Hackers are exploiting a flaw in popular file-transfer tools to launch mass hacks, again

Date:

Share post:


Security researchers are warning that hackers are actively exploiting another high-risk vulnerability in a popular file transfer technology to launch mass hacks. 

The vulnerability, tracked as CVE-2024-50623, affects software developed by Illinois-based enterprise software company Cleo, according to researchers at cybersecurity company Huntress. 

The flaw was first disclosed by Cleo in a security advisory on October 30 which warned that exploitation could lead to remote code execution. It affects ​​Cleo’s LexiCom, VLTransfer, and Harmony tools, which are commonly used by enterprises to manage file transfers.

Cleo released a patch for the vulnerability in October, but in a blog on Monday Huntress warned that the patch does not mitigate the software flaw.

Huntress security researcher John Hammond said the company has observed threat actors “exploiting this software en masse” since December 3. He added that Huntress — which protects more than 1,700 Cleo LexiCom, VLTransfer, and Harmony servers — has discovered at least 10 businesses whose servers were compromised. 

“Victim organizations so far have included various consumer product companies, logistics and shipping organizations, and food suppliers,” wrote Hammond, adding that many other customers are at risk of being hacked.

Shodan, a search engine for publicly available devices and databases, lists hundreds of vulnerable Cleo servers, the majority of which are located in the U.S.

Cleo has more than 4,200 customers, including U.S. biotechnology company Illumina, sports footwear giant New Balance, and Dutch logistics firm Portable.

Huntress has not yet identified the threat actor behind these attacks and it’s not known whether any data has been stolen from impacted Cleo customers. However, Hammond noted that the company has observed hackers performing “post-exploitation activity” after compromising vulnerable systems.

Cleo did not respond to TechCrunch’s questions and has not yet released a patch that protects against the flaw. Huntress recommends that Cleo customers move any internet-exposed systems behind a firewall until a new patch is released.

Enterprise file transfer tools are a popular target among hackers and extortion groups. Last year, the Russia-linked Clop ransomware gang claimed thousands of victims by exploiting a zero-day vulnerability in Progress Software’s MOVEit Transfer product. The same gang had previously taken credit for the mass exploitation of a vulnerability in Fortra’s GoAnywhere managed file transfer software, which was used to target more than 130 organizations. 



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

ChatGPT and Sora are down

OpenAI says ChatGPT, Sora, and its developer-facing API are experiencing a major outage, according to the company’s...

SolarSquare raises $40 million in India’s largest solar venture round

SolarSquare has raised $40 million in what is the largest venture round in India’s solar sector. The...

Trump’s proposed university endowment tax could hurt funding, VC warns

Some VCs are looking at the Trump administration’s proposed massive tax increase on university endowments with alarm,...

It sure looks like OpenAI trained Sora on game content — and legal experts say that could be a problem

OpenAI has never revealed exactly which data it used to train Sora, its video-generating AI. But from...

Hyundai’s electric air taxi startup Supernal is moving its HQ from DC to California

Hyundai’s electric vertical takeoff and landing startup Supernal is shifting its global headquarters from Washington, D.C. to...

Pentagon doesn’t know where mystery drones over New Jersey come from

In a press briefing on Wednesday, the Pentagon said it has no evidence that the mysterious drones...

Microsoft’s M12 invests another $22.5M into NeuBird, months after its $22M seed round

Late last year, Gou Rao and Vinod Jayaraman founded NeuBird to automate IT site reliability operations tasks...

Green ammonia startup Amogy is trying to raise $90M to reduce truck pollution

Green ammonia startup Amogy has raised $11.2 million of a targeted $90 million round, an SEC filing...