotlight on Progress’s security practices.

Now, some forum participants are speculating that this ShareFile incident could be related to a recently disclosed vulnerability or even a new zero-day. Progress hasn’t confirmed any of that. In fact, the company says it has “not identified any active threat.”

That’s a reassuring line, but it’s also worth remembering that the MOVEit breach initially looked contained too. The company’s history makes it hard to give it the benefit of the doubt.

What Should ShareFile Customers Do?

If you’re running a Storage Zone Controller, here’s the practical advice:

  1. Keep it off. Progress has explicitly said controllers must remain powered down until further notice. Don’t rush to reboot.
  2. Monitor the status portal. The official ShareFile status page is the best source for updates, even if it’s been quiet lately.
  3. Check your logs. Once access is restored, review access logs for any suspicious activity during the window.
  4. Talk to your account rep. If you’re a paying customer, you should be getting direct communication. If you’re not, ask why.

It’s also a good moment to review your overall enterprise file sharing security posture. Incidents like this are a reminder that even trusted vendors can be a weak link.

The Bigger Picture

Progress Software has had a rough couple of years on the security front. The MOVEit breach was a black mark that the company has been trying to live down, and now this. It’s not a good look for a vendor that positions itself as a trusted name in secure file transfer.

For CISOs and IT admins, the lesson is familiar but worth repeating: third-party risk is real. If you’re using a service like ShareFile to store sensitive data, you need a contingency plan. That means backups, alternative communication channels, and a clear understanding of what your vendor will do when things go sideways.

Progress says it has launched internal and external security investigations. No timeline has been given for when the full picture will emerge. Until then, the advice is simple: keep those controllers off, and keep an eye on your inbox.

We’ll update this story as more details become available.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version