logo

CISA warns of ransomware gangs exploiting Cleo, CyberPanel bugs

ID: 58f2edda-c2e8-5c69-bcee-9b02ba1bc030

STIX ID: report--58f2edda-c2e8-5c69-bcee-9b02ba1bc030

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2024-12-13

Date Updated: 2026-05-01

...
...

CISA has confirmed that ransomware groups are actively exploiting two vulnerabilities—CVE-2024-50623 in Cleo file-transfer products and CVE-2024-51378 in CyberPanel—prompting urgent patching deadlines for federal agencies. Security researchers report multiple ransomware strains (including PSAUX, Babuk, Cerber, and actors linked to Termite) leveraging these flaws, with evidence of widespread compromise across enterprise file-sharing and web hosting environments, including thousands of CyberPanel instances reportedly targeted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.