Western Alliance Bank at 25-0214. The Cl0p Oracle campaign at 25-1007 and Logitech at 25-1003. Chess.com at 25-1005. Four 2025 files in this database turn on software whose purpose is moving files between organisations.
The Category Has Three Properties That Compound
It must be reachable from outside, because transferring files with external parties is the function. It must authenticate parties the organisation does not control. And it holds, by definition, the material considered too large or too sensitive for ordinary channels.
That is the same three-property analysis this desk applied to security appliances at 25-0805 — internet-facing, parsing untrusted input, trusted by everything behind it — and it produces the same result: a vulnerability here is worth more than the same vulnerability almost anywhere else.
And The Data Should Not Still Be There
A transfer product is transitional by design. A file arrives, is collected, and has no reason to remain.
In practice files persist — because deletion is a configuration nobody set, because somebody might need it again, because the retention policy was written for the systems of record and not for the plumbing between them.
The corpus filed the same asymmetry at 25-1207 for durable authorisations: creating costs nothing, removing requires somebody to decide it is time, and the failure mode of leaving it in place is invisible.
What Follows
Not that the products are badly built. That a category with these properties will keep producing portfolio-scale incidents, and that the controls which help are unglamorous: automatic deletion on collection, brokered rather than direct exposure, and treating the transfer estate as a crown-jewel asset rather than as infrastructure.
Graded medium: four files in one corpus year is a pattern, not a base rate, and this desk cannot say whether the category fails more often than comparable software or is simply attacked far more.
It generalises from the file-transfer incidents recorded in this database. Sources below support the underlying cases. Corrections: corrections@forensicpost.com.