{"id":1709,"date":"2026-07-10T19:32:19","date_gmt":"2026-07-10T19:32:19","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1709"},"modified":"2026-07-10T19:32:19","modified_gmt":"2026-07-10T19:32:19","slug":"progress-tells-sharefile-customers-to-shut-down-storage-zone-controllers-over-security-threat","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1709","title":{"rendered":"Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 10, 2026<\/span><\/span><span class=\"p-tags\">Enterprise Security \/ Security Incident<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgULXOG2_Ph1198nw2lOea2pYE9u1GkPHaaMlzhpO48pOmejpWKFuHbchUac5JIRQHGiIMMTefXq-LktA8AjsqqMIsBS54bLaludxIJbq7chYfo_Vsoqf9Xi7YomnSUL9wHAYa5InCST76k1aP10VMmNKK_MDLD3o5zNXyB4ODMRMl0DbLkz9f2mg2k2S8\/s1700-e365\/progress.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to <strong>The Hacker News<\/strong> that it is responding to a \u00abcredible external security threat.\u00bb<\/p>\n<p>The company has temporarily disabled access to the affected accounts, a step it says it took \u00about of an abundance of caution\u00bb while it works with internal and external security experts.<\/p>\n<p>It says it has no indication of unauthorized access to any ShareFile accounts or data, and that it notified customers after learning of the threat.<\/p>\n<p>What Progress has not said is what the threat is or who is behind\u00a0it.<\/p>\n<p>The order became public when a customer posted the company&#8217;s email to Reddit&#8217;s\u00a0<a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/1usohco\/psa_shutdown_your_sharefile_storage_zone\/\" target=\"_blank\">r\/sysadmin<\/a>\u00a0on July 10. Progress\u00a0<a href=\"https:\/\/status.sharefile.com\/\" target=\"_blank\">confirmed the disruption<\/a> on its status page, listing Storage Zone Controller customers as \u00abnot operational\u00bb and the incident as under investigation as of a 12:12 p.m. EDT update.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Only the Storage Zone Controller is affected, not standard cloud-only ShareFile accounts. The controller is a server that a company runs itself, so files can stay on its own storage while it still uses ShareFile&#8217;s cloud to share and manage them.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The controller usually sits at the network&#8217;s edge, reachable from the internet. That exposure makes it both useful and a target. Ordering customers to take it fully offline, rather than just patch it, is a notable step.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuIEperKcgWWot-nes4WRvJrO5SGh6v427wpkWQooK_eTA9AGQzfo1YTPo9aSmrCZ25_e9NKLgRAGG9wiYyjY0Sf7tXiigFaTpLveXt6waUA2BSXpU2Ec5zWqAJaWMnM0f9sKuYOF0QklaPLgl1GZwPZbtFkVQJn9H_MpMWwJeKMkgC33dCEISt8SGS54\/s1700-e365\/email.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuIEperKcgWWot-nes4WRvJrO5SGh6v427wpkWQooK_eTA9AGQzfo1YTPo9aSmrCZ25_e9NKLgRAGG9wiYyjY0Sf7tXiigFaTpLveXt6waUA2BSXpU2Ec5zWqAJaWMnM0f9sKuYOF0QklaPLgl1GZwPZbtFkVQJn9H_MpMWwJeKMkgC33dCEISt8SGS54\/s1700-e365\/email.jpg\" alt=\"\" border=\"0\" data-original-height=\"698\" data-original-width=\"900\"\/><\/a><\/div>\n<p>That choice is itself a tell. If a fix for this threat existed, Progress would be telling customers to apply it; the shutdown order suggests there is none yet. That usually means a newly found flaw the company is racing to close, though the same step would also fit a threat a patch cannot address, such as stolen keys or a problem on Progress&#8217;s own side.<\/p>\n<p>Its statement that no accounts or data were accessed is careful wording, too, and does not rule out trouble on the controllers themselves.<\/p>\n<h2>What to do\u00a0now<\/h2>\n<ol>\n<li>Follow the shutdown order first. Keep the affected controllers offline until Progress says what the threat is and when it is safe to restart.<\/li>\n<li>Separately, confirm your version is current:\u00a05.12.4\u00a0or later on the 5.x line, or a 6.x release. That closes the flaws fixed earlier this year, but Progress has not said it clears the current threat, so do not treat it as permission to restart.<\/li>\n<li>If a controller is reachable from the internet, handle it as a possible incident. Preserve the logs and start your incident-response process, then check for unfamiliar\u00a0.aspx\u00a0files in the web folders and storage paths you did not set. A clean-looking server is not proof that it is clean.<\/li>\n<\/ol>\n<p>ShareFile has faced this before. In 2023, while the product still belonged to Citrix, attackers exploited an unauthenticated flaw in the same Storage Zones Controller (CVE-2023-24489).<\/p>\n<p>CISA\u00a0flagged it as actively exploited, and Citrix cut unpatched controllers off from the ShareFile cloud, the same access block Progress has now imposed.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiBxLQDy7VdLze43eMmpRllTXaPKPfB_veNUxQlqIu3-68GBJtegkhDGCqtaiSymOQviROdxln1FSd4zdMp5Jv9jeF1xQxLPc9uo9H7zW2nWHNax0wT0Y8JRj-zyUfbaCLqhxSfQT2sCfhWMBPL6UVgsh5RYVNVxwus_mW_BY9Ptwz3z7iF0_LWOnte-gqg\/s1600\/sy-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Progress, which acquired ShareFile in 2024, had already weathered a mass file-transfer attack of its own: MOVEit, whose 2023 zero-day was exploited by the Clop group and hit more than 2,700 organizations.<\/p>\n<p>The Storage Zones Controller also had two critical flaws that watchTowr\u00a0disclosed in April and Progress patched in March, though the company has not connected the current threat to them, and neither has been reported as exploited.<\/p>\n<p>The central question is still unanswered: Progress has pulled these systems offline and is working with outside experts, but has not said what the threat is or when customers can safely bring them back online.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Jul 10, 2026Enterprise Security \/ Security Incident Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1710,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2480,2109,1513,47,2477,676,2478,2476,171,2479],"class_list":["post-1709","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-controllers","tag-customers","tag-progress","tag-security","tag-sharefile","tag-shut","tag-storage","tag-tells","tag-threat","tag-zone"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1709","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1709"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1709\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1710"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1709"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1709"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1709"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}