Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
Sign in
Get a free key
Product
Threat intelligence API
Get started
Live feed
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
Docs
OpenAPI reference
Examples on GitHub
Integrations
Export formats
Pricing
For service providers
Use cases
Contact
Sign in
Get a free key
Back
Moveit
Vulnerability
Threat entity extracted from intelligence sources
Entities
›
vulnerability
›
Moveit
Frequency
29
occurrences
First Seen
October 29, 2025
Last Seen
August 18, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Exploited By
Midnight Blizzard
Ta505
Volt Typhoon
Cl0p
Clop
Clop Ransomware Group
FIN11
Unsafe
Tools Used
Cleo file transfer programs
Fortra GoAnywhere
LiteLLM
Openssl
Triofox
Related CVEs
CVE-2025-40538
CVE-2025-40539
CVE-2025-40540
CVE-2025-40541
CVE-2025-40551
CVE-2026-28314
CVE-2026-28315
CVE-2026-28316
MITRE Techniques
T1567 - Exfiltration Over Web Service
T1041 - Exfiltration Over C2 Channel
T1195 - Supply Chain Compromise
T1566 - Phishing
T1486 - Data Encrypted for Impact
T1190 - Exploit Public-Facing Application
T1021 - Remote Services
T1059 - Command and Scripting Interpreter
Campaigns
Oracle EBS campaign
Clop Oracle EBS Campaign
MOVEIT exploit campaign
MOVEit Mass Hack
Oracle hacking campaign
Affected Platforms
Oracle E-business Suite
GoAnywhere
Accellion
Serv-U
SolarWinds Serv-U
PaperCut
Regions
Germany
United States
Russia
Canada
China
Sectors Affected
Financial
Healthcare
Government
Manufacturing
Aerospace
Automotive
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
2
IA
Initial Access
T1566 - Phishing
T1190 - Exploit Public-Facing Application
1
EX
Execution
T1059 - Command and Scripting Interpreter
1
PE
Persistence
T1136 - Create Account
1
PE
Priv Esc
T1068 - Exploitation for Privilege Escalation
1
DE
Defense Evasion
T1562 - Impair Defenses
-
CA
Cred Access
No techniques detected
-
DI
Discovery
No techniques detected
1
LM
Lateral Mov
T1021 - Remote Services
-
CO
Collection
No techniques detected
-
C2
C2
No techniques detected
2
EX
Exfil
T1567 - Exfiltration Over Web Service
T1041 - Exfiltration Over C2 Channel
1
IM
Impact
T1486 - Data Encrypted for Impact
11
techniques detected across
8
tactics
Related Clusters (22)
Washington Post Confirms Breach from Oracle EBS Attacks by Cl0p Ransomware Gang
Nov 7
·
3 sources
79
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies
Aug 14
·
30 sources
79
Critical MOVEit Vulnerabilities Expose Organizations to Data Breaches
May 4
·
11 sources
74
Critical Vulnerabilities in SolarWinds Serv-U Require Immediate Patching
Jul 22
·
6 sources
73
Critical Vulnerabilities in Progress ShareFile Enable Unauthenticated File Exfiltration
Apr 2
·
7 sources
72
Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise
Apr 1
·
30 sources
71
Ernst & Young Data Breach Exposes Client Tax Information
Jul 17
·
23 sources
68
Clop Ransomware Group Breaches University of Phoenix Data of 3.5 Million
Dec 30
·
3 sources
62
Clop Ransomware Targets Gladinet CentreStack Servers for Data Theft
Dec 19
·
6 sources
57
Clop Ransomware Claims Breaches of Canon and Mazda
Nov 24
·
4 sources
57
Ransomware Groups Target Retailers Ahead of Holiday Shopping
Nov 21
·
31 sources
57
GRIPA Class Action Settlement for MOVEit Data Breach Announced
Jun 26
·
2 sources
52
Deutsche Bank Investigates Ransomware Breach by Unsafe Group
Jul 9
·
2 sources
52
