Progress urges ShareFile admins to shut down servers over “credible” threat

Progress Software has urged administrators of its ShareFile secure file-sharing platform to immediately shut down their servers due to a “credible external security threat” targeting on-premises Storage Zone Controllers. The warning, sent via email to customers last night, is the latest example of a sophisticated cyberattack aimed at enterprise file transfer and sharing software.

The threat affects organizations that use ShareFile’s hybrid deployment model, where files are stored locally within their own infrastructure while using Progress’ cloud platform for authentication, user management, and collaboration. In this setup, Storage Zone Controllers handle file transfers between the cloud and customer-managed storage, making them internet-accessible servers. The company has instructed customers to manually shut down these Windows servers hosting Storage Zone Controllers, indicating that disabling access through the ShareFile cloud is not enough to mitigate the threat.

Progress Software’s decision to take this precautionary measure comes after identifying a “credible external security threat” targeting its Storage Zone Controllers. While the company has not disclosed whether the threat involves a zero-day vulnerability or whether any Storage Zone Controllers have been compromised, it has temporarily disabled access to ShareFile accounts using these controllers and instructed customers to shut down their servers as an additional step to ensure data safety.

This development is reminiscent of previous attacks targeting enterprise file transfer and sharing software. In 2023, the Clop extortion gang exploited a zero-day vulnerability in Progress MOVEit Transfer to steal data from thousands of organizations before launching a widespread extortion campaign against victims. Since then, attackers have continued to target internet-facing managed file transfer and enterprise file-sharing platforms due to their sensitive data exposure.

The warning issued by Progress Software is an important reminder for security teams to stay vigilant and proactive in protecting their infrastructure. With the increasing sophistication of cyberattacks, it’s essential for organizations to regularly test their defenses and ensure that all layers are secure before attackers can exploit vulnerabilities.

In light of this incident, we recommend that ShareFile administrators take immediate action by shutting down their servers as instructed by Progress Software. Additionally, security teams should review their organization’s overall cybersecurity posture and consider implementing additional measures to prevent similar threats in the future. By staying informed and proactive, organizations can minimize the risk of a successful cyberattack and protect sensitive data.


Source: Bleeping Computer — 2026-07-10