Tech

59 organizations reportedly victim to breaches caused by Cleo software bug

Share
Share


  • At press time, Cleo’s Lexicom, VLTransfer and Harmony contain a bug it disclosed in October 2024
  • Threat actors were first observed to be exploiting it in December 2024
  • Ransomware group Clop has claimed 59 victims on its leak site, though some are disputing any intrusion

Clop, the Russian state-linked ransomware group, has now claimed to have hacked 59 companies after exploiting a known bug in a number of file transfer applications developed by software house Cleo.

The flaw, CVE-2024-50623, affects Cleo’s LexiCom, VLTransfer and Harmony software, inadvertently enables remote code execution, and was first disclosed on October 30, 2024. Clop later published the list of victims on its dark web site, though many are denying that a breach has taken place.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Google just accused iOS 26 of copying these 3 features on iPhones – and it has a point
Tech

Google just accused iOS 26 of copying these 3 features on iPhones – and it has a point

A new Google Pixel #BestPhonesForever ad appears It points out the features...

Amazon says it expects to cut human workers and replace them with AI
Tech

Amazon says it expects to cut human workers and replace them with AI

Amazon CEO Andy Jassy urges workers to be “curious about AI” It...

This leaked Insta360 camera could be the Go 4 – and the design has me asking questions
Tech

This leaked Insta360 camera could be the Go 4 – and the design has me asking questions

Leaked image shows a rounded square design and a large lens Hints...