59 organizations have reportedly fallen victim to breaches caused by Cleo software flaws


  • At press time, Cleos Lexicom, VLTransfer and Harmony contain a bug that it disclosed in October 2024
  • Threat actors were first observed exploiting it in December 2024
  • Ransomware group Clop has claimed 59 victims on its leak site, although some deny any intrusion

Clop, the Russian state-linked ransomware group, has now claimed to have hacked 59 companies after exploiting a known flaw in a number of file transfer applications developed by software house Cleo.

The flaw, CVE-2024-50623, affects Cleo’s LexiCom, VLTransfer, and Harmony software, enables accidental remote code execution, and was first disclosed on October 30, 2024. Clop later published the list of victims on his dark web site, though many have denied , that a violation has occurred.

Leave a Comment

Your email address will not be published. Required fields are marked *