logo

Ransomware scum blow holes in Cleo software patches, Cl0p (sort of) claims responsibility

ID: 17a75f20-084c-5825-9f7f-f9724a83fa8c

STIX ID: report--17a75f20-084c-5825-9f7f-f9724a83fa8c

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-12-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Cleo issued patches for an RCE-capable unrestricted file upload/download flaw (CVE-2024-50623), but a subsequent bypass (CVE-2024-55956) has been exploited in the wild; security firms report mass exploitation, discovery of the Malichus malware, and at least ten business compromises, with the Russia-linked Cl0p ransomware group claiming responsibility while CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and Cleo urged customers to upgrade to 5.8.0.24.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.