Progress urges ShareFile admins to shut down servers over “credible” threat

Progress Software has issued a warning to customers using its ShareFile enterprise secure file-sharing platform, urging them to immediately shut down their Storage Zone Controllers due to a “credible external security threat” targeting these on-premises servers. This move affects organizations that use a hybrid deployment model, where files are hosted locally within the company’s storage while leveraging ShareFile’s cloud infrastructure for authentication and collaboration.

In a hybrid setup, Storage Zone Controllers handle file transfers between the cloud platform and customer-managed storage, making them Internet-accessible servers that can potentially be vulnerable to external attacks. Progress is instructing customers to manually shut down their Windows servers hosting these controllers, as disabling access through the ShareFile cloud platform alone may not be enough to mitigate the threat.

The warning email sent to customers by Progress Software reads: “We have reason to believe there is a credible external security threat targeting Progress Software’s ShareFile Storage Zone Controllers. Currently, we have no indication of unauthorized access to any Progress ShareFile accounts or data.” The company has temporarily disabled access to ShareFile accounts using the Storage Zone Controllers as a precautionary measure while it works with internal and external cybersecurity experts to investigate the threat.

Progress’ decision to issue this warning is likely driven by its experience with similar attacks in the past. In 2023, the Clop extortion gang exploited a zero-day vulnerability in Progress MOVEit Transfer, stealing data from thousands of organizations before launching an extortion campaign against victims. This incident, along with others targeting enterprise file transfer and file-sharing platforms, highlights the importance of protecting these sensitive systems.

The fact that Progress is taking proactive measures to safeguard its customers’ data demonstrates the company’s commitment to security. However, this incident serves as a reminder for organizations to remain vigilant in their cybersecurity efforts. The warning from Progress should prompt companies to review their own security protocols and ensure they are adequately prepared to respond to potential threats.

In light of this incident, it’s essential for businesses to prioritize testing and validation of their security controls to prevent similar breaches. By regularly assessing the effectiveness of their defenses, organizations can identify vulnerabilities before attackers do. This proactive approach will help mitigate the risk of data compromise and ensure business continuity in the face of emerging threats.


Source: Bleeping Computer — 2026-07-10