US State Department Puts $10M Bounty on Clop Ransomware Gang Responsible for the Ongoing MOVEit Zero-day Vulnerability Rampage

A quick, anecdotal thumbnail sketch on the cybersecurity threat vectors for 2023: the APT and zero-day activity feel particularly ferocious right now.  As a result, on June 1, 2023, we generated a quick, general update on Federal Deadlines for Updates to Known Exploited Vulnerabilities and Zero-days Patches in an effort to wrap our brains around the current volume, severity, and frequency of recent attacks and ransomware activity.  While we were preparing the update, the first news of what has become a significant cybersecurity incident – The Clop ransomware gang exploiting a new zero-day vulnerability affecting a popular file transfer tool used by thousands of major companies – crossed our desk.  We included it in the update, including the initial advisory provided by the MOVEit transfer tool.  See Progress Software Releases Security Advisory for MOVEit Transfer.