Critical Vulnerabilities in SolarWinds Serv-U Software Patched
Feb 24
·
19 sources
50
Delta Dental Fined $2.25M for Data Breach Lapses in New York
May 2
·
5 sources
49
GlobalLogic Reports Data Breach Affecting Over 10,000 Employees
Nov 11
·
3 sources
49
Supply Chain Breaches Affect 97% of Organizations in 2025
Nov 24
·
3 sources
38
Emergence of Agentic AI Raises Governance and Security Challenges
Feb 10
·
4448 sources
35
Washington Post Data Breach Linked to Oracle E-Business Suite Exploit
Dec 1
·
50 sources
35
SMEs Urged to Enhance Cybersecurity Ahead of Small Business Saturday
Nov 16
·
32 sources
34
Third-Party Vendor Risks Lead to Cybersecurity Breaches
Feb 27
·
2 sources
31
Top Cybersecurity PR Agencies of 2026 Identified
Jun 3
·
2 sources
3
Prev
1 / 5
Next
Related Articles (29)
Unpacking The Moveit Breach Statistics And Analysis
www.emsisoft.com
·
Aug 18
Cyber gang claims to have breached dozens of multinationals, stolen data
Computing
·
Aug 14
Cl0p claims a mass hack of Shell, Philips, and dozens more
Thenextweb
·
Aug 14
Data transfer software Serv-U has 15 critical security vulnerabilities
Heise.De
·
Jul 22
EY data breach exposes client tax documents
Cybernews
·
Jul 18
Deutsche Bank probes supplier cyber incident after ransomware gang claims breach
Computing
·
Jul 9
$2.15M Settlement Ends Greater Rochester Independent Practice Association Lawsuit Over ...
Classaction
·
Jun 26
Cybersecurity PR Agencies - Best Picks 2026
Analyticsinsight
·
Jun 3
Cybersecurity PR Agencies - Best Picks 2026
Analyticsinsight
·
Jun 3
NYDFS Fines Delta Dental $2.25M Over MOVEit Data Breach
Law360
·
May 2
Filigran Report: 90% of Financial Sector Breaches Driven by Financial Gain as AI and ...
Morningstar
·
Apr 21
Researchers warn of critical flaws in Progress ShareFile
Cybersecuritydive
·
Apr 3
Mercor confirms cyberattack as hackers claim 4TB of critical data in possession
Cybernews
·
Apr 1
Counter third-party risk with continuous vendor monitoring
Techtarget
·
Feb 27
New Serv-U bugs extend SolarWinds’ run of high
Csoonline
·
Feb 25
Patch these 4 critical, make-me-root SolarWinds bugs ASAP
Theregister
·
Feb 24
Patch these 4 critical, make-me
Theregister
·
Feb 24
Latest Oracle EBS Victims Include Korean Air, University of Phoenix
Thecyberexpress
·
Dec 30
CL0P Ransomware Group Targets Gladinet CentreStack in New Campaign
Thecyberexpress
·
Dec 19
University of Pennsylvania joins growing pool of Oracle customers impacted by Clop attacks
Cyberscoop
·
Dec 2
Oracle EBS exploitation similar to Clop's MOVEit, GoAnywhere attacks
Scworld
·
Dec 1
From security silos to collective resilience: Transforming supply chain security in the UK insurance industry
Securitybrief
·
Nov 19
The Washington Post reveals thousands impacted via Oracle-based hack
Cybernews
·
Nov 16
Washington Post breach impacts nearly 10K
Scworld
·
Nov 15
Washington Post confirms data on nearly 10,000 people stolen from its Oracle environment
Cyberscoop
·
Nov 13
Hitachi-owned GlobalLogic admits data stolen by Clop
Theregister
·
Nov 11
Hitachi
Theregister
·
Nov 11
Washington Post is latest victim of Oracle-hacking Cl0p gang
Cybernews
·
Nov 7
Cyber Trends Report
Stories.Td
·
Oct 29
Prev
1 / 6
Next
Related Entities
Midnight Blizzard
Ta505
Volt Typhoon
Data Breach
Ransomware
Supply Chain Attack
Phishing
Malware
DDoS
Zero-day Exploit
Oracle EBS campaign
Clop Oracle EBS Campaign