logo

CISA confirms critical Cleo bug exploitation in ransomware attacks

ID: fd68148f-1990-5316-a619-140337369a01

STIX ID: report--fd68148f-1990-5316-a619-140337369a01

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-12-13

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

CISA confirmed active exploitation of a critical RCE flaw in Cleo file transfer products (CVE-2024-50623) used in ransomware/data-theft campaigns; researchers observed a zero-day bypass and deployment of a Java-based backdoor (Malichus), dozens of compromised Cleo hosts, and vendors issued patches and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.