LIVE
UTC --:--:--
OT SECURITY HUB
by zuckergates
// INCIDENT · 2024

Cleo MFT Mass Exploitation (Cl0p)

Cl0p kembali mengeksploitasi platform managed file transfer setelah MOVEit; gelombang Desember 2024.

highGlobalMultiCl0p
Impact
60+ organisasi (logistik, manufaktur, ritel AS) terkena pencurian data via Cleo.
Initial vector
Zero-day Cleo Harmony/VLTrader CVE-2024-50623/55956
Malware / tooling
Cl0p
Lessons learned
  • Inventaris MFT semua vendor
  • Patch & WAF darurat
  • Threat intel Cl0p TTP