
tutorials · 8 min
MOVEit: the pre-auth SQLi Cl0p turned into the event of the year
CVE-2023-34362 is a pre-auth SQL injection in MOVEit Transfer that Cl0p exploits as zero-day from 27 May. The chain goes SQLi → MachineKey leak → session forge → LEMURLOOT web shell drop (human2.aspx). Result: 2,700+ organisations exposed before the year ends.
· Manuel López Pérez









