URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat 46%

By The Hacker News36%

7/10/2026, 6:17:21 PM

BS Summary: This article contains 25 faulty reasoning types, including Appeal to Authority, Availability Heuristic, and Pessimism Bias, with Negativity Bias as the most egregious example at 15.9% saturation with 152 hits. Analysis detected 1,218 faulty-reasoning hits from 953 analyzed words, generating a BS Score of 48.2% and a BS Rank of 46% (11,826 of 21,887 articles). This article is better (less manipulative) than 54.00% of the article peer group.

URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat 
 Swati Khandelwal  Jul 10, 2026 Enterprise Security / Security Incident 
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." 
The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security experts. 
It says it has no indication of unauthorized access to any ShareFile accounts or data, and that it notified customers after learning of the threat. 
What Progress has not said is what the threat is or who is behind it. 
The order became public when a customer posted the company's email to Reddit's r/sysadmin on July 10. 
Progress confirmed the disruption on its status page, listing Storage Zone Controller customers as "not operational" and the incident as under investigation as of a 12:12 p.m. 
EDT update. 
Only the Storage Zone Controller is affected, not standard cloud-only ShareFile accounts. 
The controller is a server that a company runs itself, so files can stay on its own storage while it still uses ShareFile's cloud to share and manage them. 
The controller usually sits at the network's edge, reachable from the internet. 
That exposure makes it both useful and a target. 
Ordering customers to take it fully offline, rather than just patch it, is a notable step. 
That choice is itself a tell. 
If a fix for this threat existed, Progress would be telling customers to apply it; the shutdown order suggests there is none yet. 
That usually means a newly found flaw the company is racing to close, though the same step would also fit a threat a patch cannot address, such as stolen keys or a problem on Progress's own side. 
Its statement that no accounts or data were accessed is careful wording, too, and does not rule out trouble on the controllers themselves. 
Follow the shutdown order first. 
Keep the affected controllers offline until Progress says what the threat is and when it is safe to restart. 
Separately, confirm your version is current: 5.12.4 or later on the 5.x line, or a 6.x release. 
That closes the flaws fixed earlier this year, but Progress has not said it clears the current threat, so do not treat it as permission to restart. 
If a controller is reachable from the internet, handle it as a possible incident. 
Preserve the logs and start your incident-response process, then check for unfamiliar .aspx files in the web folders and storage paths you did not set. 
A clean-looking server is not proof that it is clean. 
ShareFile has faced this before. 
In 2023, while the product still belonged to Citrix, attackers exploited an unauthenticated flaw in the same Storage Zones Controller (CVE-2023-24489). 
CISA flagged it as actively exploited , and Citrix cut unpatched controllers off from the ShareFile cloud, the same access block Progress has now imposed. 
Progress, which acquired ShareFile in 2024, had already weathered a mass file-transfer attack of its own: MOVEit, whose 2023 zero-day was exploited by the Clop group and hit more than 2,700 organizations. 
The Storage Zones Controller also had two critical flaws that watchTowr disclosed in April and Progress patched in March, though the company has not connected the current threat to them, and neither has been reported as exploited. 
The central question is still unanswered: Progress has pulled these systems offline and is working with outside experts, but has not said what the threat is or when customers can safely bring them back online. 
Found this article interesting? 
Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. 
Cloud security , data security , enterprise security , Incident response , network security , security incident , server security , Software Security , Vulnerability , Windows Security 
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories 
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability 
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets 
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs 
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries 
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards 
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys 
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw 
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts 
 Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More 
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks 
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private 
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild 
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials 
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks 
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study 
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks 
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data 
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS 
 Featured Resources 
What 200+ Security Teams Reveal About Using IP Intelligence in 2026 
Get Hands-On SANS Training for Today’s Cyber Defense and Offensive Security Challenges 
See What’s Really Exposed Across Your IT, OT, IoT, Cloud, and Mobile Assets 
Get Gartner’s Guide to AI Agent Supervision and Runtime Controls 
Article reasoning-pattern comparisonThis article: 8.5%The Hacker News: 1.8%The Hacker News: 1.9%Confirmation Bias8.5%This article: 0.0%The Hacker News: 0.8%The Hacker News: 1.2%Anchoring Bias0.0%This article: 10.7%The Hacker News: 3.5%The Hacker News: 3.3%Availability Heuristic10.7%This article: 0.9%The Hacker News: 1.5%The Hacker News: 1.5%Representativeness Heuristic0.9%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.6%Hindsight Bias0.0%This article: 0.0%The Hacker News: 2.7%The Hacker News: 2.5%Overconfidence Bias0.0%This article: 3.1%The Hacker News: 2.8%The Hacker News: 2.7%Framing Effect3.1%This article: 2.5%The Hacker News: 1.3%The Hacker News: 1.0%Loss Aversion2.5%This article: 3.0%The Hacker News: 0.6%The Hacker News: 0.6%Status Quo Bias3.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 5.6%The Hacker News: 1.4%The Hacker News: 1.3%Optimism Bias5.6%This article: 10.2%The Hacker News: 1.4%The Hacker News: 1.6%Pessimism Bias10.2%This article: 15.9%The Hacker News: 6.6%The Hacker News: 6.7%Negativity Bias15.9%This article: 2.6%The Hacker News: 1.5%The Hacker News: 0.8%Self-Serving Bias2.6%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%The Hacker News: 0.8%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 2.7%The Hacker News: 1.0%The Hacker News: 1.5%Recency Bias2.7%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Straw Man0.0%This article: 13.3%The Hacker News: 3.7%The Hacker News: 4.0%Appeal to Authority13.3%This article: 5.2%The Hacker News: 2.4%The Hacker News: 1.6%False Dilemma5.2%This article: 0.0%The Hacker News: 0.4%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 0.5%The Hacker News: 5.1%The Hacker News: 4.3%Hasty Generalization0.5%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.2%Bandwagon0.0%This article: 0.4%The Hacker News: 1.3%The Hacker News: 1.1%Appeal to Emotion0.4%This article: 0.6%The Hacker News: 0.9%The Hacker News: 0.5%Begging the Question0.6%This article: 2.6%The Hacker News: 1.8%The Hacker News: 1.9%Post Hoc (False Cause)2.6%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.5%The Hacker News: 0.4%The Hacker News: 0.6%Burden of Proof0.5%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%The Hacker News: 0.5%The Hacker News: 0.3%Composition/Division0.0%This article: 1.8%The Hacker News: 1.2%The Hacker News: 1.0%Anecdotal1.8%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 7.3%The Hacker News: 1.3%The Hacker News: 2.3%Ambiguity (Equivocation)7.3%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 3.9%The Hacker News: 0.1%The Hacker News: 0.0%Middle Ground3.9%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 8.7%The Hacker News: 0.8%The Hacker News: 1.4%Unattributed Quote8.7%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 3.1%The Hacker News: 1.9%The Hacker News: 2.3%Biased Writer Voice3.1%This article: 8.4%The Hacker News: 5.0%The Hacker News: 4.4%Indoctrination8.4%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 5.4%The Hacker News: 6.7%The Hacker News: 3.0%Attempt to Sell a Product or S…5.4%

