Security News > 2024 > December > New Cleo zero-day RCE flaw exploited in data theft attacks

2024-12-10 15:09
Hackers are actively exploiting a zero-day vulnerability in Cleo managed file transfer software to breach corporate networks and conduct data theft attacks. [...]
News URL
Related news
- Craft CMS RCE exploit chain used in zero-day attacks to steal data (source)
- Google fixes Android zero-days exploited in attacks, 60 other flaws (source)
- CISA Warns of CentreStack's Hard-Coded MachineKey Vulnerability Enabling RCE Attacks (source)
- CentreStack RCE exploited as zero-day to breach file sharing servers (source)
- Apple fixes two zero-days exploited in targeted iPhone attacks (source)
- Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201) (source)
- Apple Patches Two Zero-Days Used in ‘Extremely Sophisticated’ Attacks (source)
- Active! Mail RCE flaw exploited in attacks on Japanese orgs (source)
- Phishing detection is broken: Why most attacks feel like a zero day (source)
- DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks (source)