#ShareFile
This seems really bad. Why would these attorneys keep these files available like this?
November 19, 2024 at 4:47 AM
We added Progress ShareFile fingerprinting to our scans & reports with 784 unique IPs seen exposed on 2026-04-02.

watchTowr recently disclosed details behind an RCE CVE-2026-2699 & CVE-2026-2701 exploit chain affecting ShareFile. Make sure to apply the latest patch!
April 3, 2026 at 9:40 AM
One of our shared logins at work called the group hotline. So you had to send out a Teams message "hey, I'm requesting a 2FA for the sharefile, let me answer it"

Or sometimes we'd get a message "Hey, who's trying to get into sharefile? Your code is 123456"
July 2, 2024 at 1:11 PM
This smells like CL0P ransomware group activity. If you use ShareFile, be like C-3PO and “shut them all down”

I’m so damned tired…but the hits never stop.

via @bleepingcomputer.com
Progress urges ShareFile customers to shut down servers over "credible" threat
Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" t...
www.bleepingcomputer.com
July 10, 2026 at 4:52 PM
Here’s their full statement via @ajvicens.bsky.social:
November 20, 2024 at 2:18 AM
A company called "Progress" bought ShareFile and now you can't update your credit card or check your invoices online or anything.

For over a month.

And their "support" just says it's been escalated.

For over a month.

Sounds like another company is getting red lobstered.
January 31, 2025 at 6:36 PM
sharefile is back baby YAYYYY
July 15, 2025 at 12:11 PM
Update on the Gaetz documents allegedly accessed by some unknown person or entity:

Data swapping platform ShareFile has says the documents were improperly shared to the open internet, leaving them available to “anyone.”

www.reuters.com/world/us/hac...
Hacker accessed documents on Matt Gaetz misconduct allegations, lawyer says
An unidentified hacker accessed copies of confidential testimony in a lawsuit involving allegations of sexual misconduct by Matt Gaetz, U.S. President-elect Donald Trump's attorney general pick, a lawyer involved in the case said on Tuesday.
www.reuters.com
November 20, 2024 at 2:16 AM
Two vulnerabilities in Progress ShareFile, an enterprise-grade secure file transfer solution, can be chained to enable unauthenticated file exfiltration from affected environments.
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
Two vulnerabilities in Progress ShareFile, an enterprise-grade secure file transfer solution, can be chained to enable unauthenticated file exfiltration from affected environments.
www.bleepingcomputer.com
April 2, 2026 at 1:33 PM
15 Captchas in, to gain the ability to hit the ‘reset password’ button, and just deciding that maybe you don’t need to respond to that work item on Sharefile today
May 24, 2025 at 8:52 AM
We are seeing exploitation attempts for Citrix ShareFile storage zones controller CVE-2023-24489 (CVSS 9.8 RCE). 13th June Citrix Advisory with details: https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489
ShareFile StorageZones Controller Security Update for CVE-2023-24489
ShareFile StorageZones Controller Security Update for CVE-2023-24489
support.citrix.com
July 26, 2023 at 9:18 AM
Is the sharefile link working for you? It isn't for me ;(
March 31, 2026 at 4:19 AM
A reminder for tax pros that scammers will try to take advantage of the busy-ness of the season and hope to catch you off guard (yes, some pros are still working on returns).
I'm getting a ton of ShareFile emails, as well as the "I missed the filing date" emails. Let's be careful out there!
April 18, 2025 at 11:57 AM
⚠️ Introducing CVE-2023-24489: A Critical Citrix ShareFile RCE Vulnerability ⚠️
Introducing CVE-2023-24489: A Critical Citrix ShareFile RCE Vulnerability
Discover the critical Citrix ShareFile vulnerability, CVE-2023-24489, a high-risk remote code execution (RCE) flaw, in our in-depth blog post. Learn how unauthenticated attackers could exploit this vu...
www.greynoise.io
July 26, 2023 at 3:58 PM
--Hacker threatens sale of files from ShareFile, Nextcloud, and OwnCloud instances,
--New ClickFix campaign delivers fake BSDs,
--Data from nearly 500k Covenant Health customers exposed in breach,
--Poor risk management leaves NSW hospitals vulnerable to cyber attacks, 4/5
January 6, 2026 at 2:43 PM
I mean, the service is 'ShareFile', and that's what they did. Truth in advertising.
November 19, 2024 at 5:04 AM
A threat actor known as Zestix has been offering to corporate data stolen from dozens of companies likely after breaching their ShareFile, Nextcloud, and OwnCloud instances.
Cloud file-sharing sites targeted for corporate data theft attacks
A threat actor known as Zestix has been offering to corporate data stolen from dozens of companies likely after breaching their ShareFile, Nextcloud, and OwnCloud instances.
www.bleepingcomputer.com
January 5, 2026 at 10:52 PM
We have also added CVE-2026-2699 tagging to our scans, which now detect unpatched Progress ShareFile instances. 120 seen 2026-04-06
dashboard.shadowserver.org/statistics/c...

Tree Map view: dashboard.shadowserver.org/statistics/c...

IP data in Vulnerable HTTP: www.shadowserver.org/what-we-do/n...
April 7, 2026 at 10:27 AM
#mEnabling26 Agenda Spotlight | Thought Leadership | Beyond the Hype: ShareFile & Applause Balance AI & Human Empathy for True Enterprise Scaling

Register now to be a part of the conversation and uncover practical approaches to scale accessibility: https://shorturl.at/MFGqE
#a11y
September 16, 2026 at 1:05 PM
Been editing a tough new finance client. I have never seen a group of editors and writers bond so fast; we all loathe ShareFile. 😅
March 5, 2024 at 11:36 PM
ShareFile (you can send a link and have him enter a password you give him over the phone or text).
July 29, 2026 at 12:49 PM
American Airlines' inflight wifi sucks as much as usual today. So sporadic I can't connect to Sharefile long enough to download a document I need to work on.

In other thoughts, there have been a steady stream of people changing clothes in the plane toilet. Plane loos are so gross, I wouldn't.
August 14, 2024 at 11:41 AM
🚨 We (@greynoise.bsky.social) have a blog about CVE-2023-24489 (Citrix ShareFile RCE) soon, but we’re seeing malicious activity NOW so here's the tag for folks that use us to protect their orgs:

https://viz.greynoise.io/tag/citrix-sharefile-rce-attempt?days=30
July 26, 2023 at 3:08 PM