Progress Software spent 2023 living down MOVEit — the file-transfer tool whose zero-day let the Clop ransomware gang rifle through more than 2,700 organizations and roughly 46 million people’s data, in what’s still one of the ugliest breach years on record. So in October 2024, Progress paid $875 million to acquire ShareFile, the old Citrix-born file-sharing platform, explicitly to diversify its file-transfer portfolio beyond MOVEit’s tarnished name.

Fast forward to July 10, 2026: ShareFile customers got an email telling them to physically shut down the Windows servers running their Storage Zone Controllers, immediately, because Progress had identified a “credible external security threat.” No CVE. No patch. No real explanation beyond “trust us, unplug it” — an email that leaked to Reddit’s r/sysadmin before Progress said a public word about it.

This isn’t even ShareFile’s first rodeo this year. Back in March, Progress quietly patched a pre-auth remote code execution chain in those same Storage Zone Controllers — CVE-2026-2699 and CVE-2026-2701, a CVSS 9.8 authentication bypass chained to a 9.1 RCE, found by watchTowr Labs. The bug was almost insultingly simple: one bad boolean in a .NET redirect kept an admin panel rendering after it should have booted the visitor out, and from there an attacker could smuggle a webshell into the webroot disguised as a legitimate file upload — no login required. watchTowr counted roughly 30,000 of these boxes exposed directly to the public internet.

So: buy a second file-transfer vendor to escape the reputational shadow of the first one’s catastrophic breach, and four months after patching one critical flaw in it, send customers a second “please turn off your file server, we won’t say why” email in the same year. If Progress Software were a stock, you’d short it on symbolism alone.

To be fair, Progress is handling this one better than MOVEit — disabling access and shutting things down before confirming any actual compromise, rather than after. That’s the right instinct. But if you’re an admin who’s now had two “kill your file server” emails from the same vendor in twelve months, the conversation stops being “patch and monitor” and starts being “why does this vendor still hold our clients’ contracts and payroll files.”

The practical takeaway for anyone moving sensitive files through third-party platforms, SaaS or on-prem, isn’t “panic-switch vendors.” It’s that your own credential hygiene is the one layer you actually control when the vendor’s isn’t holding. If admin logins, client portals, or shared drives are sitting behind reused or weak passwords, a vendor’s bad week becomes your bad week too.

Worth trying

If today's story has you thinking about your own password hygiene rather than your vendor's, 1Password's Watchtower feature flags reused, weak, and breached-site passwords automatically — the one control you actually have when a vendor's security doesn't hold.

Sources: BleepingComputer, The Hacker News, Tech Times, watchTowr Labs, TechCrunch, Techzine

Disclosure: this piece may contain affiliate links. If you buy through one, The Daily Take may earn a commission at no extra cost to you. We only link tools we'd genuinely recommend. Full policy on the about page. คำชี้แจง: บทความนี้อาจมีลิงก์พันธมิตร หากคุณซื้อผ่านลิงก์เหล่านี้ The Daily Take อาจได้รับค่าคอมมิชชันโดยไม่มีค่าใช้จ่ายเพิ่มเติมสำหรับคุณ เราแนะนำเฉพาะเครื่องมือที่เราเชื่อมั่นจริง ๆ อ่านนโยบายฉบับเต็มได้ที่หน้าเกี่ยวกับเรา