Top file-sharing tools are being hit by security attacks once again

Cyber-security
(Image credit: Getty Images)

  • Security researchers Huntress uncover flaw in LexiCom, VLTransfer, and Harmony tools
  • The flaw was patched more than a month ago, but the patch did not work
  • Now hackers are abusing the bug, possibly to steal data

Multiple managed file transfer tools from the same developer are being abused to launch attacks and possibly steal data, experts have warned, with dozens of organizations already targeted.

Cybersecurity researchers at Huntress have claimed LexiCom, VLTransfer, and Harmony were all vulnerable to CVE-2024-50623, an unrestricted file upload and download vulnerability that could lead to remote code execution.

All three tools were built by the same company, Cleo, which published a patch for the bug in late October 2024 - however, Huntress claims that the patch doesn’t work well and doesn’t protect the users from threat actors.

Post-exploitation activity

In fact, Huntress, which says its tools protect more than 1,700 Cleo users, claims it spotted at least 24 compromised businesses.

“Victim organizations so far have included various consumer product companies, logistics and shipping organizations, and food suppliers,” Huntress said in its writeup, adding that countless other companies are at risk.

TechCrunch added that Shodan shows “hundreds” of vulnerable Cleo servers, mostly in the United States. The company has more than 4,000 clients, including a number of large enterprises.

The attackers have not yet been identified, and Huntress is not conclusively saying if they stole any information from these organizations. However, the researchers did say that the threat actors were running “post-exploitation” activity, which could hint that files were, indeed, stolen.

Cleo acknowledged the flaw, and confirmed the team was working on a further fix, but until that is released, users should put the tools behind a firewall, just to be on the safe side.

Managed file transfer (MFT) solutions and security issues started grabbing headlines in 2023, when a Russian ransomware group Cl0p found a hole in MOVEit and used it to exfiltrate data from thousands of organizations around the world.

Via TechCrunch

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Avast cybersecurity
Hackers are hijacking government software to access sensitive servers
Cl0p ransomware group says it was behind Cleo attacks
coding
Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day