
Cleo File Transfer Software Faces Renewed Zero-Day Exploits
Hackers are exploiting a high-risk vulnerability, CVE-2024-50623, in Cleo's file transfer tools, affecting LexiCom, VLTransfer, and Harmony, despite a patch released in October. Huntress researchers report mass exploitation since December 3, compromising at least 10 businesses, including consumer product and logistics companies. Cleo has not responded to inquiries or released a fully effective patch, prompting recommendations to firewall vulnerable systems. The incident highlights ongoing risks in enterprise file transfer tools, similar to past attacks on MOVEit Transfer and GoAnywhere software.
