Cybersecurity experts are warning of a new critical vulnerability in popular file transfer technology, which hackers are actively exploiting for mass attacks.

The vulnerability, codenamed CVE-2024-50623, affects software from American company Cleo, according to cybersecurity group Huntress.
See more: CISA: Warns of vulnerabilities in CyberPanel, North Grid, ProjectSend and Zyxel Firewalls
Cleo first issued a warning on October 30, announcing that the vulnerability could allow remote execution of malicious code. The security issue affects LexiCom, VLTransfer, and Harmony tools, which are widely used by enterprises for file management .
Despite Cleo releasing a patch in October, Huntress stressed on Monday that the fix does not fully resolve the issue. John Hammond, a researcher at Huntress, said that since December 3, there have been massive attacks by hackers exploiting the vulnerability. At least ten businesses, including consumer products, transportation and supply chain companies, have already been compromised.
“Organizations that have been targeted so far include consumer products companies, logistics and shipping organizations, and food suppliers,” Hammond said, adding that many other customers are at risk of cyberattacks.
Additionally, Shodan, a search engine for publicly accessible devices and databases, has identified hundreds of vulnerable Cleo servers, primarily in the United States. Huntress recommends that affected businesses move any systems exposed to the internet behind a firewall until a new, effective update is available.
Read more: Hackers exploit vulnerability in Apple Safari

File transfer platforms are a frequent target of malicious attacks and ransomware gangs. Enterprise file transfer tools are one of the most attractive targets for hacking and extortion gangs. Last year, the Clop ransomware gang, linked to Russia, exploited a zero-day vulnerability in Progress Software ’s MOVEit Transfer to thousands of victims. The same gang had previously distracted researchers by exploiting another vulnerability, this time in Fortra’s GoAnywhere software, where it targeted more than 130 organizations.
Source: techcrunch
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
