Top file-sharing tools are being hit by security attacks once again

Cyber-security
(Image credit: Getty Images)

  • Security researchers Huntress uncover flaw in LexiCom, VLTransfer, and Harmony tools
  • The flaw was patched more than a month ago, but the patch did not work
  • Now hackers are abusing the bug, possibly to steal data

Multiple managed file transfer tools from the same developer are being abused to launch attacks and possibly steal data, experts have warned, with dozens of organizations already targeted.

Cybersecurity researchers at Huntress have claimed LexiCom, VLTransfer, and Harmony were all vulnerable to CVE-2024-50623, an unrestricted file upload and download vulnerability that could lead to remote code execution.

All three tools were built by the same company, Cleo, which published a patch for the bug in late October 2024 - however, Huntress claims that the patch doesn’t work well and doesn’t protect the users from threat actors.

Post-exploitation activity

In fact, Huntress, which says its tools protect more than 1,700 Cleo users, claims it spotted at least 24 compromised businesses.

“Victim organizations so far have included various consumer product companies, logistics and shipping organizations, and food suppliers,” Huntress said in its writeup, adding that countless other companies are at risk.

TechCrunch added that Shodan shows “hundreds” of vulnerable Cleo servers, mostly in the United States. The company has more than 4,000 clients, including a number of large enterprises.

The attackers have not yet been identified, and Huntress is not conclusively saying if they stole any information from these organizations. However, the researchers did say that the threat actors were running “post-exploitation” activity, which could hint that files were, indeed, stolen.

Cleo acknowledged the flaw, and confirmed the team was working on a further fix, but until that is released, users should put the tools behind a firewall, just to be on the safe side.

Managed file transfer (MFT) solutions and security issues started grabbing headlines in 2023, when a Russian ransomware group Cl0p found a hole in MOVEit and used it to exfiltrate data from thousands of organizations around the world.

Via TechCrunch

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Avast cybersecurity
Hackers are hijacking government software to access sensitive servers
Cl0p ransomware group says it was behind Cleo attacks
coding
Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off