Cleo File Transfer Vulnerabilities (CVE-2024-50623, CVE-2024-55956) – Cl0P’s Latest Attack Vector
ID: ab5bfe87-11c2-5625-b3fe-5c32e7f99a97
STIX ID: report--ab5bfe87-11c2-5625-b3fe-5c32e7f99a97
Feed Name: SOCRadar Blog
**Executive Summary:** The report details active, large-scale exploitation of two critical Cleo Managed File Transfer vulnerabilities (CVE-2024-50623, CVE-2024-55956) enabling unauthenticated file upload/download and remote code execution; attackers have deployed a Java backdoor named Malichus, multiple organizations have been impacted, Cl0p has publicly claimed and is extorting victims, and CISA has added the vulnerabilities to its KEV catalog—organizations are advised to upgrade to Cleo 5.8.0.24, disable Autorun, and isolate Cleo servers from the public internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