953 words analyzed.

Speakers

10speakers21%attributed speech756writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 15 words • 100.0% coverageWriter's voice • 15 words • 100.0% coverageSwati Khandelwal • 12 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageProgress Software • 31 words • 100.0% coverageProgress Software • 25 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageProgress • 27 words • 100.0% coverageWriter's voice • 2 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 37 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 19 words • 100.0% coverageWriter's voice • 17 words • 100.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 14 words • 100.0% coverageWriter's voice • 25 words • 100.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageCISA • 25 words • 100.0% coverageWriter's voice • 32 words • 0.0% coverageWriter's voice • 37 words • 0.0% coverageWriter's voice • 35 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 16 words • 100.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageOpenAI • 11 words • 0.0% coverageFBI • 10 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageMicrosoft • 12 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageOracle • 10 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageMicrosoft • 12 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageSANS • 12 words • 100.0% coverageWriter's voice • 13 words • 100.0% coverageGartner • 10 words • 100.0% coverage
Selected voice

CISA

100%flagged-word coverage
25 attributed words13% of attributed speech75% writer coverage
0%50.0%100.0%Unattributed Quote+100.0 ptsWriter: 0.0%CISA: 100.0%100.0%Indoctrination-10.6 ptsWriter: 10.6%CISA: 0.0%0.0%Biased Writer Voice-4.0 ptsWriter: 4.0%CISA: 0.0%0.0%Attempt to Sell a Product -3.8 ptsWriter: 3.8%CISA: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.