type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [vendor, incident, supply-chain] ยท confidence: high ยท affected_sectors: [technology, government, finance, healthcare] ยท au_impact: true
Progress Software
Progress Software is a technology company whose products have been the subject of three major security incidents in as many years: MOVEit Transfer, WS_FTP Server, and (July 2026) ShareFile StorageZone Controller.
July 2026: ShareFile Storage Zone Controllers
- Date: July 10, 2026
- Action: Progress told ShareFile customers to shut down Windows servers running Storage Zone Controllers in response to a "credible external security threat"
- Affected accounts were temporarily disabled "out of an abundance of caution"
- No confirmed unauthorized access to ShareFile accounts or data as of disclosure (raw/digests/Cyber-Digest-2026-07-11)
- The order became public after a customer posted Progress's email to Reddit's r/sysadmin on July 10
History of Incidents
| Year | Product | Impact |
|---|---|---|
| 2023 | MOVEit Transfer | Mass exploitation via SQL injection; hundreds of organisations affected |
| 2024 | WS_FTP Server | Critical vulnerabilities disclosed |
| 2026 | ShareFile StorageZone | Credible external threat โ proactive shutdown ordered |
Significance
Progress Software's repeated security incidents raise questions about their secure development lifecycle and the risk of vendor concentration in the file transfer market.
Australian Angle
Australian organisations using Progress products (MOVEit, WS_FTP, ShareFile) should: 1. Verify they are following the latest security guidance 2. Consider vendor diversification for file transfer infrastructure 3. Ensure ShareFile Storage Zone Controllers are patched or disabled per Progress guidance Au Impact
Related Pages
- Injective Labs Supply Chain โ Another supply chain incident
- Netnut Takedown โ Contrast: law enforcement action vs. vendor-triggered response