Hackers Exploit Zero-Day in Cleo MFT Software, Enabling RCE and Data Theft
Join our
Hackers are exploiting a zero-day vulnerability in Cleo’s managed file transfer (MFT) software to breach corporate networks and conduct data theft attacks.
The Vulnerability
The flaw affects Cleo’s widely-used secure file transfer products, including LexiCom, VLTrader, and Harmony, and enables unrestricted file upload and downloads, leading to remote code execution (RCE).
The vulnerability, a bypass of a previous fix for CVE-2024-50623, impacts versions 5.8.0.21 and earlier. Cleo initially patched CVE-2024-50623 in October 2024, but the fix was incomplete, leaving systems open to exploitation.
Attack Scope
Cleo’s software is used by 4,000 companies worldwide, including prominent names like Target, Walmart, CVS, FedEx, and The Home Depot, among others. Security researchers have identified Termite ransomware gang as a possible actor leveraging this zero-day, reminiscent of previous exploits by the Clop ransomware group targeting MFT tools like MOVEit Transfer and Accellion FTA servers.
See Also: So, you want to be a hacker?
Exploitation in the Wild
The active exploitation was first
Trending:
Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? If you want to express your idea in an article contact us here for a quote: [email protected]
Source: bleepingcomputer.com
Community-Analysen & Experten-Meinungen 0
Verwandte Story-Cluster & Quellen (Vektor-KI)
Ähnliche Beiträge
Auch interessante Nachrichten Hackers Exploit Zero-Day in Cleo MFT Software, Enabling RCE and Data Theft
Thematisch verwandte Begriffe: Hackers, Exploit, ZeroDay, Cleo · 6 Treffer
Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Borrowed Machinery: SnappyClient, HijackLoader, and a Shared Codebase?
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
SOCIAL SHARE CARD GENERATOR