Fully patched Cleo products under renewed 'zero-day-ish' mass attack
ID: 02ecc7a8-023f-5624-aa0d-04cbce63086f
STIX ID: report--02ecc7a8-023f-5624-aa0d-04cbce63086f
Feed Name: The Register (Security)
Threat Score
Huntress reported active, large-scale exploitation of CVE-2024-50623 against Cleo file-integration products (Harmony, VLTrader, LexiCom), with attackers abusing the Import/Autorun functionality to invoke PowerShell, download JAR webshells, and perform post-exploitation reconnaissance; thousands of exploit attempts were observed and at least ten customers are believed compromised, prompting released IOCs and mitigations while customers await vendor patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
